{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,15]],"date-time":"2026-05-15T06:07:15Z","timestamp":1778825235706,"version":"3.51.4"},"reference-count":62,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372410"],"award-info":[{"award-number":["62372410"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U22B2028"],"award-info":[{"award-number":["U22B2028"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computers &amp; Security"],"published-print":{"date-parts":[[2026,8]]},"DOI":"10.1016\/j.cose.2026.104907","type":"journal-article","created":{"date-parts":[[2026,4,6]],"date-time":"2026-04-06T16:43:30Z","timestamp":1775493810000},"page":"104907","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["ProHunter: A comprehensive APT hunting system based on whole-system provenance"],"prefix":"10.1016","volume":"167","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-3140-9917","authenticated-orcid":false,"given":"Xuebo","family":"Qiu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4810-7491","authenticated-orcid":false,"given":"Mingqi","family":"Lv","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tiantian","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yimei","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tieming","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.cose.2026.104907_bib0001","unstructured":", 2017. 5 Types of threat hunting. https:\/\/www.cybersecurity-insiders.com\/5-types-of-threat-hunting\/."},{"key":"10.1016\/j.cose.2026.104907_bib0002","unstructured":", 2017. Transparent computing engagement 3 data release. https:\/\/github.com\/darpa-i2o\/Transparent-Computing\/blob\/master\/README-E3.md."},{"key":"10.1016\/j.cose.2026.104907_bib0003","unstructured":", 2020a. Operationally transparent cyber (opTC) data release. https:\/\/github.com\/FiveDirections\/OpTC-data."},{"key":"10.1016\/j.cose.2026.104907_bib0004","unstructured":", 2020b. Transparent computing engagement 5 data release. https:\/\/github.com\/darpa-i2o\/Transparent-Computing."},{"key":"10.1016\/j.cose.2026.104907_bib0005","series-title":"Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security","first-page":"2247","article-title":"Provg-searcher: a graph representation learning approach for efficient provenance graph search","author":"Altinisik","year":"2023"},{"key":"10.1016\/j.cose.2026.104907_bib0006","doi-asserted-by":"crossref","first-page":"5257","DOI":"10.1109\/TIFS.2024.3396390","article-title":"MEGR-APT: a memory-efficient APT hunting system based on attack representation learning","volume":"19","author":"Aly","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.cose.2026.104907_bib0007","series-title":"Proceedings of the 26th ACM Symposium on Access Control Models and Technologies","first-page":"27","article-title":"Analyzing the usefulness of the DARPA opTC dataset in cyber threat detection research","author":"Anjum","year":"2021"},{"key":"10.1016\/j.cose.2026.104907_bib0008","series-title":"24th USENIX Security Symposium (USENIX Security 15)","first-page":"319","article-title":"Trustworthy {Whole-System} provenance for the linux kernel","author":"Bates","year":"2015"},{"key":"10.1016\/j.cose.2026.104907_bib0009","first-page":"1","article-title":"APT-KGL: an intelligent APT detection system based on threat knowledge and heterogeneous provenance graph learning","author":"Chen","year":"2022","journal-title":"IEEE Trans. Depend. Secure Comput."},{"key":"10.1016\/j.cose.2026.104907_bib0010","unstructured":"Chen, T., Song, Q., Qiu, X., Zhu, T., Zhu, Z., Lv, M., 2022b. Kellect: a kernel-based efficient and lossless event log collector. arXiv preprint arXiv: 2207.11530."},{"key":"10.1016\/j.cose.2026.104907_bib0011","series-title":"2023 26th International Conference on Computer Supported Cooperative Work in Design (CSCWD)","first-page":"1014","article-title":"Ghunter: a fast subgraph matching method for threat hunting","author":"Cheng","year":"2023"},{"key":"10.1016\/j.cose.2026.104907_bib0012","unstructured":"Cheng, Z., Lv, Q., Liang, J., Wang, Y., Sun, D., Pasquier, T., Han, X., 2023b. Kairos:: practical intrusion detection and investigation using whole-system provenance. arXiv preprint arXiv: 2308.05034."},{"key":"10.1016\/j.cose.2026.104907_bib0013","unstructured":"Corporation, M., 2015. Mitre att&ck. https:\/\/attack.mitre.org."