Adversary-Aware IOC Retention: Analyzing Time-to-Live Patterns by Threat Actor Attribution
Adversary-Aware IOC Retention: Analyzing Time-to-Live Patterns by Threat Actor Attribution, published by SANS Institute in October 2025, proposes a threat-actor-specific enhancement to the widely used MISP indicator of compromise (IOC) decay model. The research analyzed hundreds of domains and file hash IOCs tied to three Advanced Persistent Threat (APT) groups from different regions to test whether IOC lifespan varies predictably by threat actor and can be built into automated decay scoring.
Key findings:
- APT10 (China, linked to the Ministry of State Security) shows the longest-lived IOCs of the three groups studied, with a mean domain Time to Live (TTL) of 591 days and a mean hash TTL of 3,140 days
- APT29 (Russia, Cozy Bear/SVR) has the shortest and tightest domain TTL distribution, with a median domain TTL of just 40 days, reflecting fast infrastructure cycling despite being one of the most technically sophisticated groups tracked
- APT38 (North Korea, a Lazarus Group subgroup) falls in the middle, with a mean domain TTL of 403 days and a mean hash TTL of 601 days
- Contrary to the assumptions behind the widely cited Pyramid of Pain, file hashes were found to persist far longer than domains across all three threat actors, not less
- IP addresses were excluded from the study entirely because their TTL was too short and volatile (driven by CDN and cloud provider rotation) to produce a meaningful signal
- The study's new Lifetime Variable (LTV), derived through Min-Max normalization on a 0.5 to 2.5 scale, quantifies this behavior: APT10 scored highest (0.97 domain LTV, 1.85 hash LTV), APT29 lowest on domains (0.61), and APT38 in between (0.83 domain LTV, 0.77 hash LTV)
- Applying the LTV to the standard MISP decay formula changes real scoring outcomes: for an APT29 domain IOC, the original formula scored a 18-day-old indicator at 64 out of 100, while the LTV-adjusted formula scored the same indicator at 3.25, effectively decaying it roughly 11.7 days earlier
- Domain lifetime data was sourced from historical DNS records via SecurityTrails, while hash lifetime data used VirusTotal's first and last submission timestamps rather than creation time, since PE timestamps can be manipulated
The findings challenge a uniform, one-size-fits-all approach to IOC decay. A security team applying the same 60-day retention window to an APT10 hash and an APT29 domain is very likely misjudging both: keeping the APT10 hash for too short a period given its multi-year persistence pattern and keeping the APT29 domain for far too long given how quickly that actor rotates infrastructure. Building threat actor attribution into decay scoring lets teams cut storage and alert noise from stale IOCs while retaining the indicators most likely to still be live. The research drew on IOC datasets tied to well-documented APT campaigns, including APT10's Cloud Hopper operation (2014-2018, 66 hashes and 30 domains), APT38's SWIFT and cryptocurrency exchange heists from 2015 to 2018 (36 hashes and 30 domains), and APT29's European campaigns from 2023 to 2024 (80 hashes and 91 domains), with all indicators enriched in VirusTotal and filtered to those with at least ten malicious vendor detections.
SANS-Adversary-Aware-IOC-Retention (PDF, 1.12MB)
23 Oct 2025Related Content
DeScrypt: A Multi-Tool Framework for Automated Unpacking and Analysis of Malicious Scripts
Research PaperScripting languages are increasingly dominant malware vectors that often employ layered obfuscation techniques to slow down manual analysis by reverse engineers and to prevent pattern recognition.
- 28 Sep 2026
- Daniel Schalla
The Invisible Checkpoint: Passive LTE Traffic Capture for Mobile Malware Detection
Research PaperThis paper presents a privacy-preserving, field-deployable framework for passive mobile malware detection.
- 11 Aug 2026
- Garo Sinanian
Reconstructing Deleted File Activity Using FSEvents from macOS
Research PaperThis paper examines the role of FSEvents as a source of historical file system activity, particularly in scenarios where files are no longer present on disk.
- 30 Jul 2026
- Josh Clevenger
Benchmarking Free-Tier Large Language Models as Cognitive Aids for Operationalizing Unstructured Cyber Threat Intelligence
Research PaperModern Security Operations Centers (SOCs) face a deepening burnout crisis.
- 20 Jul 2026
- Jose "Ricky" Banda
Detection Strategies for AskCreds Beacon Object File Credential Harvesting Across Multiple C2 Frameworks
Research PaperThis study evaluates layered detection strategies against AskCreds BOF execution in an isolated Azure lab using Cobalt Strike 4.12 and Outflank C2 v2.11.1, with Velociraptor as the primary DFIR platform.
