遇见数据集

Forensic Value of Enhanced Endpoint Telemetry in Active Directory Attack Detection: A Controlled Comparative Study

收藏
Zenodo2026-06-10 更新2026-06-12 收录
官方服务:

资源简介:

Experimental dataset evaluating Wazuh SIEM detection performance for Kerberoasting (T1558.003), AS-REP Roasting (T1558.004), and DCSync (T1003.006) attacks in a controlled Active Directory laboratory. Includes 30 attack run CSVs, Wazuh alert screenshots, BloodHound pre/post remediation graphs, custom detection rules, Sysmon configuration, and full statistical analysis across two logging conditions (native Windows Security channel vs Sysmon+Wazuh enhanced telemetry).

提供机构:
Zenodo
创建时间:
2026-06-09
二维码
社区交流群
二维码
科研交流群
商业服务