},{"key":"10.1016\/j.cose.2026.104907_bib0014","unstructured":"DavidJBianco, 2014. The pyramid of pain. https:\/\/detect-respond.blogspot.com\/2013\/03\/the-pyramid-of-pain.html."},{"issue":"2","key":"10.1016\/j.cose.2026.104907_bib0015","doi-asserted-by":"crossref","first-page":"61","DOI":"10.1145\/3575637.3575646","article-title":"Data augmentation for deep graph learning: a survey","volume":"24","author":"Ding","year":"2022","journal-title":"ACM SIGKDD Explorations Newsl."},{"key":"10.1016\/j.cose.2026.104907_bib0016","series-title":"Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security","first-page":"2396","article-title":"Are we there yet? An industrial viewpoint on provenance-based endpoint detection and response tools","author":"Dong","year":"2023"},{"key":"10.1016\/j.cose.2026.104907_bib0017","unstructured":"Fey, M., Lenssen, J. E., 2019. Fast graph representation learning with pytorch geometric. arXiv preprint arXiv: 1903.02428."},{"key":"10.1016\/j.cose.2026.104907_bib0018","series-title":"2021 IEEE 37th International Conference on Data Engineering (ICDE)","first-page":"193","article-title":"Enabling efficient cyber threat hunting with cyber threat intelligence","author":"Gao","year":"2021"},{"issue":"7","key":"10.1016\/j.cose.2026.104907_bib0019","doi-asserted-by":"crossref","first-page":"1100","DOI":"10.1109\/TPAMI.2005.138","article-title":"Exact and approximate graph matching using random walks","volume":"27","author":"Gori","year":"2005","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10.1016\/j.cose.2026.104907_bib0020","series-title":"30th Network and Distributed System Security Symposium","article-title":"Sometimes, you aren\u2019t what you do: mimicry attacks against provenance graph host intrusion detection systems","author":"Goyal","year":"2023"},{"key":"10.1016\/j.cose.2026.104907_bib0021","series-title":"Technical Report","article-title":"Exploring Network Structure, Dynamics, and Function Using NetworkX","author":"Hagberg","year":"2008"},{"key":"10.1016\/j.cose.2026.104907_bib0022","series-title":"Inductive Representation Learning on Large Graphs","author":"Hamilton","year":"2017"},{"key":"10.1016\/j.cose.2026.104907_bib0023","doi-asserted-by":"crossref","unstructured":"Han, X., Pasquier, T., Bates, A., Mickens, J., Seltzer, M., 2020. Unicorn: runtime provenance-based detector for advanced persistent threats. arXiv preprint arXiv: 2001.01525.","DOI":"10.14722\/ndss.2020.24046"},{"key":"10.1016\/j.cose.2026.104907_bib0024","doi-asserted-by":"crossref","unstructured":"Hassan, W. U., Guo, S., Li, D., Chen, Z., Jee, K., Li, Z., Bates, A., 2019. Nodoze: combatting threat alert fatigue with automated provenance triage. In: Netw. Distrib. Syst. Secur. Symp.","DOI":"10.14722\/ndss.2019.23349"},{"key":"10.1016\/j.cose.2026.104907_bib0025","series-title":"26th USENIX Security Symposium (USENIX Security 17)","first-page":"487","article-title":"{SLEUTH}: real-time attack scenario reconstruction from {COTS} audit data","author":"Hossain","year":"2017"},{"key":"10.1016\/j.cose.2026.104907_bib0026","series-title":"27th USENIX Security Symposium (USENIX Security 18)","first-page":"1723","article-title":"{Dependence-Preserving} data compaction for scalable forensic analysis","author":"Hossain","year":"2018"},{"key":"10.1016\/j.cose.2026.104907_bib0027","series-title":"Proceedings of the 2022 SIAM International Conference on Data Mining (SDM)","first-page":"172","article-title":"Neural graph matching for pre-training graph neural networks","author":"Hou","year":"2022"},{"key":"10.1016\/j.cose.2026.104907_bib0028","series-title":"Proceedings of the 2022 SIAM International Conference on Data Mining (SDM)","first-page":"172","article-title":"Neural graph matching for pre-training graph neural networks","author":"Hou","year":"2022"},{"key":"10.1016\/j.cose.2026.104907_bib0029","unstructured":"Jia, Z., Xiong, Y., Nan, Y., Zhang, Y., Zhao, J., Wen, M., 2023. Magic: detecting advanced persistent threats via masked graph representation learning. In: 33th USENIX Security Symposium (USENIX Security 24), pp. 5197\u20135214."},{"key":"10.1016\/j.cose.2026.104907_bib0030","series-title":"2021 20th IEEE International Conference on Machine Learning and Applications (ICMLA)","first-page":"1720","article-title":"Prov-gem: automated provenance analysis framework using graph embeddings","author":"Kapoor","year":"2021"},{"key":"10.1016\/j.cose.2026.104907_bib0031","unstructured":"Kipf, T. N., Welling, M., 2016. Semi-supervised classification with graph convolutional networks. arXiv preprint arXiv: 1609.02907."