A Large-Scale Analysis of Attacker Activity in Compromised Enterprise Accounts
Neil Shah, Grant Ho, Marco Schweighauser, M.H. Afifi, Asaf Cidon,, David Wagner

TL;DR
This study analyzes attacker behavior in compromised enterprise accounts across 111 organizations, introducing a novel forensic technique to distinguish malicious activity, revealing attacker dwell times, access patterns, and market dynamics, informing improved detection strategies.
Contribution
The paper presents a new forensic method for accurately identifying attacker activity in enterprise accounts and provides large-scale insights into attacker behavior and market dynamics.
Findings
Attackers often remain active for days to weeks.
Two distinct attacker access modalities suggest a hijacked account market.
Delayed detection can still be effective in identifying attacks.
Abstract
We present a large-scale characterization of attacker activity across 111 real-world enterprise organizations. We develop a novel forensic technique for distinguishing between attacker activity and benign activity in compromised enterprise accounts that yields few false positives and enables us to perform fine-grained analysis of attacker behavior. Applying our methods to a set of 159 compromised enterprise accounts, we quantify the duration of time attackers are active in accounts and examine thematic patterns in how attackers access and leverage these hijacked accounts. We find that attackers frequently dwell in accounts for multiple days to weeks, suggesting that delayed (non-real-time) detection can still provide significant value. Based on an analysis of the attackers' timing patterns, we observe two distinct modalities in how attackers access compromised accounts, which could be…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
