Skip to main content

Exploring Infostealer Malware Techniques on Automotive Head Units

Automotive vehicles have become exponentially more computerized in the last decade, and automakers continue to add new functionality and integrations to these systems. While most research focuses on the safety features of autonomous and semi-autonomous vehicle capabilities, there is little research regarding the data collected by these systems and whether this data is of interest to threat actors.

SANS-D_Mazzella_Exploring_Infostealer_Malware_Techniques_on_Automotive_Head_Units (PDF, 62.95MB)

1 Mar 2024
ByDaniel Mazzella
Share
All papers are copyrighted

No re-posting of papers is permitted

Related Content

Evaluating the Impact of Log Configuration on Lateral Movement Detection Using Windows Event Logs

Research Paper

These findings demonstrate that effective endpoint logging depends not only on the amount of telemetry collected but also on the configuration and filtering strategy.

  • 22 Sep 2026
  • Michael Dobbs

Bot or Not? Detecting AI-Driven Web Traffic Using Network Metadata Analysis

Research Paper

This detection method is lightweight, non-intrusive, and easily integrated into existing security toolsets, offering defenders a scalable alternative to traditional bot detection and mitigation techniques.

  • 22 Sep 2026
  • William Hatfield

Continuous Enforcement vs Out-of-Band Validation: Mitigating Configuration Drift on Windows Server 2022 with Automated Remediation Loops

Research Paper

This paper examines the persistent issue of configuration drift within enterprise data centers, where routine administration, patches, and user activity silently degrade established security postures between scheduled audits.

  • 22 Sep 2026
  • Christopher Sandoval

WAFstat: External Verification of WAF Enforcement Posture: Measuring Observable WAF Enforcement Beyond Presence Fingerprinting

Research Paper

This study presents WAFstat, a lightweight external verification method that combines a fixed, versioned marker corpus with response-shape baselines, configuration validation, and immutable provenance.

  • 22 Sep 2026
  • Tiago Kiill

Beyond the Tunnel: A Lab-Based Comparative Evaluation of Network-Layer VPN and Identity-Aware Reverse Proxy Architectures Against the CISA Zero Trust Maturity Model

Research Paper

For the Applications and Data pillars, the results depend primarily on the security features bundled with each product and its platform, and the two architectures converge on Identity because both draw their authentication strength from the same identity provider. The study contributes a repeatable methodology and a scored matrix that shows where the architectures genuinely diverge.

  • 17 Sep 2026
  • Henry Cheung

Assessing the Feasibility and Effectiveness of AI in CTI-Driven Threat Hunting

Research Paper

This study evaluates three commercial LLMs, OpenAI GPT-4o, Google Gemini, and Microsoft Copilot, against ten recent CTI reports, measuring indicator extraction accuracy and validating generated Kusto Query Language (KQL) and CrowdStrike Query Language (CQL) hunting queries in Microsoft Sentinel and CrowdStrike NG-SIEM.

  • 17 Sep 2026
  • Devron West

The Invisible Checkpoint: Passive LTE Traffic Capture for Mobile Malware Detection

Research Paper

This paper presents a privacy-preserving, field-deployable framework for passive mobile malware detection.

  • 11 Aug 2026
  • Garo Sinanian

Evaluating LLMs as a Bridge Between Cyber Threats and Business Risk for Executive Decision-Making

Research Paper

Security leaders cannot act on intelligence they cannot understand, yet most cyber threat intelligence (CTI) reporting is written for analysts, not executives.

  • 11 Aug 2026
  • Arcadio Aguilar

Entra ID Governance: Insta-IAM/IGA Solution?

Research Paper

This research evaluates the viability of using Entra ID Governance as a primary IAM/IGA solution through a proof-of-concept implementation modeled on a moderately complex organization with multiple systems of record.

  • 6 Aug 2026
  • Scott Fortin

Reconstructing Deleted File Activity Using FSEvents from macOS

Research Paper

This paper examines the role of FSEvents as a source of historical file system activity, particularly in scenarios where files are no longer present on disk.

  • 30 Jul 2026
  • Josh Clevenger

Benchmarking Free-Tier Large Language Models as Cognitive Aids for Operationalizing Unstructured Cyber Threat Intelligence

Research Paper

Modern Security Operations Centers (SOCs) face a deepening burnout crisis.

  • 20 Jul 2026
  • Jose "Ricky" Banda

Evaluating the Detection Effectiveness of Network Monitoring Tools Against Modern Command-and-Control Frameworks

Research Paper

This research measures the effectiveness of Zeek, Suricata, and Security Onion against representative modern C2 frameworks in a controlled laboratory environment.

  • 9 Jul 2026
  • Joseph Zderadicka

Practical MFA for the Enterprise: Enforcing Strong Authentication for Non-Human Identities Using Compensating Controls

Research Paper

This paper’s case study examined a production Microsoft Entra ID environment at a large North American organization encompassing more than 500 app registrations and 21,000 directory accounts.

  • 9 Jul 2026
  • Fredrick Stock

Cyber Intelligence GraphRAGs for Behavioral Detection

Research Paper

This paper introduces chatAPT, a prototype graphRAG system that extends a hybrid dual-retrieval architecture with domain-contextualized extraction, ontologies, and entity alignment, and exposes tools that enable human analysts and AI agents to query enriched threat intelligence during hypothesis generation.

  • 9 Jul 2026
  • Robert Heald

USB: Universal Security Breach or Uniquely Secured Bus? Assessing the Effectiveness of Windows 11 Group Policy at Controlling USB Device Installation for Budget-Constrained Security Teams

Research Paper

This study evaluates three progressively granular Windows 11 Group Policy (GPO) configurations—class-based blocking, VID/PID allowlisting, and Device Instance ID allowlisting—against legitimate business peripherals and a Hak5 USB Rubber Ducky configured as a composite BadUSB device, using the Windows 11 v25H2 Security Baseline as the unmodified reference state.

  • 22 Jun 2026
  • Kire Jacobson

Investigating Operating System Variations in IPv6 Implementations

Research Paper

This research tested the four most common operating system families, Windows, Linux, macOS, and BSD, for RFC compliance and behavioral differences across a controlled set of IPv6 test cases. Because RFC specifications leave many implementation details to the developer, behavior was expected to diverge, and the testing confirmed that it did.

  • 22 Jun 2026
  • Donovan Rodriguez

macOS Infostealer Exfiltration Techniques via Native Tooling: Behavioral Analysis and Defenses

Research Paper

This paper analyzes macOS infostealers and their reliance on native system utilities. The use of specific command-line options and arguments should be predictable and detectable with proper analysis.

  • 22 Jun 2026
  • Cory Findley

Detection Strategies for AskCreds Beacon Object File Credential Harvesting Across Multiple C2 Frameworks

Research Paper

This study evaluates layered detection strategies against AskCreds BOF execution in an isolated Azure lab using Cobalt Strike 4.12 and Outflank C2 v2.11.1, with Velociraptor as the primary DFIR platform.

  • 22 Jun 2026
  • Eric Fletcher

Capturing the Click: Process-Based Detection of Malicious Link Interactions

Research Paper

This research validates the browser command-line flags used by Chrome, Edge, and Firefox as parameters in process-creation events, capturing both the clicked URL and the parent application, document, or script that delivered it.

  • 22 Jun 2026
  • Daniel Gott

Know Your Blind Spots: Better Visibility Through EDR Policy Hardening

Research Paper

Endpoint Detection and Response (EDR) tools identify, detect, and respond to anomalous behavior.

  • 9 Jun 2026
  • Joshuah Williams