Dataset of APT Persistence Techniques on Windows Platforms Mapped to the MITRE ATT&CK Framework

Khaled Rahal, Arbia Riahi, Thibault Debatty

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Securing against intrusions is a crucial aspect of cybersecurity defense. As systems become more complex and new technologies are introduced, new threats are constantly emerging, putting all aspects of information systems at risk. To detect these threats and put in place effective response strategies, security professionals must test their solutions on real-world data. This underscores the importance of datasets to provide a simulation of attack scenarios. Advanced Persistent Threats (APT) carry out multi-stage attacks on an organization’s network, often spanning extended periods. Existing datasets on APT mainly focus on the different kill chain stages such as initial intrusion, privilege escalation, lateral movements, and command and control. However, the persistence phase, which is crucial for the sustainability of attacks, is often neglected [10]. In this work, we propose a dataset specifically dedicated to the persistence techniques employed by the threat actor targeting the Windows platform. Our work offers a detailed analysis of persistence mechanisms, relying on realistic virtualized environments and attack simulation tools, based on MITRE ATT&CK TTP (Tactics, Techniques, and Procedures) used by known APT groups. Publicly available at [26], the datasets include detailed instructions for access and use, ensuring reproducibility and usability for researchers and cybersecurity practitioners.

Original languageEnglish
Title of host publicationProceedings of the 28th Conference on Innovation in Clouds, Internet and Networks, ICIN 2025
EditorsFrederica Paganelli, Elisa Rojas, Nathalie Mitton, Diala Naboulsi, Davide Borsatti, Stephane Rovedakis
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages17-24
Number of pages8
ISBN (Electronic)9798331542399
DOIs
Publication statusPublished - 2025
Event28th Conference on Innovation in Clouds, Internet and Networks, ICIN 2025 - Paris, France
Duration: 11 Mar 202514 Mar 2025

Publication series

NameProceedings of the 28th Conference on Innovation in Clouds, Internet and Networks, ICIN 2025

Conference

Conference28th Conference on Innovation in Clouds, Internet and Networks, ICIN 2025
Country/TerritoryFrance
CityParis
Period11/03/2514/03/25

Keywords

  • Advanced Persistent Threat
  • Datasets
  • Mitre Att&ck
  • Persistence Techniques

Fingerprint

Dive into the research topics of 'Dataset of APT Persistence Techniques on Windows Platforms Mapped to the MITRE ATT&CK Framework'. Together they form a unique fingerprint.

Cite this