{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,3]],"date-time":"2025-11-03T04:57:33Z","timestamp":1762145853371,"version":"3.40.3"},"reference-count":25,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,3,11]],"date-time":"2025-03-11T00:00:00Z","timestamp":1741651200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,3,11]],"date-time":"2025-03-11T00:00:00Z","timestamp":1741651200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,3,11]]},"DOI":"10.1109\/icin64016.2025.10943025","type":"proceedings-article","created":{"date-parts":[[2025,4,4]],"date-time":"2025-04-04T18:22:30Z","timestamp":1743790950000},"page":"17-24","source":"Crossref","is-referenced-by-count":2,"title":["Dataset of APT Persistence Techniques on Windows Platforms Mapped to the MITRE ATT&amp;CK Framework"],"prefix":"10.1109","author":[{"given":"Khaled","family":"Rahal","sequence":"first","affiliation":[{"name":"Royal Military Academy,Cyber Defence Lab,Brussels,Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Arbia","family":"Riahi","sequence":"additional","affiliation":[{"name":"Royal Military Academy,Cyber Defence Lab,Brussels,Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Thibault","family":"Debatty","sequence":"additional","affiliation":[{"name":"Royal Military Academy,Cyber Defence Lab,Brussels,Belgium"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"volume-title":"Statista","article-title":"Cybercrime Expected To Skyrocket in Coming Years","key":"ref1"},{"volume-title":"CrowdStrike","article-title":"What is an Advanced Persistent Threat?","key":"ref2"},{"volume-title":"The MITRE Corporation","article-title":"MITRE ATT&CK","key":"ref3"},{"volume-title":"LOLBAS Project","article-title":"Living Off The Land Binaries, Scripts and Libraries","key":"ref4"},{"key":"ref5","article-title":"Cyber Kill Chain-Based Taxonomy of Advanced Persistent Threat Actors: Analogy of Tactics, Techniques, and Procedures","volume":"15","author":"Bahrami","year":"2021","journal-title":"Journal of Information Processing Systems"},{"doi-asserted-by":"publisher","key":"ref6","DOI":"10.1016\/j.comnet.2023.109688"},{"key":"ref7","article-title":"DAPT 2020-constructing a benchmark dataset for advanced persistent threats","volume-title":"Deployable Machine Learning for Security Defense: First International Workshop, MLHat 2020","author":"Sowmya","year":"2020"},{"doi-asserted-by":"publisher","key":"ref8","DOI":"10.1016\/j.dib.2024.110290"},{"key":"ref9","article-title":"SCVIC-APT-2021","volume-title":"IEEE Dataport","author":"Liu","year":"2022"},{"key":"ref10","article-title":"Accurate and Scalable Detection and Investigation of Cyber Persistence Threats","author":"Liu","year":"2024","journal-title":"arXiv preprint"},{"volume-title":"ATLASv2","author":"Riddle","key":"ref11"},{"key":"ref12","article-title":"A Review of Wazuh Tool Capabilities for Detecting Attacks Based on Log Analysis","volume":"1","author":"Stefan","year":"2022","journal-title":"No Nama Agent Integrity File Added Delete Modified"},{"volume-title":"Chocolatey","key":"ref13"},{"doi-asserted-by":"publisher","key":"ref14","DOI":"10.1109\/ICSPIS60075.2023.10343783"},{"volume-title":"Simulate user activity with the GHOSTS framework: Client set-up and Timelines","author":"Nikolov","key":"ref15"},{"doi-asserted-by":"publisher","key":"ref16","DOI":"10.1007\/s10207-023-00725-8"},{"year":"2023","author":"Tran Duc","journal-title":"Exploring Common Malware Persistence Techniques on Windows Operating Systems (OS) for Enhanced Cybersecurity Management","key":"ref17"},{"volume-title":"Fortinet","article-title":"TeamCity Intrusion Saga: APT29 Suspected Among the Attackers Exploiting CVE-2023\u201342793","key":"ref18"},{"volume-title":"Ghost Scheduled Task","key":"ref19"},{"volume-title":"TTPs and IOCs Used by MuddyWater APT Group in Latest Attack Campaign","key":"ref20"},{"doi-asserted-by":"publisher","key":"ref21","DOI":"10.1145\/2991079.2991111"},{"volume-title":"Analyzing APT19 malware using a step-by-step method","key":"ref22"},{"volume-title":"APT41 Has Arisen From the DUST","key":"ref23"},{"volume-title":"Dissecting One of APT29\u2019s Fileless WMI and PowerShell Backdoors (POSHSPY)","key":"ref24"},{"volume-title":"Desktop Operating System Market Share Worldwide","key":"ref25"}],"event":{"name":"2025 28th Conference on Innovation in Clouds, Internet and Networks (ICIN)","start":{"date-parts":[[2025,3,11]]},"location":"Paris, France","end":{"date-parts":[[2025,3,14]]}},"container-title":["2025 28th Conference on Innovation in Clouds, Internet and Networks (ICIN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10942563\/10942564\/10943025.pdf?arnumber=10943025","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,5]],"date-time":"2025-04-05T09:09:17Z","timestamp":1743844157000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10943025\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,11]]},"references-count":25,"URL":"https:\/\/doi.org\/10.1109\/icin64016.2025.10943025","relation":{},"subject":[],"published":{"date-parts":[[2025,3,11]]}}}