An Empirical Study of Automated Adversary Emulators
| dc.contributor.author | Holm, Hannes | |
| dc.contributor.author | Helgeson, Lars | |
| dc.date.accessioned | 2025-12-23T16:40:14Z | |
| dc.date.available | 2025-12-23T16:40:14Z | |
| dc.date.issued | 2026-01-06 | |
| dc.description.abstract | Automated adversary emulators are increasingly researched and applied, but their effectiveness remains unclear. This paper empirically evaluates four emulators using data collected from 1700 hours of tests within a cyber range: Caldera, Deep Exploit, Infection Monkey, and Lore. The outcome from each test was scored according to fulfillment of different tactics in MITRE ATT&CK. The results show that Lore consistently discovered all machines and compromised 97% on average. Caldera discovered 27% and compromised 7%, Infection Monkey discovered 23% but compromised none, and Deep Exploit neither discovered nor compromised any machine. All emulators generated similar intrusion alerts except Caldera, which triggered significantly more when starting with elevated privileges. | |
| dc.format.extent | 10 pages | |
| dc.identifier.doi | https://doi.org/10.24251/HICSS.2026.834 | |
| dc.identifier.isbn | 978-0-9981331-9-5 | |
| dc.identifier.other | b1107fa5-5fc6-4f35-af72-70a46ef12fc9 | |
| dc.identifier.uri | https://hdl.handle.net/10125/112239 | |
| dc.language.iso | eng | |
| dc.relation.ispartof | Proceedings of the 59th Hawaii International Conference on System Sciences | |
| dc.rights | Attribution-NonCommercial-NoDerivatives 4.0 International | |
| dc.rights.uri | https://creativecommons.org/licenses/by-nc-nd/4.0/ | |
| dc.subject | AI-Powered Cyber Attacks and Countermeasures | |
| dc.subject | automated adversary emulation | |
| dc.subject | experiments | |
| dc.subject | network security | |
| dc.title | An Empirical Study of Automated Adversary Emulators | |
| dc.type | Conference Paper | |
| dc.type.dcmi | Text | |
| prism.startingpage | 7028 |
Files
Original bundle
1 - 1 of 1
