papersTODAY 04:00 UTC
SENTINEL framework targets living-off-the-land APT attacks on Windows command lines
A new arXiv paper introduces SENTINEL, a detection architecture that combines multiple analysis pathways to catch advanced persistent threat activity on Windows. The work focuses on living-off-the-land techniques, where attackers abuse built-in Windows utilities instead of deploying custom malware. According to the abstract, such abuse is a leading evasion method used in state-sponsored campaigns.