Τροποποίηση και αξιολόγηση σεναρίων adversary emulation στο MITRE CALDERA
Modifying and evaluating adversary emulation with MITRE CALDERA

View/ Open
Keywords
MITRE CALDERA ; Adversary emulation ; Προσομοίωση κυβερνοεπιθέσεων ; Χρονικές καθυστερήσεις ; Καλοήθης δραστηριότητα ; Ανίχνευση επιθέσεωνAbstract
This thesis examines the temporal and behavioral variation of adversary emulation scenarios using the MITRE CALDERA platform. The study focuses on investigating how the temporal distribution of offensive actions and the incorporation of benign activity affect the overall picture of a cyberattack scenario’s execution.
As part of the project, a controlled lab environment was created using Oracle VM VirtualBox, consisting of Kali Linux, Windows 10, and Debian virtual machines. The MITRE CALDERA Server, the Sandcat Agent, and the Wazuh platform were installed in this environment for collecting and monitoring events. The MITRE CALDERA Discovery Adversary Profile was used as the baseline scenario, to which two categories of modifications were applied: the introduction of time delays between specific actions and the incorporation of benign activity between steps in the scenario.
The evaluation was based on a comparison of the original scenario with the modified scenarios, through the analysis of CALDERA data, Windows Event Logs, and data collected by Wazuh. The study focused on the total execution duration, the temporal distribution of activity, and the detection delay observed through the Wazuh platform.
The results showed that, although the MITRE ATT&CK techniques used remained unchanged, the introduction of time delays and benign activity altered the temporal and behavioral profile of the scenario’s execution, contributing to the development of more realistic adversary emulation scenarios in the field of cybersecurity.