},{"key":"10.1016\/j.cose.2026.104907_bib0032","unstructured":"Li, J., Zhang, R., Liu, J., Zhao, W., 2025. Cliprov: a contrastive log-to-intelligence multimodal approach for threat detection and provenance analysis. arXiv preprint arXiv: 2507.09133."},{"key":"10.1016\/j.cose.2026.104907_bib0033","series-title":"European Symposium on Research in Computer Security","first-page":"589","article-title":"AttacKG: constructing technique knowledge graph from cyber threat intelligence reports","author":"Li","year":"2022"},{"key":"10.1016\/j.cose.2026.104907_bib0034","article-title":"A survey on the evolution of fileless attacks and detection techniques","volume":"137","author":"Liu","year":"2023","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cose.2026.104907_bib0035","unstructured":"Lohmann, N., 2023. JSON for modern C++. https:\/\/github.com\/nlohmann\/json."},{"key":"10.1016\/j.cose.2026.104907_bib0036","series-title":"Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security","first-page":"139","article-title":"Trec: apt tactic\/technique recognition via few-shot provenance subgraph learning","author":"Lv","year":"2024"},{"key":"10.1016\/j.cose.2026.104907_bib0037","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2025.114169","article-title":"Actminer: applying causality tracking and increment aligning for graph-based threat hunting","volume":"327","author":"Ma","year":"2025","journal-title":"Knowl. Based Syst."},{"key":"10.1016\/j.cose.2026.104907_bib0038","series-title":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","first-page":"1795","article-title":"Poirot: aligning attack behavior with kernel audit records for cyber threat hunting","author":"Milajerdi","year":"2019"},{"key":"10.1016\/j.cose.2026.104907_bib0039","series-title":"2019 IEEE Symposium on Security and Privacy (SP)","first-page":"1137","article-title":"Holmes: real-time APT detection through correlation of suspicious information flows","author":"Milajerdi","year":"2019"},{"issue":"5","key":"10.1016\/j.cose.2026.104907_bib0040","doi-asserted-by":"crossref","first-page":"5178","DOI":"10.1109\/TNSM.2024.3378972","article-title":"Automa: automated generation of attack hypotheses and their variants for threat hunting using knowledge discovery","volume":"21","author":"Nour","year":"2024","journal-title":"IEEE Trans. Netw. Serv. Manage."},{"key":"10.1016\/j.cose.2026.104907_bib0041","article-title":"Pytorch: an imperative style, high-performance deep learning library","volume":"32","author":"Paszke","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.cose.2026.104907_bib0042","series-title":"2025 55th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN)","first-page":"664","article-title":"Towards automated and explainable threat hunting with generative AI","author":"Purba","year":"2025"},{"key":"10.1016\/j.cose.2026.104907_bib0043","series-title":"International Conference on Information and Communications Security","first-page":"531","article-title":"Provenance-based intrusion detection via multi-scale graph representation learning","author":"Qiu","year":"2025"},{"key":"10.1016\/j.cose.2026.104907_bib0044","unstructured":"Qiu, X., Lv, M., Zhang, Y., Chen, T., Zhu, T., Song, Q., Ji, S., 2025b. APT-CGLP: advanced persistent threat hunting via contrastive graph-language pre-training. arXiv preprint arXiv: 2511.20290."},{"key":"10.1016\/j.cose.2026.104907_bib0045","series-title":"2024 IEEE Symposium on Security and Privacy (SP)","first-page":"139","article-title":"Flash: a comprehensive approach to intrusion detection via provenance graph representation learning","author":"Rehman","year":"2024"},{"key":"10.1016\/j.cose.2026.104907_bib0046","unstructured":"Rex, Ying, Lou, Z., You, J., Wen, C., Canedo, A., Leskovec, J., 2020. Neural subgraph matching."},{"key":"10.1016\/j.cose.2026.104907_bib0047","series-title":"MLG","first-page":"21","article-title":"Speeding up graph edit distance computation with a bipartite heuristic","author":"Riesen","year":"2007"},{"key":"10.1016\/j.cose.2026.104907_bib0048","unstructured":"SANS, Qualys, 2019. SANs 2018 threat hunting survey results. https:\/\/www.qualys.com\/forms\/whitepapers\/sans-2018-threat-hunting-survey-results\/."