- 22 Jun 2026
- Eric Fletcher
Capturing the Click: Process-Based Detection of Malicious Link Interactions
Research PaperThis research validates the browser command-line flags used by Chrome, Edge, and Firefox as parameters in process-creation events, capturing both the clicked URL and the parent application, document, or script that delivered it.
- 22 Jun 2026
- Daniel Gott
Know Your Blind Spots: Better Visibility Through EDR Policy Hardening
Research PaperEndpoint Detection and Response (EDR) tools identify, detect, and respond to anomalous behavior.
- 9 Jun 2026
- Joshuah Williams
Applying CIS Controls to AI Workflows
Research PaperThis research provides guidance on using the CIS Controls in conjunction with AI-specific frameworks to build a robust information security program.
- 12 May 2026
- Brian Ventura
A Forensic Study of Artifact Persistence in Containerd-Based Kubernetes Workloads
Research PaperA container is a standard unit of software that packages code, including its dependencies, so the application runs quickly and reliably across computing environments.
- 12 May 2026
- Ahmed Alharbi
Implementing Micro-Segmentation in a Legacy Enterprise Lab Network: A Zero Trust Approach to Reducing Lateral Movement, Improving Containment, and Controlling Operational Overhead
Research PaperThis study evaluates micro-segmentation as a practical Zero Trust control in a Windows Active Directory lab that models common legacy dependencies (directory services, file services, a web tier, and a database tier).
- 24 Mar 2026
- Dennis Ankrah
Assessing the Impact of Memory Acquisition on Key Windows Artifacts
Research PaperThis research evaluates the impact of memory capture tools on data at rest, aiming to understand the degree of change that occurs to artifacts, measure differences based on tool selection, and inform best practices for live responders.
- 20 Mar 2026
- Russell Devine
From Ambiguity to Action: A Forensic Framework for Differentiating ClickFix Payloads
Research PaperThe "ClickFix" social engineering technique, which leverages fake CAPTCHA or browser update lures to trick users into executing a malicious PowerShell script, presents a critical challenge for incident responders.
- 24 Feb 2026
- James Chisolm-Williams
Measuring Malware Obfuscation: Evaluating CNN- Based Detection for Real-World Resilience
Research PaperThis study examined how layered obfuscation affects image-based convolutional neural network (CNN) detectors and introduces a novel, reproducible framework for measuring obfuscation itself.
- 19 Nov 2025
- Michael Reglein
Scrutinizing A Web-Based LLM in Private Browsing Mode: An Analysis of Memory Artifacts and Privacy Implications
Research PaperUsing web-based LLMs such as ChatGPT has changed the web browsing landscape to become part of the typical everyday experience.
- 7 Nov 2025
- Chris Kosmas
Breaking Time: Methods, Artifacts, and Forensic Detection of Timestomping on FAT32, Ext3, and Ext4 File Systems
Research PaperThis paper explores the diverse methods used to timestomp files on FAT, Ext3, and Ext4 file systems, focusing on how adversaries adapt their approaches based on available system access and permissions.
- 23 Oct 2025
- Allan Kroll
Breaking Through Deception: Addressing Barriers in the Adoption of Cyber Deception Technologies
Research PaperDespite the increasing sophistication of cyber threats and the need for organizations to employ innovative defense strategies, cyber deception technologies, tools designed to mislead attackers and gain a defensive advantage, remain significantly underutilized across organizational cybersecurity programs.
- 23 Oct 2025
- Dakota Campbell
Forensic Investigation of Bluetooth-Based Credit Card Skimmers
Research PaperHidden Bluetooth Low Energy (BLE) credit skimmers are a growing threat to credit card fraud. Criminals can set up practical and inexpensive systems built on top of modules, such as the HM-19, to collect and transmit stolen data covertly across wireless channels.
- 3 Sep 2025
- John Passaro
Beneath the Mask: Can Contribution Data Unveil Malicious Personas in Open-Source Projects?
Research PaperIn February 2024, after building trust over two years with project maintainers by making a significant volume of legitimate contributions, GitHub user "JiaT75" self-merged a version of the XZ Utils project containing a highly sophisticated well-disguised backdoor targeting sshd processes running on systems with the backdoored package installed.
- 13 May 2025
- SANS Institute
Catching the Hand in the Cookie Jar: Canary Session Cookies
Research PaperThis project demonstrates how even applications secured with MFA are still vulnerable to hijacked session cookies. Given the persistent threats posed to organizations by stolen authentication cookies, this research proposes implementing Canary session cookies to detect the theft and malicious use of credentials.
- 17 Apr 2025
- Caleb Patten
A Pebble In the Ocean: Maximizing Log Fidelity In Container Environments
Research PaperLog fidelity is crucial for Incident Response Teams to investigate and contain cyber incidents but can be difficult to optimize in containerized environments.
- 17 Apr 2025
- Zach Salva
