arXiv · 2311.08274
Laccolith: Hypervisor-Based Adversary Emulation with Anti-Detection
Abstract
Advanced Persistent Threats (APTs) represent the most threatening form of attack nowadays since they can stay undetected for a long time. Adversary emulation is a proactive approach for preparing against these attacks. However, adversary emulation tools lack the anti-detection abilities of APTs. We introduce Laccolith, a hypervisor-based solution for adversary emulation with anti-detection to fill this gap. We also present an experimental study to compare Laccolith with MITRE CALDERA, a state-of-the-art solution for adversary emulation, against five popular anti-virus products. We found that CALDERA cannot evade detection, limiting the realism of emulated attacks, even when combined with a state-of-the-art anti-detection framework. Our experiments show that Laccolith can hide its activities from all the tested anti-virus products, thus making it suitable for realistic emulations.
Explore related subjects
Keep this discovery
Vittorio Orbinato, Marco Carlo Feliciano, Domenico Cotroneo, Roberto Natella. 2023-11-14. Laccolith: Hypervisor-Based Adversary Emulation with Anti-Detection. https://doi.org/10.1109/tdsc.2024.3376129
Cite the original work for its findings. Save a collection to share your selection of sources.