{"id":{"repo_id":"southwales","oai_identifier":"oai:pure.atira.dk:studenttheses/3dfe8c83-3cfd-461c-9b24-28e8513b868d"},"canonical_url":"https://search.dev.ndltd.org/etd/southwales/oai:pure.atira.dk:studenttheses/3dfe8c83-3cfd-461c-9b24-28e8513b868d","repository":{"repo_id":"southwales","name":"University of South Wales","base_url":"https://pure.southwales.ac.uk/ws/oai"},"display":{"title":"An Integrated Cyber Threat Hunting Program Applying Machine Learning for Enhanced Intelligence Capabilities","abstract":"This project entails the creation of a simplified event log filterer that can be used by new threat hunters to the field of threat intelligence. The event log filterer employs three filtering options that allow the threat hunter to analyse application, system, security and Sysmon logs, which are the most common logs used for hunting for threats. This tool was created to allow new users to get to grips with threat hunting without the need go through the hundreds of unnecessary logs that Windows Event Viewer collects and displays and the array of options that may seem overwhelming to those starting out in this field. The tool also analyses Sysmon logs using anomaly spike detection machine learning to highlight any logs that may be anomalous and should be investigated further. The idea of this is to allow the new threat hunter to pinpoint which Sysmon logs require attention, whereas the conventional Windows Event Viewer approach does not afford this anomaly detection and is a laborious task to sift through all the logs looking for anomalies, which is difficult for experienced hunters, let alone novices.","abstract_html":"This project entails the creation of a simplified event log filterer that can be used by new threat hunters to the field of threat intelligence. The event log filterer employs three filtering options that allow the threat hunter to analyse application, system, security and Sysmon logs, which are the most common logs used for hunting for threats. This tool was created to allow new users to get to grips with threat hunting without the need go through the hundreds of unnecessary logs that Windows Event Viewer collects and displays and the array of options that may seem overwhelming to those starting out in this field. The tool also analyses Sysmon logs using anomaly spike detection machine learning to highlight any logs that may be anomalous and should be investigated further. The idea of this is to allow the new threat hunter to pinpoint which Sysmon logs require attention, whereas the conventional Windows Event Viewer approach does not afford this anomaly detection and is a laborious task to sift through all the logs looking for anomalies, which is difficult for experienced hunters, let alone novices.","abstract_has_math":false,"creators":["Richards, Joshua"],"institution":null,"degree_name":"Master's Thesis","degree_level":"Student thesis","degree_discipline":null,"degree_department":null,"school":null,"contributors":[],"advisors":["Ward, Richard"],"committee_chairs":[],"committee_members":[],"year":2021,"date_issued":"2021-9","date_published":"2021-9","updated_at":"2026-07-24T04:39:51Z","subjects":["Anomaly","Events","Detection","Logs","Machine Learning","Threat Hunting"],"languages":["eng"],"rights":[],"rights_urls":[],"identifier_entries":[{"key":"dc:identifier","label":"Identifier","values":["oai:pure.atira.dk:studenttheses/3dfe8c83-3cfd-461c-9b24-28e8513b868d"],"render_values":[{"text":"oai:pure.atira.dk:studenttheses/3dfe8c83-3cfd-461c-9b24-28e8513b868d","href":null,"code":true}]}]},"links":{"outbound_url":"https://pure.southwales.ac.uk/en/studentTheses/3dfe8c83-3cfd-461c-9b24-28e8513b868d","outbound_label":"Repository record","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Ward, Richard"]},{"key":"dc:creator","label":"Author","values":["Richards, Joshua"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2021-9"]},{"key":"dc:date.issued","label":"Date","values":["2021-9"]},{"key":"dc:relation.isreferencedby","label":"Dc Relation Isreferencedby","values":["https://pure.southwales.ac.uk/en/studentTheses/3dfe8c83-3cfd-461c-9b24-28e8513b868d"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"dc:type.qualificationlevel","label":"Dc Type Qualificationlevel","values":["Student thesis"]},{"key":"dc:type.qualificationname","label":"Dc Type Qualificationname","values":["Master's Thesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Anomaly","Events","Detection","Logs","Machine Learning","Threat Hunting"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["eng"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["oai:pure.atira.dk:studenttheses/3dfe8c83-3cfd-461c-9b24-28e8513b868d","https://pure.southwales.ac.uk/en/studentTheses/3dfe8c83-3cfd-461c-9b24-28e8513b868d"]},{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://pure.southwales.ac.uk/files/9872387/MSc_Thesis_Joshua_Richards.pdf"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["This project entails the creation of a simplified event log filterer that can be used by new threat hunters to the field of threat intelligence. The event log filterer employs three filtering options that allow the threat hunter to analyse application, system, security and Sysmon logs, which are the most common logs used for hunting for threats. This tool was created to allow new users to get to grips with threat hunting without the need go through the hundreds of unnecessary logs that Windows Event Viewer collects and displays and the array of options that may seem overwhelming to those starting out in this field. The tool also analyses Sysmon logs using anomaly spike detection machine learning to highlight any logs that may be anomalous and should be investigated further. The idea of this is to allow the new threat hunter to pinpoint which Sysmon logs require attention, whereas the conventional Windows Event Viewer approach does not afford this anomaly detection and is a laborious task to sift through all the logs looking for anomalies, which is difficult for experienced hunters, let alone novices."]},{"key":"dc:title","label":"Title","values":["An Integrated Cyber Threat Hunting Program Applying Machine Learning for Enhanced Intelligence Capabilities"]}]}],"canonical_facts":{"dc:contributor.advisor":["Ward, Richard"],"dc:creator":["Richards, Joshua"],"dc:date":["2021-9"],"dc:date.issued":["2021-9"],"dc:description.abstract":["This project entails the creation of a simplified event log filterer that can be used by new threat hunters to the field of threat intelligence. The event log filterer employs three filtering options that allow the threat hunter to analyse application, system, security and Sysmon logs, which are the most common logs used for hunting for threats. This tool was created to allow new users to get to grips with threat hunting without the need go through the hundreds of unnecessary logs that Windows Event Viewer collects and displays and the array of options that may seem overwhelming to those starting out in this field. The tool also analyses Sysmon logs using anomaly spike detection machine learning to highlight any logs that may be anomalous and should be investigated further. The idea of this is to allow the new threat hunter to pinpoint which Sysmon logs require attention, whereas the conventional Windows Event Viewer approach does not afford this anomaly detection and is a laborious task to sift through all the logs looking for anomalies, which is difficult for experienced hunters, let alone novices."],"dc:identifier":["oai:pure.atira.dk:studenttheses/3dfe8c83-3cfd-461c-9b24-28e8513b868d","https://pure.southwales.ac.uk/en/studentTheses/3dfe8c83-3cfd-461c-9b24-28e8513b868d"],"dc:identifier.uri":["https://pure.southwales.ac.uk/files/9872387/MSc_Thesis_Joshua_Richards.pdf"],"dc:language":["eng"],"dc:relation.isreferencedby":["https://pure.southwales.ac.uk/en/studentTheses/3dfe8c83-3cfd-461c-9b24-28e8513b868d"],"dc:subject":["Anomaly","Events","Detection","Logs","Machine Learning","Threat Hunting"],"dc:title":["An Integrated Cyber Threat Hunting Program Applying Machine Learning for Enhanced Intelligence Capabilities"],"dc:type":["Thesis"],"dc:type.qualificationlevel":["Student thesis"],"dc:type.qualificationname":["Master's Thesis"]},"updated_at":"2026-07-24T04:39:51Z"}