Anomalous Executable Files Detection Using Random Forest Classification with SIEM Integration
Waqas Ahmad, Usama Mustafa, Faiz Ul Islam, Muhammad Faisal Amjad · 2025
Malware will eventually be one of the significant threats to the computer realm. It is utilized for the purpose of unauthorized access and extraction of classified information. There has been a huge explosion in terms of internet coverage, thus enabling people to download files and install executables such as .bat, .msi, and .exe files, among others. These scenarios consequently lead to numerous complications because these are the channels through which offensive code rides on. This paper presented a technique to identify anomalous executable files (exe files) through a thorough examination of the Portable Executable (PE) files that are associated with the exe files. We employed a machine learning model using a Random Forest classifier that classifies anomalous and benign files, achieving 99.45% accuracy. The dataset we are employing comprises 70% malware and 30% benign files. This solution is deployed on the network side to detect anomalous executable files and send the detection details to the Security Information and Event Management (SIEM) solution. The proposed solution will help the Security Operation Center (SOC) analyst and threat-hunting teams.