SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsLinux systems have become foundational across modern IT enterprises. Threat actors are increasingly targeting Linux systems, including well - known advanced persistent threats (APTs) such as Sandworm. This research evaluates the effectiveness of Sysmon for Linux in detecting Sandworm tactics, techniques, and procedures (TTPs) compared to the more established Linux audit subsystem (auditd).

















