This year marks three years since we published our CTU-SME-11 dataset: 11 devices, 7 days, 99 million expert-labeled network flows with real benign and malicious traffic. 🔗 Explore the dataset: doi.org/10.5281/zeno...
Sebastian Garcia
@eldraco.bsky.social
Cybersecurity Researcher and Assist Prof in ČVUT University. Machine Learning. AI. Detection with IDS/IPS in the network. Reinforcement Learning. Agents. Attacking/Defending. DNS. VPNs. Honeypots. Malware analysis.
We believe practical cybersecurity education should be available to anyone with curiosity and an internet connection, regardless of where they live or what they can afford. Help us spread the word! Learn with us through our free or professional track: cybersecurity.bsy.fel.cvut.cz
Non-interactive SSH attacks dominate after login 📖 Read more: www.helpnetsecurity.com/2026/07/03/r... #cybersecurity #cybersecuritynews #authentication #bot #devicefingerprinting #honeypots #LLMs #SSH #threatintelligence @verovaleros.bsky.social @eldraco.bsky.social
Non-interactive SSH attacks dominate after login - Help Net Security
Non-interactive SSH attacks now make up over 99% of honeypot logins, new research finds, as scanners run one command and disconnect.
helpnetsecurity.com
Registrations are OPEN for the “Introduction to Security” course 2026. 🔗 Read more:
Ángel de la soledad Y de la desolación Preso de tu ilusión Vas a bailar … a bailar bailar…
Doctoral fellow Swantje Lange @swantjelan.bsky.social spoke with the Hasso Plattner Institut @hpi.bsky.social about sophisticated surveillance campaigns being used to exploit mobile networks, sharing that “the mobile network is highly opaque and extremely complex.” hpi.de/en/article/r...
Researchers uncover espionage in mobile networks
Like a spy movie: Researchers from HPI and the University of Toronto reveal how surveillance actors exploit mobile networks to track people worldwide.
hpi.de
Security of an In-orbit Satellite: Detection of Compromise Through Integrity 🔗 Read more:
Security of an In-orbit Satellite: Detection of Compromise Through Integrity — Stratosphere Laboratory
Small satellites are increasingly vulnerable to cyberattacks, yet their resource constraints make implementing robust security mechanisms a significant challenge. This thesis explores how to protect the...
stratosphereips.org
Poster: Multi-Objective Model Selection Pipeline for Network Flow Classification at POSTERS 2026 🔗 Read more:
Poster: Multi-Objective Model Selection Pipeline for Network Flow Classification at POSTERS 2026 — Stratosphere Laboratory
Training classifiers for network intrusion detection is hindered by two types of problems: data challenges (lack of labels, class imbalance, non-IID data, and concept drift) and engineering challenges...
stratosphereips.org
Dean's Award Outstanding Teaching "Lecturer Category" to Sebastian Garcia 🔗 Read more:
Dean's Award Outstanding Teaching "Lecturer Category" to Sebastian Garcia — Stratosphere Laboratory
Sebastian has just been awarded by the Dean of the Faculty of Electrical Engineering, Czech Technical University in Prague, for his outstanding teaching performance in the Winter Semester 2025/2026!
stratosphereips.org
NetSecGame - A Framework for Training and Evaluating AI Agents in Network Security Environments 🔗 Read more: www.stratosphereips.org/blog/2026/1/...
