{"as_of":"2026-08-13T17:34:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:90f2378224dfc49d774746a5f759a94e25cbc7509cd7e5d0b416c12e119b4faa","coverage":[{"denominator":129,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":100,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-07T23:35:22.985699Z","state":"measured"},{"denominator":101,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":101,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-13T06:32:02.005865+00:00","state":"measured"},{"denominator":1,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":1,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-05T10:43:07.700563Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":1,"source":"pith","source_observed_at":"2026-08-10T05:30:23.456663Z","state":"measured"}],"external_citation_measurements":[{"count":0,"observed_at":"2026-08-10T05:30:23.456663Z","source":"pith"}],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"cited_work":{"arxiv_id":"2502.08830","doi":"10.48550/arxiv.2502.08830","metadata_source":"pith","pith_arxiv_id":"2502.08830","snapshot_observed_at":"2026-08-10T05:30:23.456663Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","venue":"cs.CR","work_id":"e66ab25c-4ae7-4bac-857c-338b5362c0eb","year":2025},"citing_paper":{"arxiv_id":"2509.03806","last_updated":"2025-09-04T01:47:22Z","snapshot_observed_at":"2026-08-11T21:03:47.375897Z","submitted_at":"2025-09-04T01:47:22Z","title":"Peekaboo, I See Your Queries: Passive Attacks Against DSSE Via Intermittent Observations","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-05T10:43:07.700563Z"},"links":{"cited_paper":"/paper/2502.08830","citing_paper":"/paper/2509.03806"},"observation_digest":"sha256:9823efbff80da8d2fb1c36152045a9f9d4846003e8d0f79e12bda28e51a2dae1","observation_id":"f0e1ee45-9e25-4aa5-a5d3-00e07699e6ed","resolution":{"observed_at":"2026-08-05T10:43:13.031329Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2502.08830/citation-record","integrity":"/paper/2502.08830/integrity","json":"/paper/2502.08830/citation-record.json","paper":"/paper/2502.08830"},"outbound":[{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.646244Z","title":"Computer security incident handling guide,","venue":null,"work_id":null,"year":2012},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.646244Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:ea2a622979a6c4768c0b1aa1c4a55ab1a25547676fe4e5d2726a52ef4fcaf185","observation_id":"9c57aa00-ad48-4f80-856f-116966edf673","resolution":{"observed_at":"2026-08-07T23:35:22.646244Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.649796Z","title":"Advanced persistent threats and how to monitor and deter them,","venue":null,"work_id":null,"year":2011},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.649796Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:4c59fe89b95333a5884eff19711bf1c38dbd8c1d6ebb961faf8e2afbc4677a8b","observation_id":"f6fbc5fa-2ece-44eb-8ba9-55bd2605fe50","resolution":{"observed_at":"2026-08-07T23:35:22.649796Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.652801Z","title":"APT 1: Exposing one of china’s cyber espionage units,","venue":null,"work_id":null,"year":2013},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.652801Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:975ae554d0e7038e36842eb5c2c34eb0707bb4ed801750962750abc5f9b9f349","observation_id":"8b8f1ff0-7567-4676-917d-7989628b78f0","resolution":{"observed_at":"2026-08-07T23:35:22.652801Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.656937Z","title":"E ARLYCROW: Detecting APT malware command and control over HTTP(S) using contextual summaries,","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.656937Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:4159023560eb49c8b2621509347626f7271b574b423a343fea90cb02e9c3dd37","observation_id":"dbf8544b-0f63-440d-98c1-6d0eaa8adb9f","resolution":{"observed_at":"2026-08-07T23:35:22.656937Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.660856Z","title":"Apt beaconing detection: A systematic review,","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.660856Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:88abcc3b96e3e5016e6cf086882993280443a2171833bddc21fadfefca2c510d","observation_id":"44dd7f4e-07d4-4903-810e-bc2432c9d18a","resolution":{"observed_at":"2026-08-07T23:35:22.660856Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.664769Z","title":"Survey of publicly available reports on advanced persistent threat actors,","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.664769Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:86ae0ab3724949bee1b7c853de94fc2e35a75c302feccc2cb4911883e0bd31cb","observation_id":"26d74dcc-d828-4301-bb7a-cc34d61077ca","resolution":{"observed_at":"2026-08-07T23:35:22.664769Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.669497Z","title":"Apt datasets and attack modeling for automated detection methods: A review,","venue":null,"work_id":null,"year":2020},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.669497Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:c5a1e6ccd5eea43d18e464400534ea71d426a6f850410b7ffb6c9828901d256f","observation_id":"2e4651e9-8634-4e92-9a51-69ec776d23c6","resolution":{"observed_at":"2026-08-07T23:35:22.669497Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.673739Z","title":"A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities,","venue":null,"work_id":null,"year":2019},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.673739Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:302764a170faa07a6500a54cb6d6e7fe0d60b263c15375af580d7b9c5f50ed06","observation_id":"ca5b8936-1f69-475a-a019-3688c8e476bf","resolution":{"observed_at":"2026-08-07T23:35:22.673739Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.677087Z","title":"Finding cyber threats with att&ck™-based analytics,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.677087Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:19674f64c8a667bc325a1e2c4bf3d33b6bca4fcb6531ebc87576771082722777","observation_id":"d4d77364-3308-4f12-a098-17f25154762a","resolution":{"observed_at":"2026-08-07T23:35:22.677087Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.680544Z","title":"APT 28 under the scope a journey into exfiltrating intelligence and government