Threat Hunting in System Using Log Analysis
P Jyothi A, Chaithanya, Anirudh Shankar, Jr Ashwath Narayan, Aishwary Anurag, Skanda S Kumar · 2024
The research paper presents a proactive system security enhancement methodology called “Threat hunting in systems using log analysis.” This methodology employs various modules across different vectors to detect potential security breaches before they can cause significant harm. The initial module, “Threat Hunting in Event Logs,” utilizes advanced log analysis techniques to identify suspicious activities indicative of security threats. Subsequent modules focus on analyzing scheduled tasks, evaluating start-up entries, monitoring USB devices, and detecting hidden files, all of which contribute to a comprehensive approach to system security. The integration of Python scripting further enhances the effectiveness of the methodology by enabling automated analysis and detection of potential threats and vulnerabilities. By leveraging system logs for proactive threat detection, this methodology strengthens the resilience of computer systems against cyber threats. The methodology outlined in this paper contributes to the advancement of cybersecurity practices, emphasizing the importance of leveraging log analysis as a proactive defense mechanism against evolving cyber threats.