| dc.contributor.advisor | Πατσάκης, Κωνσταντίνος | |
| dc.contributor.author | Λυμπέρη, Παναγιώτα - Αθηνά | |
| dc.date.accessioned | 2026-08-31T10:44:58Z | |
| dc.date.available | 2026-08-31T10:44:58Z | |
| dc.date.issued | 2026-07 | |
| dc.identifier.uri | https://dione.lib.unipi.gr/xmlui/handle/unipi/19697 | |
| dc.description.abstract | Η παρούσα πτυχιακή εργασία εξετάζει τη χρονική και συμπεριφορική διαφοροποίηση των σεναρίων adversary emulation με τη χρήση της πλατφόρμας MITRE CALDERA. Η μελέτη επικεντρώνεται στη διερεύνηση του τρόπου με τον οποίο η χρονική κατανομή των επιθετικών ενεργειών και η ενσωμάτωση καλοήθους δραστηριότητας επηρεάζουν τη συνολική εικόνα της εκτέλεσης ενός σεναρίου κυβερνοεπίθεσης.
Στο πλαίσιο της εργασίας δημιουργήθηκε ένα ελεγχόμενο εργαστηριακό περιβάλλον μέσω του Oracle VM Virtual Box, αποτελούμενο από Virtual Machines και ειδικότερα από τα Kali Linux, Windows 10 και Debian. Σε αυτό το περιβάλλον εγκαταστάθηκαν ο Server του MITRE CALDERA, ο Sandcat Agent και η πλατφόρμα Wazuh για την συλλογή και την παρακολούθηση των events. Ως βασικό σενάριο χρησιμοποιήθηκε το Discovery Adversary Profile του MITRE
CALDERA, στο οποίο εφαρμόστηκαν δύο κατηγορίες τροποποιήσεων: η εισαγωγή χρονικών καθυστερήσεων μεταξύ συγκεκριμένων ενεργειών και η ενσωμάτωση καλοήθους δραστηριότητας μεταξύ βημάτων του σεναρίου.
Η αξιολόγηση βασίστηκε στη σύγκριση του αρχικού σεναρίου με τα τροποποιημένα σενάρια, μέσω της ανάλυσης των καταγραφών του CALDERA, των Windows Event Logs και των δεδομένων που συλλέχθηκαν από το Wazuh. Η μελέτη επικεντρώθηκε στη συνολική διάρκεια της εκτέλεσης, στη χρονική κατανομή της δραστηριότητας και στον χρόνο πρώτης ανίχνευσης μέσω της πλατφόρμας Wazuh.
Τα αποτελέσματα έδειξαν ότι, παρότι οι τεχνικές του MITRE ATT&CK που χρησιμοποιήθηκαν παρέμειναν αμετάβλητες, η εισαγωγή χρονικών καθυστερήσεων και καλοήθους δραστηριότητας μετέβαλαν τη χρονική και συμπεριφορική εικόνα της εκτέλεσης του σεναρίου, συμβάλλοντας στη διαμόρφωση πιο ρεαλιστικών σεναρίων adversary emulation στο πεδίο της κυβερνοασφάλειας. | el |
| dc.format.extent | 59 | el |
| dc.language.iso | el | el |
| dc.publisher | Πανεπιστήμιο Πειραιώς | el |
| dc.rights | Αναφορά Δημιουργού-Μη Εμπορική Χρήση-Όχι Παράγωγα Έργα 3.0 Ελλάδα | * |
| dc.rights | Αναφορά Δημιουργού-Μη Εμπορική Χρήση-Όχι Παράγωγα Έργα 3.0 Ελλάδα | * |
| dc.rights.uri | http://creativecommons.org/licenses/by-nc-nd/3.0/gr/ | * |
| dc.title | Τροποποίηση και αξιολόγηση σεναρίων adversary emulation στο MITRE CALDERA | el |
| dc.title.alternative | Modifying and evaluating adversary emulation with MITRE CALDERA | el |
| dc.type | Bachelor Dissertation | el |
| dc.contributor.department | Σχολή Τεχνολογιών Πληροφορικής και Επικοινωνιών. Τμήμα Πληροφορικής | el |
| dc.description.abstractEN | This thesis examines the temporal and behavioral variation of adversary emulation scenarios using the MITRE CALDERA platform. The study focuses on investigating how the temporal distribution of offensive actions and the incorporation of benign activity affect the overall picture of a cyberattack scenario’s execution.
As part of the project, a controlled lab environment was created using Oracle VM VirtualBox, consisting of Kali Linux, Windows 10, and Debian virtual machines. The MITRE CALDERA Server, the Sandcat Agent, and the Wazuh platform were installed in this environment for collecting and monitoring events. The MITRE CALDERA Discovery Adversary Profile was used as the baseline scenario, to which two categories of modifications were applied: the introduction of time delays between specific actions and the incorporation of benign activity between steps in the scenario.
The evaluation was based on a comparison of the original scenario with the modified scenarios, through the analysis of CALDERA data, Windows Event Logs, and data collected by Wazuh. The study focused on the total execution duration, the temporal distribution of activity, and the detection delay observed through the Wazuh platform.
The results showed that, although the MITRE ATT&CK techniques used remained unchanged, the introduction of time delays and benign activity altered the temporal and behavioral profile of the scenario’s execution, contributing to the development of more realistic adversary emulation scenarios in the field of cybersecurity. | el |
| dc.subject.keyword | MITRE CALDERA | el |
| dc.subject.keyword | Adversary emulation | el |
| dc.subject.keyword | Προσομοίωση κυβερνοεπιθέσεων | el |
| dc.subject.keyword | Χρονικές καθυστερήσεις | el |
| dc.subject.keyword | Καλοήθης δραστηριότητα | el |
| dc.subject.keyword | Ανίχνευση επιθέσεων | el |
| dc.date.defense | 2026-07-10 | |