},{"key":"10.1016\/j.cose.2026.104907_bib0049","series-title":"2021 IEEE European Symposium on Security and Privacy (EuroS&P)","first-page":"598","article-title":"Extractor: extracting attack behavior from threat reports","author":"Satvat","year":"2021"},{"key":"10.1016\/j.cose.2026.104907_bib0050","series-title":"2024 IEEE Symposium on Security and Privacy (SP)","first-page":"87","article-title":"eaudit: a fast, scalable and deployable audit data collection system","author":"Sekar","year":"2023"},{"key":"10.1016\/j.cose.2026.104907_bib0051","series-title":"Proceedings of the 17th Annual Workshop on Circuits, Systems and Signal Processing (ProRISC 2006)","first-page":"334","article-title":"Performance impact of misaligned accesses in SIMD extensions","author":"Shahbahrami","year":"2006"},{"key":"10.1016\/j.cose.2026.104907_bib0052","unstructured":"Taschler, S., 2023. What is cyber threat hunting?https:\/\/www.crowdstrike.com\/cybersecurity-101\/threat-hunting\/."},{"key":"10.1016\/j.cose.2026.104907_bib0053","unstructured":"TylerMSFT, 2022. C and C++ in visual studio. https:\/\/learn.microsoft.com\/en-us\/cpp\/overview\/visual-cpp-in-visual-studio?view=msvc-170."},{"key":"10.1016\/j.cose.2026.104907_bib0054","unstructured":"Veli\u010dkovi\u0107, P., Cucurull, G., Casanova, A., Romero, A., Lio, P., Bengio, Y., 2017. Graph attention networks. arXiv preprint arXiv: 1710.10903."},{"key":"10.1016\/j.cose.2026.104907_bib0055","doi-asserted-by":"crossref","first-page":"3972","DOI":"10.1109\/TIFS.2022.3208815","article-title":"Threatrace: detecting and tracing host-based threats in node level through provenance graph learning","volume":"17","author":"Wang","year":"2022","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.cose.2026.104907_bib0056","series-title":"Security and Privacy in Communication Networks","first-page":"3","article-title":"Deephunter: a graph neural network based approach for robust cyber threat hunting","author":"Wei","year":"2021"},{"key":"10.1016\/j.cose.2026.104907_bib0057","unstructured":"Xu, K., Hu, W., Leskovec, J., Jegelka, S., 2018. How powerful are graph neural networks?arXiv preprint arXiv: 1810.00826."},{"issue":"10","key":"10.1016\/j.cose.2026.104907_bib0058","doi-asserted-by":"crossref","first-page":"110","DOI":"10.1109\/MCOM.001.2300224","article-title":"Hypothesis generation model for cyber threat hunting","volume":"62","author":"Yi","year":"2024","journal-title":"IEEE Commun. Mag."},{"key":"10.1016\/j.cose.2026.104907_bib0059","first-page":"5812","article-title":"Graph contrastive learning with augmentations","volume":"33","author":"You","year":"2020","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.cose.2026.104907_bib0060","series-title":"Proceedings 2021 Network and Distributed System Security Symposium","article-title":"Watson: abstracting behaviors from audit logs via aggregation of contextual semantics","author":"Zeng","year":"2021"},{"key":"10.1016\/j.cose.2026.104907_bib0061","doi-asserted-by":"crossref","first-page":"3312","DOI":"10.1109\/TIFS.2021.3076288","article-title":"General, efficient, and real-time data compaction strategy for APT forensic analysis","volume":"16","author":"Zhu","year":"2021","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.cose.2026.104907_bib0062","first-page":"1","article-title":"APTshield: a stable, efficient and real-time APT detection system for linux hosts","author":"Zhu","year":"2023","journal-title":"IEEE Trans. Depend. Secure Comput."}],"container-title":["Computers &amp; Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404826000830?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404826000830?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,15]],"date-time":"2026-05-15T05:10:23Z","timestamp":1778821823000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0167404826000830"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,8]]},"references-count":62,"alternative-id":["S0167404826000830"],"URL":"https:\/\/doi.org\/10.1016\/j.cose.2026.104907","relation":{},"ISSN":["0167-4048"],"issn-type":[{"value":"0167-4048","type":"print"}],"subject":[],"published":{"date-parts":[[2026,8]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"ProHunter: A comprehensive APT hunting system based on whole-system provenance","name":"articletitle","label":"Article Title"},{"value":"Computers & Security","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.cose.2026.104907","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"104907"}}