| 2026 | SP | The Passkey Promise: A Comparative Usability Study of MFA Methods. | Erwin Kupris, Thomas Schreck |
| 2025 | EDCC | Device Identity Bootstrapping in Constrained Environments: A BLE-Based BRSKI Extension. | Julian Krieger, Tobias Hilbig, Thomas Schreck |
| 2024 | RAID | The "Big Beast to Tackle": Practices in Quality Assurance for Cyber Threat Intelligence. | Thomas Geras, Thomas Schreck |
| 2024 | SP | Do You Play It by the Books? A Study on Incident Response Playbooks and Influencing Factors. | Daniel Schlette, Philip Empl, Marco Caselli, Thomas Schreck, Gnther Pernul |
| 2023 | CCS | Sharing Communities: The Good, the Bad, and the Ugly. | Thomas Geras, Thomas Schreck |
| 2016 | SAC | MalFlow: identification of C&C servers through host-based data flow profiling. | Tobias Wchner, Martn Ochoa, Mojdeh Golagha, Gaurav Srivastava, Thomas Schreck, Alexander Pretschner |
| 2013 | SAC | Mobile-sandbox: having a deeper look into android applications. | Michael Spreitzenbarth, Felix C. Freiling, Florian Echtler, Thomas Schreck, Johannes Hoffmann |
| 2012 | DIMVA | BISSAM: Automatic Vulnerability Identification of Office Documents. | Thomas Schreck, Stefan Berger, Jan Gbel |
| 2010 | CCS | Towards incident handling in the cloud: challenges and approaches. | Bernd Grobauer, Thomas Schreck |
| 2000 | SAC | R-Tree Implementation Using Branch-Grafting Method. | Thomas Schreck, Zhengxin Chen |