Skip to main content

Cybersecurity Research Papers

Master's degree candidates at SANS.edu conduct research that is relevant, has real world impact, and often provides cutting-edge advancements to the field of cybersecurity, all under the guidance and review of our world-class instructors.

Showing 12 of 803

USB: Universal Security Breach or Uniquely Secured Bus? Assessing the Effectiveness of Windows 11 Group Policy at Controlling USB Device Installation for Budget-Constrained Security Teams

Research PaperCyber Defense

This study evaluates three progressively granular Windows 11 Group Policy (GPO) configurations—class-based blocking, VID/PID allowlisting, and Device Instance ID allowlisting—against legitimate business peripherals and a Hak5 USB Rubber Ducky configured as a composite BadUSB device, using the Windows 11 v25H2 Security Baseline as the unmodified reference state.

  • 22 Jun 2026
  • Kire Jacobson

Investigating Operating System Variations in IPv6 Implementations

Research PaperCyber Defense

This research tested the four most common operating system families, Windows, Linux, macOS, and BSD, for RFC compliance and behavioral differences across a controlled set of IPv6 test cases. Because RFC specifications leave many implementation details to the developer, behavior was expected to diverge, and the testing confirmed that it did.

  • 22 Jun 2026
  • Donovan Rodriguez

macOS Infostealer Exfiltration Techniques via Native Tooling: Behavioral Analysis and Defenses

Research PaperCyber Defense

This paper analyzes macOS infostealers and their reliance on native system utilities. The use of specific command-line options and arguments should be predictable and detectable with proper analysis.

  • 22 Jun 2026
  • Cory Findley

Detection Strategies for AskCreds Beacon Object File Credential Harvesting Across Multiple C2 Frameworks

Research PaperDigital Forensics and Incident Response

This study evaluates layered detection strategies against AskCreds BOF execution in an isolated Azure lab using Cobalt Strike 4.12 and Outflank C2 v2.11.1, with Velociraptor as the primary DFIR platform.

  • 22 Jun 2026
  • Eric Fletcher

Capturing the Click: Process-Based Detection of Malicious Link Interactions

Research PaperDigital Forensics and Incident Response

This research validates the browser command-line flags used by Chrome, Edge, and Firefox as parameters in process-creation events, capturing both the clicked URL and the parent application, document, or script that delivered it.

  • 22 Jun 2026
  • Daniel Gott

Cloud Ace Journeys: The Analyst Flight Plan

Research PaperCloud Security

Cloud security analysts are responsible for securing environments, detecting threats, locking down identity, and responding to breach.

  • 18 Jun 2026
  • SANS Institute

2026 SANS SOC Survey Insights: A Decade of Evolution in Cyber Defense

Research PaperSecurity Awareness

SANS 2026 SOC Survey findings that dive into: where SOCs are investing, where they are struggling, and where the gap between high-performing teams and everyone else is widening.

  • 15 Jun 2026
  • Christopher Crowley

Securing the Sun: Impact-Effective Cybersecurity Controls for Solar SCADA

Research PaperIndustrial Control Systems Security

Based on research conducted with a custom-built lab emulating a utility-grade solar SCADA network, this paper details the greatest impact on a solar site, in the form of physical consequences to power generation capabilities.

  • 11 Jun 2026
  • Wesley D. Barrier

From Alert to Evidence: Evaluating AI Agents for Cyber Forensic Triage

Research PaperArtificial Intelligence

Cyber defense teams are beginning to experiment with large language models in security operations, but their usefulness in digital forensics and incident triage is still uncertain.

  • 11 Jun 2026
  • Connor Blackard

Know Your Blind Spots: Better Visibility Through EDR Policy Hardening

Research PaperDigital Forensics and Incident Response

Endpoint Detection and Response (EDR) tools identify, detect, and respond to anomalous behavior.

  • 9 Jun 2026
  • Joshuah Williams

Risk-Adaptive Data Loss Prevention: Behavioral Intelligence with DLP

Research PaperCyber Defense

Risk-Adaptive Data Loss Prevention: Behavioral Intelligence with DLP

  • 4 Jun 2026
  • Matt Bromiley

Bridging the Gap Between Threat Intelligence and Business Risk

Research PaperCyber Defense

The importance of the threat intelligence function has grown significantly over the years to become a cornerstone of any cybersecurity group.

  • 29 May 2026
  • Kevin Garvey