Forensic Value of Enhanced Endpoint Telemetry in Active Directory Attack Detection: A Controlled Comparative Study
收藏官方服务:
资源简介:
Experimental dataset evaluating Wazuh SIEM detection performance for Kerberoasting (T1558.003), AS-REP Roasting (T1558.004), and DCSync (T1003.006) attacks in a controlled Active Directory laboratory. Includes 30 attack run CSVs, Wazuh alert screenshots, BloodHound pre/post remediation graphs, custom detection rules, Sysmon configuration, and full statistical analysis across two logging conditions (native Windows Security channel vs Sysmon+Wazuh enhanced telemetry).
提供机构:
Zenodo创建时间:
2026-06-09



