Detecting random filenames using (un)supervised machine learning
ID: 532b520d-3984-5985-a485-d6376740ff66
STIX ID: report--532b520d-3984-5985-a485-d6376740ff66
Feed Name: Fox-IT blog
This blog post describes Fox-IT’s approach to detecting random filenames—a potential sign of lateral movement—by combining an unsupervised bigrams model and a supervised random forest trained on SMB filename data. The authors collected ~180,000 real filenames and 1,000 synthetic random examples, stripped extensions, and achieved detection rates of ~71% for the bigrams model and ~81% for the random forest (F1 scores 0.83 and 0.89) with very low false positive rates; combining both models yields an estimated ~90% detection. The post recommends deploying both models cooperatively in a SOC and suggests future work applying the methods to endpoint data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
