Contact Sales
Contact Sales

Enhancing Linux Threat Detection: A Sysmon - Based Approach to Identifying Sandworm TTPs

Enhancing Linux Threat Detection: A Sysmon - Based Approach to Identifying Sandworm TTPs (PDF, 0.45MB)Published: 20 Mar, 2026
Created by:
Joshua Keller

Linux systems have become foundational across modern IT enterprises. Threat actors are increasingly targeting Linux systems, including well - known advanced persistent threats (APTs) such as Sandworm. This research evaluates the effectiveness of Sysmon for Linux in detecting Sandworm tactics, techniques, and procedures (TTPs) compared to the more established Linux audit subsystem (auditd).

Enhancing Linux Threat Detection: A Sysmon - Based Approach to Identifying Sandworm TTPs | SANS Institute