Aviz Networks describes packet-derived telemetry for OMB M-21-31 EL3
Federal guidance such as OMB M-21-31 and NIST SP 800-92r1 emphasizes that event logging maturity depends on telemetry assurance, not just collecting more logs. The update centers on using packet-derived, wire-level visibility to recover visibility when hosts or endpoints are compromised, which affects how agencies plan EL1 through EL3 and zero trust controls.
Research Overview
The blog describes ongoing federal investment in SIEM deployment and log pipelines alongside continued long attacker dwell times. It frames the problem as a gap between available log volume and the ability to reliably discover intrusions.
It cites OMB M-21-31 and NIST SP 800-92r1 as the policy and technical basis for changing event logging maturity requirements toward trusted telemetry, including packet-derived information.
Key Findings
The blog states that device- and application-level logs may be insufficient because attackers can tamper with the systems that generate them after compromise. It also describes MITRE ATT&CK techniques as a basis for log deletion, disabling logging, or filtering targeted records.
It argues that SIEM-only approaches can miss activity when attackers purge or alter the logs the SIEM relies on. The blog characterizes wire-level packet capture as an out-of-scope source for compromised endpoints because the capture occurs as traffic crosses the network.
Technical Breakdown
The blog explains that a packet broker capturing traffic off the wire creates records independent of endpoint reporting. It describes “telemetry assurance” in line with NIST SP 800-92r1 as a rationale for shifting the practical definition of “federal log” toward network data less resistant to tampering.
It then maps requirements to EL1 through EL3 using capabilities the blog associates with network-derived inputs. For EL1, it references syslog-flow data and non-intrusive DNS monitoring as packet based, while EL2 is described as visibility into encrypted traffic and EL3 as East-West visibility for lateral movement.
Product and Operational Impact
Although the directives are described as vendor-agnostic, the blog positions Aviz Deep Network Observability (DNO) as delivering continuous wire-level packet-derived telemetry. It states DNO ingests traffic via Tap/SPAN, processes it, and delivers optimized raw packets and metadata to inspection tools such as NDR and IDS, as well as to SIEM and observability platforms.
The blog also claims that, with a single capture point, Aviz can produce both raw packets and metadata outputs without adding taps or displacing existing tools. It reports examples from a deployed customer product, including East-West attacks not seen by perimeter controls, encrypted traffic containing expired SSL certificates not appearing in device logs, unapproved AI platform usage from internal servers calling external clouds, and anomalous DNS queries not seen by device logs.
The blog ties OMB M-21-31’s event logging maturity framework to NIST SP 800-92r1 telemetry assurance, emphasizing that EL3 and zero trust efforts require continuous visibility on the wire rather than relying on logs produced by potentially compromised endpoints. This “Blog Signals brief” is a fact-based summary of the vendor blog.
Source: aviznetworks.com, by Ram Mohan Hariprasad.