Skip to main content

Cybersecurity Research Papers

Master's degree candidates at SANS.edu conduct research that is relevant, has real world impact, and often provides cutting-edge advancements to the field of cybersecurity, all under the guidance and review of our world-class instructors.

Showing 12 of 771

Network Artifacts of Trusted Service Abuse

Research PaperOffensive Operations

This study contrasts normal user traffic with known malicious activity to identify alternative indicators from four public C2 frameworks (DaaC2, DBC2, gdog, Callidus) operating on Dropbox, Discord, Gmail, and OneNote, using 51 packet captures (3 baselines, 6 automated browser tests and 6 framework tests per service).

  • 6 Aug 2026
  • Nicholas Vaniscak

Dual-Module QR Codes: Bypassing QR Code Scanners in Enterprise Email Gateways

Research PaperOffensive Operations

By exploiting the decoding algorithm and leveraging existing QR data-layering techniques, this research provides the security industry with a working proof-of-concept to bypass email security gateway detection systems.

  • 6 Aug 2026
  • Steven Legere

Entra ID Governance: Insta-IAM/IGA Solution?

Research PaperCyber Defense

This research evaluates the viability of using Entra ID Governance as a primary IAM/IGA solution through a proof-of-concept implementation modeled on a moderately complex organization with multiple systems of record.

  • 6 Aug 2026
  • Scott Fortin

Reconstructing Deleted File Activity Using FSEvents from macOS

Research PaperDigital Forensics and Incident Response

This paper examines the role of FSEvents as a source of historical file system activity, particularly in scenarios where files are no longer present on disk.

  • 30 Jul 2026
  • Josh Clevenger

Benchmarking Free-Tier Large Language Models as Cognitive Aids for Operationalizing Unstructured Cyber Threat Intelligence

Research PaperDigital Forensics and Incident Response

Modern Security Operations Centers (SOCs) face a deepening burnout crisis.

  • 20 Jul 2026
  • Jose "Ricky" Banda

Evaluating the Detection Effectiveness of Network Monitoring Tools Against Modern Command-and-Control Frameworks

Research PaperCyber Defense

This research measures the effectiveness of Zeek, Suricata, and Security Onion against representative modern C2 frameworks in a controlled laboratory environment.

  • 9 Jul 2026
  • Joseph Zderadicka

Practical MFA for the Enterprise: Enforcing Strong Authentication for Non-Human Identities Using Compensating Controls

Research PaperCyber Defense

This paper’s case study examined a production Microsoft Entra ID environment at a large North American organization encompassing more than 500 app registrations and 21,000 directory accounts.

  • 9 Jul 2026
  • Fredrick Stock

Cyber Intelligence GraphRAGs for Behavioral Detection

Research PaperCyber Defense

This paper introduces chatAPT, a prototype graphRAG system that extends a hybrid dual-retrieval architecture with domain-contextualized extraction, ontologies, and entity alignment, and exposes tools that enable human analysts and AI agents to query enriched threat intelligence during hypothesis generation.

  • 9 Jul 2026
  • Robert Heald

USB: Universal Security Breach or Uniquely Secured Bus? Assessing the Effectiveness of Windows 11 Group Policy at Controlling USB Device Installation for Budget-Constrained Security Teams

Research PaperCyber Defense

This study evaluates three progressively granular Windows 11 Group Policy (GPO) configurations—class-based blocking, VID/PID allowlisting, and Device Instance ID allowlisting—against legitimate business peripherals and a Hak5 USB Rubber Ducky configured as a composite BadUSB device, using the Windows 11 v25H2 Security Baseline as the unmodified reference state.

  • 22 Jun 2026
  • Kire Jacobson

Investigating Operating System Variations in IPv6 Implementations

Research PaperCyber Defense

This research tested the four most common operating system families, Windows, Linux, macOS, and BSD, for RFC compliance and behavioral differences across a controlled set of IPv6 test cases. Because RFC specifications leave many implementation details to the developer, behavior was expected to diverge, and the testing confirmed that it did.

  • 22 Jun 2026
  • Donovan Rodriguez

macOS Infostealer Exfiltration Techniques via Native Tooling: Behavioral Analysis and Defenses

Research PaperCyber Defense

This paper analyzes macOS infostealers and their reliance on native system utilities. The use of specific command-line options and arguments should be predictable and detectable with proper analysis.

  • 22 Jun 2026
  • Cory Findley

Detection Strategies for AskCreds Beacon Object File Credential Harvesting Across Multiple C2 Frameworks

Research PaperDigital Forensics and Incident Response

This study evaluates layered detection strategies against AskCreds BOF execution in an isolated Azure lab using Cobalt Strike 4.12 and Outflank C2 v2.11.1, with Velociraptor as the primary DFIR platform.

  • 22 Jun 2026
  • Eric Fletcher