Build Cyber Agents with NetSecGame v0.1.0 — Stratosphere Laboratory
Build, train, and evaluate network security agents using NetSecGame. A high-speed, Docker-ready framework for Reinforcement Learning and cyber research.
stratosphereips.org
Adaptive Response in Slips IDS as Immune T Cells 🔗 Read more:
Adaptive Response in Slips IDS as Immune T Cells — Stratosphere Laboratory
The T Cell module was created to give Slips a stateful adaptive response layer on top of its existing evidence pipeline.
stratosphereips.org
Adapting Detections in Slips with Immune Pseudo-Generated Regexes 🔗 Read more:
Adapting Detections in Slips with Immune Pseudo-Generated Regexes — Stratosphere Laboratory
The RegexGenerator module was created to give Slips an adaptive way to discover new string-based detectors for changing indicators such as domains, URIs, filenames, TLS SNI values, and certificate common...
stratosphereips.org
Most malware traffic analysis fails when the answer isn’t obvious. Our signature training at Black Hat Asia with @eldraco.bsky.social, teaches a repeatable methodology for analyzing network traffic that holds up in complex cases. Join us blackhat.com/asia-26/trai... ! #blackhat #training
What if we told you we built a system that can break every LLM assistant you throw at it? Our tool presented today at #BHEU Arsenal, achieves just that! 💾 Explore more here: github.com/stratosphere...
The StratoCyberLab (SCL) is our local cyber range, where anyone can test and practice their offensive and defensive cybersecurity skills: github.com/stratosphere... 🔒 Local-only. No cloud. No tracking. No login. No data collection. ⚙️ Easy-To-Use. Only Docker is required. #CyberRange #Education
Woohoo! A new edition of our Stratosphere newsletter is just out! Catch up with some of our team activities since the last edition! 🚀 www.linkedin.com/pulse/strato...
If you missed our talk at #ekoparty, here's a poster summarizing some of our results on evaluating ARACNE, our multi-agent framework for autonomous Linux shell security testing. Our evaluation is still ongoing, and we hope to share more results soon 🚀
EFF Teams Up With AV Comparatives to Test Android Stalkerware Detection by Major Antivirus Apps | Electronic Frontier Foundation https://www.eff.org/deeplinks/2025/11/eff-teams-av-comparatives-test-android-stalkerware-detection-major-antivirus-apps
EFF Teams Up With AV Comparatives to Test Android Stalkerware Detection by Major Antivirus Apps
EFF has, for many years, raised the alarm about the proliferation of stalkerware—commercially-available apps designed to be installed covertly on another person’s device to exfiltrate data from that device without their knowledge. We’ve teamed up with the researchers at AV Comparatives to test the most popular anti-virus products for Android to see how well they detect the most popular stalkerware products in 2025
eff.org
Every year, thousands join our CTU Introduction to Security — where curiosity meets courage, and learning means attacking & defending. This is our heartbeat. 🎬 Watch the premiere → www.youtube.com/watch?v=FLtX... #CyberSecurity #Animation
Official Intro Theme — CTU Introduction to Security
Every year, hundreds of students start Introduction to Security — a 14-week, hands-on course where curiosity meets courage, and learning means breaking, building, and defending…
youtube.com
🚀 At #ekoparty, our team presented ARACNE, a multi-agent LLM based offensive and defensive agent for Linux shell systems, and one of the largest LLM model evaluations to date. 🔗 Slides: bit.ly/EKO21ARACNES... 🔗 Code: bit.ly/EKO21ARACNEC... 🔗 Paper: bit.ly/EKO21ARACNEP...
Grokipedia is the antithesis of everything that makes Wikipedia good, useful, and human. Grokipedia looks like what you would get if you told an LLM to go make an anti-woke encyclopedia, which is essentially exactly what Elon Musk did. www.404media.co/grokipedia-i...
Grokipedia Is the Antithesis of Everything That Makes Wikipedia Good, Useful, and Human
Grokipedia is not a 'Wikipedia competitor.' It is a fully robotic regurgitation machine designed to protect the ego of the world’s wealthiest man.
404media.co
Missed my my talk for #roguelikecelebration yesterday? Here you go! www.youtube.com/live/kBfytrn... #generative #procedural #creativecoding
Our colleague Lukáš Forst talked with Česká televize on the partial end of support for Windows 10, and what are the implications for European users. Watch the full segment in Czech here: www.ceskatelevize.cz/porady/10971...