Group Purchasing
Group Purchasing

Adversary-Aware IOC Retention: Analyzing Time-to-Live Patterns by Threat Actor Attribution

Adversary-Aware IOC Retention: Analyzing Time-to-Live Patterns by Threat Actor Attribution (PDF, 1.12MB)Published: 23 Oct, 2025
Created by:

Adversary-Aware IOC Retention: Analyzing Time-to-Live Patterns by Threat Actor Attribution, published by SANS Institute in October 2025, proposes a threat-actor-specific enhancement to the widely used MISP indicator of compromise (IOC) decay model. The research analyzed hundreds of domains and file hash IOCs tied to three Advanced Persistent Threat (APT) groups from different regions to test whether IOC lifespan varies predictably by threat actor and can be built into automated decay scoring.

Key findings:

  • APT10 (China, linked to the Ministry of State Security) shows the longest-lived IOCs of the three groups studied, with a mean domain Time to Live (TTL) of 591 days and a mean hash TTL of 3,140 days
  • APT29 (Russia, Cozy Bear/SVR) has the shortest and tightest domain TTL distribution, with a median domain TTL of just 40 days, reflecting fast infrastructure cycling despite being one of the most technically sophisticated groups tracked
  • APT38 (North Korea, a Lazarus Group subgroup) falls in the middle, with a mean domain TTL of 403 days and a mean hash TTL of 601 days
  • Contrary to the assumptions behind the widely cited Pyramid of Pain, file hashes were found to persist far longer than domains across all three threat actors, not less
  • IP addresses were excluded from the study entirely because their TTL was too short and volatile (driven by CDN and cloud provider rotation) to produce a meaningful signal
  • The study's new Lifetime Variable (LTV), derived through Min-Max normalization on a 0.5 to 2.5 scale, quantifies this behavior: APT10 scored highest (0.97 domain LTV, 1.85 hash LTV), APT29 lowest on domains (0.61), and APT38 in between (0.83 domain LTV, 0.77 hash LTV)
  • Applying the LTV to the standard MISP decay formula changes real scoring outcomes: for an APT29 domain IOC, the original formula scored a 18-day-old indicator at 64 out of 100, while the LTV-adjusted formula scored the same indicator at 3.25, effectively decaying it roughly 11.7 days earlier
  • Domain lifetime data was sourced from historical DNS records via SecurityTrails, while hash lifetime data used VirusTotal's first and last submission timestamps rather than creation time, since PE timestamps can be manipulated

The findings challenge a uniform, one-size-fits-all approach to IOC decay. A security team applying the same 60-day retention window to an APT10 hash and an APT29 domain is very likely misjudging both: keeping the APT10 hash for too short a period given its multi-year persistence pattern and keeping the APT29 domain for far too long given how quickly that actor rotates infrastructure. Building threat actor attribution into decay scoring lets teams cut storage and alert noise from stale IOCs while retaining the indicators most likely to still be live. The research drew on IOC datasets tied to well-documented APT campaigns, including APT10's Cloud Hopper operation (2014-2018, 66 hashes and 30 domains), APT38's SWIFT and cryptocurrency exchange heists from 2015 to 2018 (36 hashes and 30 domains), and APT29's European campaigns from 2023 to 2024 (80 hashes and 91 domains), with all indicators enriched in VirusTotal and filtered to those with at least ten malicious vendor detections.

FAQ

APT10 (China), with a mean domain TTL of 591 days and a mean hash TTL of 3,140 days, the highest of any group studied in the SANS Adversary-Aware IOC Retention research. 

Yes. Despite hash values sitting at the bottom of the Pyramid of Pain, this research found hashes persisted far longer than domains across all three APT groups studied, and IP addresses had the shortest lifespan of all, rotating too quickly to be useful for this kind of analysis. 

The LTV is a threat-actor-specific multiplier, normalized to a 0.5-2.5 scale using Min-Max normalization, that adjusts how quickly an IOC's relevance score decays in the MISP decay formula based on the attributed threat actor's historical infrastructure and malware lifetime patterns. 

Substantially. For an 18-day-old domain IOC attributed to APT29, the standard MISP formula scored it at 64 out of 100, while the LTV-adjusted formula scored the same IOC at 3.25, decaying it about 11.7 days earlier to reflect APT29's fast infrastructure rotation. 

APT29 had the shortest domain TTLs of the three groups studied (median of 40 days), which the research interprets as a sign of tight operational security and rapid infrastructure cycling rather than lower sophistication.