Skip to main content

Cybersecurity Research Papers

Master's degree candidates at SANS.edu conduct research that is relevant, has real world impact, and often provides cutting-edge advancements to the field of cybersecurity, all under the guidance and review of our world-class instructors.

Showing 12 of 779

Evaluating the Impact of Log Configuration on Lateral Movement Detection Using Windows Event Logs

Research PaperCyber Defense

These findings demonstrate that effective endpoint logging depends not only on the amount of telemetry collected but also on the configuration and filtering strategy.

  • 22 Sep 2026
  • Michael Dobbs

Bot or Not? Detecting AI-Driven Web Traffic Using Network Metadata Analysis

Research PaperCyber Defense, Artificial Intelligence

This detection method is lightweight, non-intrusive, and easily integrated into existing security toolsets, offering defenders a scalable alternative to traditional bot detection and mitigation techniques.

  • 22 Sep 2026
  • William Hatfield

Continuous Enforcement vs Out-of-Band Validation: Mitigating Configuration Drift on Windows Server 2022 with Automated Remediation Loops

Research PaperCyber Defense

This paper examines the persistent issue of configuration drift within enterprise data centers, where routine administration, patches, and user activity silently degrade established security postures between scheduled audits.

  • 22 Sep 2026
  • Christopher Sandoval

WAFstat: External Verification of WAF Enforcement Posture: Measuring Observable WAF Enforcement Beyond Presence Fingerprinting

Research PaperCyber Defense

This study presents WAFstat, a lightweight external verification method that combines a fixed, versioned marker corpus with response-shape baselines, configuration validation, and immutable provenance.

  • 22 Sep 2026
  • Tiago Kiill

Beyond the Tunnel: A Lab-Based Comparative Evaluation of Network-Layer VPN and Identity-Aware Reverse Proxy Architectures Against the CISA Zero Trust Maturity Model

Research PaperCyber Defense

For the Applications and Data pillars, the results depend primarily on the security features bundled with each product and its platform, and the two architectures converge on Identity because both draw their authentication strength from the same identity provider. The study contributes a repeatable methodology and a scored matrix that shows where the architectures genuinely diverge.

  • 17 Sep 2026
  • Henry Cheung

Assessing the Feasibility and Effectiveness of AI in CTI-Driven Threat Hunting

Research PaperArtificial Intelligence, Cyber Defense

This study evaluates three commercial LLMs, OpenAI GPT-4o, Google Gemini, and Microsoft Copilot, against ten recent CTI reports, measuring indicator extraction accuracy and validating generated Kusto Query Language (KQL) and CrowdStrike Query Language (CQL) hunting queries in Microsoft Sentinel and CrowdStrike NG-SIEM.

  • 17 Sep 2026
  • Devron West

The Invisible Checkpoint: Passive LTE Traffic Capture for Mobile Malware Detection

Research PaperDigital Forensics and Incident Response, Cyber Defense

This paper presents a privacy-preserving, field-deployable framework for passive mobile malware detection.

  • 11 Aug 2026
  • Garo Sinanian

Evaluating LLMs as a Bridge Between Cyber Threats and Business Risk for Executive Decision-Making

Research PaperArtificial Intelligence, Cyber Defense

Security leaders cannot act on intelligence they cannot understand, yet most cyber threat intelligence (CTI) reporting is written for analysts, not executives.

  • 11 Aug 2026
  • Arcadio Aguilar

Network Artifacts of Trusted Service Abuse

Research PaperOffensive Operations

This study contrasts normal user traffic with known malicious activity to identify alternative indicators from four public C2 frameworks (DaaC2, DBC2, gdog, Callidus) operating on Dropbox, Discord, Gmail, and OneNote, using 51 packet captures (3 baselines, 6 automated browser tests and 6 framework tests per service).

  • 6 Aug 2026
  • Nicholas Vaniscak

Dual-Module QR Codes: Bypassing QR Code Scanners in Enterprise Email Gateways

Research PaperOffensive Operations

By exploiting the decoding algorithm and leveraging existing QR data-layering techniques, this research provides the security industry with a working proof-of-concept to bypass email security gateway detection systems.

  • 6 Aug 2026
  • Steven Legere

Entra ID Governance: Insta-IAM/IGA Solution?

Research PaperCyber Defense

This research evaluates the viability of using Entra ID Governance as a primary IAM/IGA solution through a proof-of-concept implementation modeled on a moderately complex organization with multiple systems of record.

  • 6 Aug 2026
  • Scott Fortin

Reconstructing Deleted File Activity Using FSEvents from macOS

Research PaperDigital Forensics and Incident Response

This paper examines the role of FSEvents as a source of historical file system activity, particularly in scenarios where files are no longer present on disk.

  • 30 Jul 2026
  • Josh Clevenger