Cybersecurity Research Papers
Master's degree candidates at SANS.edu conduct research that is relevant, has real world impact, and often provides cutting-edge advancements to the field of cybersecurity, all under the guidance and review of our world-class instructors.
Network Artifacts of Trusted Service Abuse
Research PaperOffensive OperationsThis study contrasts normal user traffic with known malicious activity to identify alternative indicators from four public C2 frameworks (DaaC2, DBC2, gdog, Callidus) operating on Dropbox, Discord, Gmail, and OneNote, using 51 packet captures (3 baselines, 6 automated browser tests and 6 framework tests per service).
- 6 Aug 2026
- Nicholas Vaniscak
Dual-Module QR Codes: Bypassing QR Code Scanners in Enterprise Email Gateways
Research PaperOffensive OperationsBy exploiting the decoding algorithm and leveraging existing QR data-layering techniques, this research provides the security industry with a working proof-of-concept to bypass email security gateway detection systems.
- 6 Aug 2026
- Steven Legere
Entra ID Governance: Insta-IAM/IGA Solution?
Research PaperCyber DefenseThis research evaluates the viability of using Entra ID Governance as a primary IAM/IGA solution through a proof-of-concept implementation modeled on a moderately complex organization with multiple systems of record.
- 6 Aug 2026
- Scott Fortin
Reconstructing Deleted File Activity Using FSEvents from macOS
Research PaperDigital Forensics and Incident ResponseThis paper examines the role of FSEvents as a source of historical file system activity, particularly in scenarios where files are no longer present on disk.
- 30 Jul 2026
- Josh Clevenger
Benchmarking Free-Tier Large Language Models as Cognitive Aids for Operationalizing Unstructured Cyber Threat Intelligence
Research PaperDigital Forensics and Incident ResponseModern Security Operations Centers (SOCs) face a deepening burnout crisis.
- 20 Jul 2026
- Jose "Ricky" Banda
Evaluating the Detection Effectiveness of Network Monitoring Tools Against Modern Command-and-Control Frameworks
Research PaperCyber DefenseThis research measures the effectiveness of Zeek, Suricata, and Security Onion against representative modern C2 frameworks in a controlled laboratory environment.
- 9 Jul 2026
- Joseph Zderadicka
Practical MFA for the Enterprise: Enforcing Strong Authentication for Non-Human Identities Using Compensating Controls
Research PaperCyber DefenseThis paper’s case study examined a production Microsoft Entra ID environment at a large North American organization encompassing more than 500 app registrations and 21,000 directory accounts.
- 9 Jul 2026
- Fredrick Stock
Cyber Intelligence GraphRAGs for Behavioral Detection
Research PaperCyber DefenseThis paper introduces chatAPT, a prototype graphRAG system that extends a hybrid dual-retrieval architecture with domain-contextualized extraction, ontologies, and entity alignment, and exposes tools that enable human analysts and AI agents to query enriched threat intelligence during hypothesis generation.
- 9 Jul 2026
- Robert Heald
USB: Universal Security Breach or Uniquely Secured Bus? Assessing the Effectiveness of Windows 11 Group Policy at Controlling USB Device Installation for Budget-Constrained Security Teams
Research PaperCyber DefenseThis study evaluates three progressively granular Windows 11 Group Policy (GPO) configurations—class-based blocking, VID/PID allowlisting, and Device Instance ID allowlisting—against legitimate business peripherals and a Hak5 USB Rubber Ducky configured as a composite BadUSB device, using the Windows 11 v25H2 Security Baseline as the unmodified reference state.
- 22 Jun 2026
- Kire Jacobson
Investigating Operating System Variations in IPv6 Implementations
Research PaperCyber DefenseThis research tested the four most common operating system families, Windows, Linux, macOS, and BSD, for RFC compliance and behavioral differences across a controlled set of IPv6 test cases. Because RFC specifications leave many implementation details to the developer, behavior was expected to diverge, and the testing confirmed that it did.
- 22 Jun 2026
- Donovan Rodriguez
macOS Infostealer Exfiltration Techniques via Native Tooling: Behavioral Analysis and Defenses
Research PaperCyber DefenseThis paper analyzes macOS infostealers and their reliance on native system utilities. The use of specific command-line options and arguments should be predictable and detectable with proper analysis.
- 22 Jun 2026
- Cory Findley
Detection Strategies for AskCreds Beacon Object File Credential Harvesting Across Multiple C2 Frameworks
Research PaperDigital Forensics and Incident ResponseThis study evaluates layered detection strategies against AskCreds BOF execution in an isolated Azure lab using Cobalt Strike 4.12 and Outflank C2 v2.11.1, with Velociraptor as the primary DFIR platform.
- 22 Jun 2026
- Eric Fletcher
