SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsKey findings:
The findings challenge a uniform, one-size-fits-all approach to IOC decay. A security team applying the same 60-day retention window to an APT10 hash and an APT29 domain is very likely misjudging both: keeping the APT10 hash for too short a period given its multi-year persistence pattern and keeping the APT29 domain for far too long given how quickly that actor rotates infrastructure. Building threat actor attribution into decay scoring lets teams cut storage and alert noise from stale IOCs while retaining the indicators most likely to still be live. The research drew on IOC datasets tied to well-documented APT campaigns, including APT10's Cloud Hopper operation (2014-2018, 66 hashes and 30 domains), APT38's SWIFT and cryptocurrency exchange heists from 2015 to 2018 (36 hashes and 30 domains), and APT29's European campaigns from 2023 to 2024 (80 hashes and 91 domains), with all indicators enriched in VirusTotal and filtered to those with at least ten malicious vendor detections.
APT10 (China), with a mean domain TTL of 591 days and a mean hash TTL of 3,140 days, the highest of any group studied in the SANS Adversary-Aware IOC Retention research.
Yes. Despite hash values sitting at the bottom of the Pyramid of Pain, this research found hashes persisted far longer than domains across all three APT groups studied, and IP addresses had the shortest lifespan of all, rotating too quickly to be useful for this kind of analysis.
The LTV is a threat-actor-specific multiplier, normalized to a 0.5-2.5 scale using Min-Max normalization, that adjusts how quickly an IOC's relevance score decays in the MISP decay formula based on the attributed threat actor's historical infrastructure and malware lifetime patterns.
Substantially. For an 18-day-old domain IOC attributed to APT29, the standard MISP formula scored it at 64 out of 100, while the LTV-adjusted formula scored the same IOC at 3.25, decaying it about 11.7 days earlier to reflect APT29's fast infrastructure rotation.
APT29 had the shortest domain TTLs of the three groups studied (median of 40 days), which the research interprets as a sign of tight operational security and rapid infrastructure cycling rather than lower sophistication.















