Cybersecurity Research Papers
Master's degree candidates at SANS.edu conduct research that is relevant, has real world impact, and often provides cutting-edge advancements to the field of cybersecurity, all under the guidance and review of our world-class instructors.
Evaluating the Impact of Log Configuration on Lateral Movement Detection Using Windows Event Logs
Research PaperCyber DefenseThese findings demonstrate that effective endpoint logging depends not only on the amount of telemetry collected but also on the configuration and filtering strategy.
- 22 Sep 2026
- Michael Dobbs
Bot or Not? Detecting AI-Driven Web Traffic Using Network Metadata Analysis
Research PaperCyber Defense, Artificial IntelligenceThis detection method is lightweight, non-intrusive, and easily integrated into existing security toolsets, offering defenders a scalable alternative to traditional bot detection and mitigation techniques.
- 22 Sep 2026
- William Hatfield
Continuous Enforcement vs Out-of-Band Validation: Mitigating Configuration Drift on Windows Server 2022 with Automated Remediation Loops
Research PaperCyber DefenseThis paper examines the persistent issue of configuration drift within enterprise data centers, where routine administration, patches, and user activity silently degrade established security postures between scheduled audits.
- 22 Sep 2026
- Christopher Sandoval
WAFstat: External Verification of WAF Enforcement Posture: Measuring Observable WAF Enforcement Beyond Presence Fingerprinting
Research PaperCyber DefenseThis study presents WAFstat, a lightweight external verification method that combines a fixed, versioned marker corpus with response-shape baselines, configuration validation, and immutable provenance.
- 22 Sep 2026
- Tiago Kiill
Beyond the Tunnel: A Lab-Based Comparative Evaluation of Network-Layer VPN and Identity-Aware Reverse Proxy Architectures Against the CISA Zero Trust Maturity Model
Research PaperCyber DefenseFor the Applications and Data pillars, the results depend primarily on the security features bundled with each product and its platform, and the two architectures converge on Identity because both draw their authentication strength from the same identity provider. The study contributes a repeatable methodology and a scored matrix that shows where the architectures genuinely diverge.
- 17 Sep 2026
- Henry Cheung
Assessing the Feasibility and Effectiveness of AI in CTI-Driven Threat Hunting
Research PaperArtificial Intelligence, Cyber DefenseThis study evaluates three commercial LLMs, OpenAI GPT-4o, Google Gemini, and Microsoft Copilot, against ten recent CTI reports, measuring indicator extraction accuracy and validating generated Kusto Query Language (KQL) and CrowdStrike Query Language (CQL) hunting queries in Microsoft Sentinel and CrowdStrike NG-SIEM.
- 17 Sep 2026
- Devron West
The Invisible Checkpoint: Passive LTE Traffic Capture for Mobile Malware Detection
Research PaperDigital Forensics and Incident Response, Cyber DefenseThis paper presents a privacy-preserving, field-deployable framework for passive mobile malware detection.
- 11 Aug 2026
- Garo Sinanian
Evaluating LLMs as a Bridge Between Cyber Threats and Business Risk for Executive Decision-Making
Research PaperArtificial Intelligence, Cyber DefenseSecurity leaders cannot act on intelligence they cannot understand, yet most cyber threat intelligence (CTI) reporting is written for analysts, not executives.
- 11 Aug 2026
- Arcadio Aguilar
Network Artifacts of Trusted Service Abuse
Research PaperOffensive OperationsThis study contrasts normal user traffic with known malicious activity to identify alternative indicators from four public C2 frameworks (DaaC2, DBC2, gdog, Callidus) operating on Dropbox, Discord, Gmail, and OneNote, using 51 packet captures (3 baselines, 6 automated browser tests and 6 framework tests per service).
- 6 Aug 2026
- Nicholas Vaniscak
Dual-Module QR Codes: Bypassing QR Code Scanners in Enterprise Email Gateways
Research PaperOffensive OperationsBy exploiting the decoding algorithm and leveraging existing QR data-layering techniques, this research provides the security industry with a working proof-of-concept to bypass email security gateway detection systems.
- 6 Aug 2026
- Steven Legere
Entra ID Governance: Insta-IAM/IGA Solution?
Research PaperCyber DefenseThis research evaluates the viability of using Entra ID Governance as a primary IAM/IGA solution through a proof-of-concept implementation modeled on a moderately complex organization with multiple systems of record.
- 6 Aug 2026
- Scott Fortin
Reconstructing Deleted File Activity Using FSEvents from macOS
Research PaperDigital Forensics and Incident ResponseThis paper examines the role of FSEvents as a source of historical file system activity, particularly in scenarios where files are no longer present on disk.
- 30 Jul 2026
- Josh Clevenger
