• Open Access IconOpen Access
  • Cite Icon49
  • https://doi.org/10.1145/3199478.3199490Copy DOI Icon

Data-Driven Threat Hunting Using Sysmon

  • Mar 16, 2018
  • Vasileios Mavroeidis +1 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Threat actors can be persistent, motivated and agile, and leverage a\ndiversified and extensive set of tactics and techniques to attain their goals.\nIn response to that, defenders establish threat intelligence programs to stay\nthreat-informed and lower risk. Actionable threat intelligence is integrated\ninto security information and event management systems (SIEM) or is accessed\nvia more dedicated tools like threat intelligence platforms. A threat\nintelligence platform gives access to contextual threat information by\naggregating, processing, correlating, and analyzing real-time data and\ninformation from multiple sources, and in many cases, it provides centralized\nanalysis and reporting of an organization's security events. Sysmon logs is a\ndata source that has received considerable attention for endpoint visibility.\nApproaches for threat detection using Sysmon have been proposed, mainly\nfocusing on search engine technologies like NoSQL database systems. This paper\ndemonstrates one of the many use cases of Sysmon and cyber threat intelligence.\nIn particular, we present a threat assessment system that relies on a cyber\nthreat intelligence ontology to automatically classify executed software into\ndifferent threat levels by analyzing Sysmon log streams. The presented system\nand approach augments cyber defensive capabilities through situational\nawareness, prediction, and automated courses of action.\n

Similar Papers
  • Research Article

Optimizing Threat Intelligence Sharing Across Multiple Security Platforms

  • Nov 30, 2025
  • The American Journal of Engineering and Technology
  • John Komarthi
  • Research Article
  • Citations27

Generating Quality Threat Intelligence Leveraging OSINT and a Cyber Threat Unified Taxonomy

  • May 19, 2022
  • ACM Transactions on Privacy and Security
  • Cláudio Martins +1
  • PDF
  • Research Article
  • Citations15

Generative AI for cyber threat intelligence: applications, challenges, and analysis of real-world case studies

  • Aug 20, 2025
  • Artificial Intelligence Review
  • Prasasthy Balasubramanian +6
  • PDF
  • Research Article
  • Citations4

Weighted quality criteria for cyber threat intelligence: assessment and prioritisation in the MISP data model

  • Jun 19, 2025
  • International Journal of Information Security
  • Dimitrios Chatziamanetoglou +1
  • Book Chapter

CloudWall: A Cloud-enabled Resiliency Framework for HealthCare IT Infrastructures

  • Jan 01, 2021
  • Colección Jornadas y congresos
  • Ivan Marsa-Maestre +6
  • Research Article

Cyber Threat Intelligence Platform for Real-Time Attack Detection using SIEM

  • Jun 30, 2025
  • International Journal of Research and Development in Engineering Sciences
  • Obulakonda Reddy R +4
  • PDF
  • Research Article
  • Citations42

Distributed Security Framework for Reliable Threat Intelligence Sharing

  • Aug 01, 2020
  • Security and Communication Networks
  • Davy Preuveneers +3
  • Research Article
  • Citations34

Cyber Threat Intelligence for Improving Cybersecurity and Risk Management in Critical Infrastructure

  • Nov 28, 2019
  • Journal of Universal Computer Science
  • Halima Ibrahim Kure +1
  • PDF
  • Research Article
  • Citations8

Attack Behavior Extraction Based on Heterogeneous Cyberthreat Intelligence and Graph Convolutional Networks

  • Jan 01, 2023
  • Computers, Materials & Continua
  • Binhui Tang +5
  • Research Article

Framework for Monitoring Malicious Channels in Phishing Campaigns: A Cyber Threat Intelligence Perspective

  • Jun 15, 2025
  • International Journal of Electrical and Computer Engineering Research
  • Ivo Ricardo Dias Rosa
  • Book Chapter
  • Citations25

An Overview of Cyber Threat Intelligence Platform and Role of Artificial Intelligence and Machine Learning

  • Jan 01, 2020
  • Abir Dutta +1
  • Book Chapter
  • Citations2

Data Privacy Implications for Security Information and Event Management Systems and Other Meta-Systems

  • Jan 01, 2013
  • Herah Khan +1
  • Supplementary Content

Threat Intelligence Platforms evaluation

  • May 21, 2021
  • Filippos Papaioannou +1
  • Research Article
  • Citations1

Explainable AI for Cyber Threat Intelligence and Risk Assessment

  • Jan 01, 2020
  • Journal of Frontiers in Multidisciplinary Research
  • Ehimah Obuse +6
  • Book Chapter
  • Citations4

Dynamical Attack Simulation for Security Information and Event Management

  • Dec 05, 2013
  • Igor Kotenko +3
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.