The Invisible Checkpoint: Passive LTE Traffic Capture for Mobile Malware Detection
This paper presents a privacy-preserving, field-deployable framework for passive mobile malware detection that uses an LTE-connected laptop with a controlled Wi-Fi hotspot, migrating the passive-inspection model of TinyCheck and SpyGuard from resource-constrained hardware to a scalable platform running Suricata and Zeek.
SANS-Invisible-Checkpoint-Sinanian (PDF, 4.19MB)
11 Aug 2026Related Content
Beyond the Tunnel: A Lab-Based Comparative Evaluation of Network-Layer VPN and Identity-Aware Reverse Proxy Architectures Against the CISA Zero Trust Maturity Model
Research PaperFor the Applications and Data pillars, the results depend primarily on the security features bundled with each product and its platform, and the two architectures converge on Identity because both draw their authentication strength from the same identity provider. The study contributes a repeatable methodology and a scored matrix that shows where the architectures genuinely diverge.
- 17 Sep 2026
- Henry Cheung
Assessing the Feasibility and Effectiveness of AI in CTI-Driven Threat Hunting
Research PaperThis study evaluates three commercial LLMs, OpenAI GPT-4o, Google Gemini, and Microsoft Copilot, against ten recent CTI reports, measuring indicator extraction accuracy and validating generated Kusto Query Language (KQL) and CrowdStrike Query Language (CQL) hunting queries in Microsoft Sentinel and CrowdStrike NG-SIEM.
- 17 Sep 2026
- Devron West
Evaluating LLMs as a Bridge Between Cyber Threats and Business Risk for Executive Decision-Making
Research PaperSecurity leaders cannot act on intelligence they cannot understand, yet most cyber threat intelligence (CTI) reporting is written for analysts, not executives.
- 11 Aug 2026
- Arcadio Aguilar
Entra ID Governance: Insta-IAM/IGA Solution?
Research PaperThis research evaluates the viability of using Entra ID Governance as a primary IAM/IGA solution through a proof-of-concept implementation modeled on a moderately complex organization with multiple systems of record.
- 6 Aug 2026
- Scott Fortin
Reconstructing Deleted File Activity Using FSEvents from macOS
Research PaperThis paper examines the role of FSEvents as a source of historical file system activity, particularly in scenarios where files are no longer present on disk.
- 30 Jul 2026
- Josh Clevenger
Benchmarking Free-Tier Large Language Models as Cognitive Aids for Operationalizing Unstructured Cyber Threat Intelligence
Research PaperModern Security Operations Centers (SOCs) face a deepening burnout crisis.
- 20 Jul 2026
- Jose "Ricky" Banda
Evaluating the Detection Effectiveness of Network Monitoring Tools Against Modern Command-and-Control Frameworks
Research PaperThis research measures the effectiveness of Zeek, Suricata, and Security Onion against representative modern C2 frameworks in a controlled laboratory environment.
- 9 Jul 2026
- Joseph Zderadicka
Practical MFA for the Enterprise: Enforcing Strong Authentication for Non-Human Identities Using Compensating Controls
Research PaperThis paper’s case study examined a production Microsoft Entra ID environment at a large North American organization encompassing more than 500 app registrations and 21,000 directory accounts.
- 9 Jul 2026
- Fredrick Stock
Cyber Intelligence GraphRAGs for Behavioral Detection
Research PaperThis paper introduces chatAPT, a prototype graphRAG system that extends a hybrid dual-retrieval architecture with domain-contextualized extraction, ontologies, and entity alignment, and exposes tools that enable human analysts and AI agents to query enriched threat intelligence during hypothesis generation.
- 9 Jul 2026
- Robert Heald
USB: Universal Security Breach or Uniquely Secured Bus? Assessing the Effectiveness of Windows 11 Group Policy at Controlling USB Device Installation for Budget-Constrained Security Teams
Research PaperThis study evaluates three progressively granular Windows 11 Group Policy (GPO) configurations—class-based blocking, VID/PID allowlisting, and Device Instance ID allowlisting—against legitimate business peripherals and a Hak5 USB Rubber Ducky configured as a composite BadUSB device, using the Windows 11 v25H2 Security Baseline as the unmodified reference state.
- 22 Jun 2026
- Kire Jacobson
Investigating Operating System Variations in IPv6 Implementations
Research PaperThis research tested the four most common operating system families, Windows, Linux, macOS, and BSD, for RFC compliance and behavioral differences across a controlled set of IPv6 test cases. Because RFC specifications leave many implementation details to the developer, behavior was expected to diverge, and the testing confirmed that it did.
- 22 Jun 2026
- Donovan Rodriguez
macOS Infostealer Exfiltration Techniques via Native Tooling: Behavioral Analysis and Defenses
Research PaperThis paper analyzes macOS infostealers and their reliance on native system utilities. The use of specific command-line options and arguments should be predictable and detectable with proper analysis.
- 22 Jun 2026
- Cory Findley
Detection Strategies for AskCreds Beacon Object File Credential Harvesting Across Multiple C2 Frameworks
Research PaperThis study evaluates layered detection strategies against AskCreds BOF execution in an isolated Azure lab using Cobalt Strike 4.12 and Outflank C2 v2.11.1, with Velociraptor as the primary DFIR platform.
- 22 Jun 2026
- Eric Fletcher
Capturing the Click: Process-Based Detection of Malicious Link Interactions
Research PaperThis research validates the browser command-line flags used by Chrome, Edge, and Firefox as parameters in process-creation events, capturing both the clicked URL and the parent application, document, or script that delivered it.
- 22 Jun 2026
- Daniel Gott
Know Your Blind Spots: Better Visibility Through EDR Policy Hardening
Research PaperEndpoint Detection and Response (EDR) tools identify, detect, and respond to anomalous behavior.
- 9 Jun 2026
- Joshuah Williams
Applying CIS Controls to AI Workflows
Research PaperThis research provides guidance on using the CIS Controls in conjunction with AI-specific frameworks to build a robust information security program.
- 12 May 2026
- Brian Ventura
A Forensic Study of Artifact Persistence in Containerd-Based Kubernetes Workloads
Research PaperA container is a standard unit of software that packages code, including its dependencies, so the application runs quickly and reliably across computing environments.
- 12 May 2026
- Ahmed Alharbi
Untested: An Overlooked Link in the Software Supply Chain
Research PaperThis research explores test code as an attack surface and takes a first step toward creating a tool to help analysts detect and mitigate malware lurking in test libraries.
- 16 Apr 2026
- Evan Ottinger
Cyber Risk Intelligence and Security Posture (CRISP): From Compliance to Threat-Informed Intelligence
Research PaperThis paper presents CRISP (Cyber Risk Intelligence & Security Posture), a platform that automates the transformation of STIG compliance data into threat-informed security intelligence.
- 7 Apr 2026
- Eric Kaden
Operationalizing CTEM within the SOC: A Proactive Approach to Threat Detection and Response
Research PaperWith either an in-house or an outsourced approach, organizations invest in a security operations center (SOC) to perform threat detection, investigation, and response. SOCs may also leverage threat hunting to identify threats earlier and proactively reduce risk.
- 1 Apr 2026
- Jay Yaneza
