This research examines the effectiveness of using Elasticsearch, Kibana, and Lucene for an intelligence-driven threat hunting to identify attack infrastructure or a Command & Control (C2) server.
Abstract
The increasingly advanced forms of cyber-attacks have highlighted the importance of advanced threat hunting as a necessary skillset. The current research examines the effectiveness of using Elasticsearch, Kibana, and Lucene for an intelligence-driven threat hunting to identify attack infrastructure or a Command & Control (C2) server. By aggregating all system traffic logs and security artifacts into a single data lake/warehouse, organizations are able to leverage centralized analysis of information from different sources on a corporate scale. Utilizing Kibana’s ability to perform network and log analysis, using Lucene’s rich syntax to make sophisticated queries will empower individuals to make valuable findings from log and network traffic logs that identify behaviours and patterns typical of C2 activities. A novel intelligence-based threat hunting approach is presented here that utilizes Elasticsearch, with domain-specific language additions to refine search queries and investigate for C2 related activity. A detailed analysis of the research based on real-world datasets is conducted to evaluation the threat hunting framework’s abilities in detecting C2 servers and minimize true/false positives in relation to organizational security concerns.
The presented framework manages to incorporate explainable scoring, convergence of behavior analysis, adaptive control, environment mutation, and reinforcement learning into one cyber deception framework and manages to incorporate all of these features while still preserving transparency and adaptability during the whole process of deception.
S. Roy, G. Khekare, Sejal Chhajed· Scientific Reports· 0 citations
This review provides a novel synthesis of recent Large Language Model applications in threat hunting and identifies critical research gaps, and presents a refined perspective on the practical implementation and future trajectory of these technologies.
Three research directions for automating the production of shareable intelligence are derived from a literature survey of academic papers, organizing the CTI lifecycle into three stages: Threat Data Collection, CTI Generation and Sharing, and CTI Consumption.
Saastha Vasan, Hadjer Benkraouda, Jizhou Chen et al.· 0 citations
Working baseline levels of capability are provided with respect to current LLM-based solutions in 6G mission-critical and public safety contexts, and specific research directions to advance LLM-driven cybersecurity toward robust, adaptable, explainable, and life-safety-aware solutions are mapped out.
Siva Sai, Bhuvan Arora, Vineet Suri et al.· IEEE Open Journal of the Com...· 1 citation
This project asks whether feeding a report into a knowledge-graph retrieval system, Microsoft GraphRAG, rather than a standard vector-similarity retrieval system (Naive RAG), produces detection plans that rely more on these durable, top-of-pyramid clues.
A. Kabra, Prakhar Paliwal, M. Hanawal· 0 citations
Experimental results show that LLMs, when guided by rubric-based prompts and supplemented with ATT&CK domain knowledge, achieve robust performance across detection, localization, and TTP mapping tasks.
Joon-Young Gwak, Aubrey Strier, Zhaohan Xi et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.