Enhancing Linux Threat Detection: A Sysmon - Based Approach to Identifying Sandworm TTPs

Linux systems have become foundational across modern IT enterprises. Threat actors are increasingly targeting Linux systems, including well - known advanced persistent threats (APTs) such as Sandworm. This research evaluates the effectiveness of Sysmon for Linux in detecting Sandworm tactics,...
By
Joshua Keller
March 20, 2026

All papers are copyrighted. No re-posting of papers is permitted

470x382_Research_Paper_gray.jpg