2022
DOI: 10.20944/preprints202207.0176.v1
|View full text |Cite
Preprint
|
Sign up to set email alerts
|

Revisiting the Detection of Lateral Movement through Sysmon

Abstract: This work attempts to answer in a clear way the following key questions regarding the optimal initialization of the Sysmon tool, towards the identification of Lateral Movement in the MS Windows ecosystem. First, from an expert’s standpoint and with reference to the relevant literature, what are the criteria of determining the possibly optimal initialization features of the Sysmon’s event monitoring tool, which are also applicable as custom rules within the config.xml configuration file? Sec… Show more

Help me understand this report
View published versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

0
4
0

Year Published

2023
2023
2024
2024

Publication Types

Select...
1
1

Relationship

2
0

Authors

Journals

citations
Cited by 2 publications
(4 citation statements)
references
References 10 publications
0
4
0
Order By: Relevance
“…In comparison to the relevant literature, which is rather scarce, the present work offers a solid, as it concerns both theoretical and empirical viewpoint, process for selecting the most appropriate classification features and data preprocessing methods towards the elimination of overfitting and the implementation of accurate and well-generalized ML models. To aid the evaluation of ML models, the LMD-2022 log-based dataset was enhanced into the LMD-2023 [26] version and implemented as element of investigation in the conducted experiments. Moreover, it is demonstrated that datasets created from the extraction of Sysmon logs into the CSV format can be quite effective, even in multiclass classification, if just trained with a bare minimum of high importance features.…”
Section: Discussionmentioning
confidence: 99%
See 3 more Smart Citations
“…In comparison to the relevant literature, which is rather scarce, the present work offers a solid, as it concerns both theoretical and empirical viewpoint, process for selecting the most appropriate classification features and data preprocessing methods towards the elimination of overfitting and the implementation of accurate and well-generalized ML models. To aid the evaluation of ML models, the LMD-2022 log-based dataset was enhanced into the LMD-2023 [26] version and implemented as element of investigation in the conducted experiments. Moreover, it is demonstrated that datasets created from the extraction of Sysmon logs into the CSV format can be quite effective, even in multiclass classification, if just trained with a bare minimum of high importance features.…”
Section: Discussionmentioning
confidence: 99%
“…The work ended with the presentation and evaluation of the Python_Evtx_Analyzer -(PeX) EDR tool, which incorporated the aforementioned EDR-policy's criteria. The tool manipulates Sysmon files in their raw EVTX form, which are then iterated over the presented EDR policy's features to reveal the existence of potential malicious LM activity (Python_Evtx_Analyzer -(PeX)) tool is publicly available on GitHub [23].…”
Section: Key Observationsmentioning
confidence: 99%
See 2 more Smart Citations