Skip to content

Methods For Identifying Living-Off-The-Land Attacks Using Sysmon Telemetry Analysis And Machine Learning Models

Sep 2026 · Communications of International Proceedings · 0 citations

TL;DR

A proprietary methodology for identifying LOLBin abuse in Windows environments, based on telemetry collected by Sysmon and machine learning models is presented, which indicates that incorporating the context of natural user behavior significantly reduces the number of false alarms and increases the effectiveness of detection for unknown attack variants.

Abstract

Modern advanced cyber attacks increasingly use native operating system tools to hide their presence and bypass security mechanisms. One popular technique is living-off-the-land binaries (LOLBins), which make classic signature-based detection difficult. This article presents a proprietary methodology for identifying LOLBin abuse in Windows environments, based on telemetry collected by Sysmon and machine learning models. The research was conducted in a controlled virtual machine environment, where attack scenarios were carried out using PowerShell commands and selected LOLBins, while generating a realistic user activity profile. The recorded logs were processed, labeled, and analyzed for features, and then used in the training process of classification models such as Random Forest and XGBoost. The results indicate that incorporating the context of natural user behavior significantly reduces the number of false alarms and increases the effectiveness of detection for unknown attack variants. The article discusses the process of creating a test environment, the data processing procedure, the selection of input features, and the results of comparing different algorithms. The limitations of the presented solution and future research directions are also indicated, including the extension of scenarios to other system platforms and integration with SIEM-type tools.

View source

Similar papers

Review

ma-Does the implementation of machine-learning-based anomaly detection increase the risk of system latency and false-positive trips in automated smart grid controllers compared to traditional regex-based filtering?

The findings indicate that hybrid-based approach to architecture should be suggested, where rule-based filtering is applied to address the time-sensitive deterministic checks, and the ML models give the context-driven anomaly analysis on both the SCADA and the wide-area layers.

Wenxuan Cao · 0 citations
Open access Nov 2026

Detection of attacks on computer networks using machine learning – predictive model

Intrusion detection systems based on machine learning achieve high effectiveness under optimal testing conditions. However, real environments come with limitations such as changing data characteristics, previously unknown attacks or low and delayed label availability. To address these challenges, this paper proposed an...

Julia Stępień, I. El Fray · 0 citations
Review Open access Aug 2026

Does the implementation of machine-learning-based anomaly detection increase the risk of system latency and false-positive trips in automated smart grid controllers compared to traditional regex-based filtering?

The findings indicate that hybrid-based approach to architecture should be suggested, where rule-based filtering is applied to address the time-sensitive deterministic checks, and the ML models give the context-driven anomaly analysis on both the SCADA and the wide-area layers.

Wenxuan Cao · 0 citations
Open access Aug 2026

Enhancing Network Security with a Hybrid Intrusion Detection System Using SVM

A thorough analysis of a modest version of a suggested system that use Support Vector Machines (SVM) to address networking anomaly and misuse detection in the face of insurmountable obstacles, foreseeing an all-encompassing solution to modern network security issues.

Gaurav Kishor Saxena, Shambhu Dayal Sahu · 0 citations
Conference Open access Dec 2023

Detecting DDoS Attacks in the Internet of Medical Things Through Machine Learning Based Classification

The healthcare industry has witnessed a significant transformation due to the emergence of open-source medical cyber-physical systems, primarily driven by advancements in 3D printing technology. However, the growing use of these open-source systems in hospitals has also brought about cybersecurity concerns. In particul...

Brandon Peddle, Wei Lu, Qiao-Yan Yu · 1 citation
Aug 2026

An approach to protecting corporate networks from DDoS attacks based on machine learning and neural networks

The purpose of this study is to develop an approach for implementing DDoS protection mechanisms in corporate networks using a decision-making system based on machine learning methods. The proposed DDoS attack detection process comprises several stages, including data collection and analysis, model training, feature sel...

A. A. Alekseeva, L. Safiullina, A. M. Sadykov · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.