EILMELDUNGEN LIVE
🔧 ProgrammierungGitHub Release: google-gemini/gemini-cli v0.57.0 (25.08.2026)(25.08.2026 um 20:37 Uhr)
🪟 Windows TippsWindows 11: Nach Apples Erfolg ändert auch Microsoft den Kurs(26.08.2026 um 09:55 Uhr)
🪟 Windows TippsGute Nachrichten für Windows-11-Nutzer mit einem Android-Handy(27.08.2026 um 09:12 Uhr)
🔧 AI Nachrichten GitHub Release: can1357/oh-my-pi v18.0.4 (24.08.2026)(24.08.2026 um 06:05 Uhr)
🔧 ProgrammierungThis Week In Rust: This Week in Rust 666(26.08.2026 um 06:00 Uhr)
🕵️ SicherheitslückenLSN-0121-1: Kernel Live Patch Security Notice(27.08.2026 um 12:07 Uhr)
🕵️ SicherheitslückenUSN-8684-1: Perl vulnerabilities(27.08.2026 um 13:10 Uhr)
🕵️ SicherheitslückenUSN-8686-1: openCryptoki vulnerabilities(27.08.2026 um 16:43 Uhr)
🕵️ SicherheitslückenUSN-8687-1: p11-kit vulnerabilities(27.08.2026 um 17:20 Uhr)
🔧 ProgrammierungGitHub Release: google-gemini/gemini-cli v0.57.0 (25.08.2026)(25.08.2026 um 20:37 Uhr)
🪟 Windows TippsWindows 11: Nach Apples Erfolg ändert auch Microsoft den Kurs(26.08.2026 um 09:55 Uhr)
🪟 Windows TippsGute Nachrichten für Windows-11-Nutzer mit einem Android-Handy(27.08.2026 um 09:12 Uhr)
🔧 AI Nachrichten GitHub Release: can1357/oh-my-pi v18.0.4 (24.08.2026)(24.08.2026 um 06:05 Uhr)
🔧 ProgrammierungThis Week In Rust: This Week in Rust 666(26.08.2026 um 06:00 Uhr)
🕵️ SicherheitslückenLSN-0121-1: Kernel Live Patch Security Notice(27.08.2026 um 12:07 Uhr)
🕵️ SicherheitslückenUSN-8684-1: Perl vulnerabilities(27.08.2026 um 13:10 Uhr)
🕵️ SicherheitslückenUSN-8686-1: openCryptoki vulnerabilities(27.08.2026 um 16:43 Uhr)
🕵️ SicherheitslückenUSN-8687-1: p11-kit vulnerabilities(27.08.2026 um 17:20 Uhr)

29 🕛 kürzlich 2 Min Lesezeit 10 Leser online ️ CVE-RADAR
0

Black Hat Asia 2026 | Graph-Aware LLM for Windows Logon with a Closed-Loop Guarded Detection Agent

↗ Quelle (YouTube · Black Hat)
🗣️ Stimme:
📺
YouTube · Black Hat
25 YouTube-Aufrufe
Because Windows Event Logs were never originally designed for detecting unauthorized logons, traces of attacks are easily buried in a massive amount of noise. It is also inherently difficult to create reliable signatures for suspicious log entries in Windows Event Logs, and research on analysis methods has been ongoing for many years. In recent years, the use of LLMs for log analysis has advanced; however, in real-world investigations, log sizes often exceed hundreds of gigabytes. In such cases, prompts quickly become too large, making it impractical to apply LLMs directly. In addition, hallucinated explanations and lack of reproducibility remain key challenges when using LLMs in security operations.

In this Briefing, we will present a practical, production-ready framework that combines graph analytics with LLM agents to accurately detect suspicious logons. Concretely, we compress logs into graph information by constructing an authentication graph of users and hosts from Windows Event Logs. This makes it possible to reduce the data to a realistic size that can actually be fed to an LLM. On top of that, a closed-loop detection agent autonomously iterates the cycle of generating search queries to a database → executing the queries → evaluating the results → exploring further. Through this loop, it detects signs such as concentrations of service tickets, cross-host logons by privileged accounts, remote service access, and suspicious chains of logons. The outcome of the analysis is presented as an incident severity level, an evidence timeline, and an attack scenario summary, automatically providing information that can be directly used in real incident investigations.

Our approach aggregates millions of events down to a few dozen suspicious logons within minutes, and elevates LLM usage in DFIR into a form that is auditable, reproducible, and operationally viable. We will release an open-source tool that implements this method so that analysts can apply it to real-world incident analysis.

Shusei Tomonaga | CTO, JPCERT/CC

https://blackhat.com/asia-26/briefings/schedule/?#graph-aware-llm-for-windows-logon-with-a-closed-loop-guarded-detection-agent-50039
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
144 Fachleser & IT-Security Experten haben diesen Report heute geteilt
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 52%
🟡 In Evaluierung 32%
🟢 Keine Auswirkung 11%
Spannende Innovation 5%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
2 Quellen
GitHub Release: google-gemini/gemini-cli v0.57.0 (25.08.2026)
2 Quellen
The Rust Programming Language Blog: Announcing our first Maintainers in Residence
1 Quelle
Windows 11: Nach Apples Erfolg ändert auch Microsoft den Kurs