information,","venue":null,"work_id":null,"year":2015},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.680544Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:ac7e1df30232da5de39e91974919a1636a2163249c0165e99456ba942826ab88","observation_id":"733c086f-0cae-4243-9f21-f4f815628219","resolution":{"observed_at":"2026-08-07T23:35:22.680544Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.684073Z","title":"Sednit update: How fancy bear spent the year","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.684073Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:f05a2aff7de4ead53103a718a95c6e9eb26f588923bfc240ab55d710c7111771","observation_id":"1b7632a8-d432-4094-b1bd-b123a2512059","resolution":{"observed_at":"2026-08-07T23:35:22.684073Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.687388Z","title":"Operation cobalt kitty: A large-scale APT in asia carried out by the oceanlotus group","venue":null,"work_id":null,"year":2019},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.687388Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:25e907d950d4721f186cca8dbcc684429b76306c5882a2ecbdcd44ab954a7836","observation_id":"457c0c5b-0ff9-4da0-9399-49f4aa47b490","resolution":{"observed_at":"2026-08-07T23:35:22.687388Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.690823Z","title":"Operation cobalt kitty cybereason labs analysis,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.690823Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:c1a206d58e918b95ee07458f1d3e79875889eaa13276ebec9187afda609ed85f","observation_id":"559bef54-cdee-4aca-b157-c6b0d68bbb82","resolution":{"observed_at":"2026-08-07T23:35:22.690823Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.694189Z","title":"The dukes 7 years of russian cyberespionage,","venue":null,"work_id":null,"year":2016},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.694189Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:eb50595feab080c52c0105c46666487b243a2d9df7d928c886a4b61c083401f6","observation_id":"59a11d99-26d9-47e5-bfd7-58f266b8aa06","resolution":{"observed_at":"2026-08-07T23:35:22.694189Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.697559Z","title":"Bears in the midst: Intrusion into the democratic national committee","venue":null,"work_id":null,"year":2019},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.697559Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:e361a4b0e8d26c89c937c1e61bb9943bf579743364cedc6cd7f60c5935bb6b4b","observation_id":"7cccd95a-36bc-4c61-b953-b48d8ecafb74","resolution":{"observed_at":"2026-08-07T23:35:22.697559Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.700856Z","title":"Buckeye cyberespionage group shifts gaze from us to hong kong","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.700856Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:dc70c6d68dc8160bfe1b030e5bb328d277989a1b60641def78dcc2d7b3f8383f","observation_id":"b665c94f-c363-42e4-b70e-10d3f00cb9bb","resolution":{"observed_at":"2026-08-07T23:35:22.700856Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.707896Z","title":"Where you at?: Indicators of lateral movement using at.exe on windows 7 systems","venue":null,"work_id":null,"year":2014},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.707896Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:6adf5c258d7c01e9c05bb64016a769f59ae496f3cfbb5f5159188c77212bfd6e","observation_id":"550d7160-e059-4e31-b673-3d37c21a8412","resolution":{"observed_at":"2026-08-07T23:35:22.707896Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.711390Z","title":"Evasive maneuvers by the wekby group with custom rop-packing and dns covert channels","venue":null,"work_id":null,"year":2015},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.711390Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:7b4334aac4fe900320437d3518f5bf7ecffcd452be52ed19c9b751ed3b0eadc9","observation_id":"9dc5709d-3ca2-4ddd-b9ee-0f010b085555","resolution":{"observed_at":"2026-08-07T23:35:22.711390Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.714825Z","title":"APT 37 (reaper) the overlooked north korean actor, special report,","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.714825Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:ee607ca5bbb8f9b13f3cfb4fc5e0525c4b756a5c89ee99b172be57b2dad6aa9c","observation_id":"5f65e229-6482-45dc-be57-e81d8151b3a0","resolution":{"observed_at":"2026-08-07T23:35:22.714825Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.718563Z","title":"A taxonomy of botnet behavior, detection, and defense,","venue":null,"work_id":null,"year":2013},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.718563Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:5cc970bced924c6dd8ce947f4d0677ba92d1c2ae0b8934204b77dc8d1fa30178","observation_id":"0f873496-590a-49e6-b8b6-64fe98841de2","resolution":{"observed_at":"2026-08-07T23:35:22.718563Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.722240Z","title":"Detecting APT malware infections based on malicious dns and traffic analysis,","venue":null,"work_id":null,"year":2015},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.722240Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:4abbcbeb764596e75207b0d6b7546eb772b3cecb59ec3774049e7a79bdeb2a5e","observation_id":"3735ab84-30c3-4d12-8b9c-46940332a6fd","resolution":{"observed_at":"2026-08-07T23:35:22.722240Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.725929Z","title":"Botnet communication patterns,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.725929Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:d9227b8040bbd4fc02b1066b1d66abae3021451ec403221abec90d359edb9205","observation_id":"bd0f8f98-191a-4233-8946-79a680f90ec6","resolution":{"observed_at":"2026-08-07T23:35:22.725929Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.729365Z","title":"Advanced persistent threats: Behind the scenes,","venue":null,"work_id":null,"year":2016},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.729365Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:c67bec091c423f39b1635390b87f718de88c5518a3e3566266f28624d1150daa","observation_id":"1670e588-ecb1-4bcd-b389-21870d3c01a7","resolution":{"observed_at":"2026-08-07T23:35:22.729365Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.733120Z","title":"A study on advanced persistent threats,","venue":null,"work_id":null,"year":2014},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.733120Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:42281771119834eecbd6310c38155988b1ba619c473411ce8a1a4050af54a326","observation_id":"93133b80-0bbc-4c5a-a16f-0e0f70e84081","resolution":{"observed_at":"2026-08-07T23:35:22.733120Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.736564Z","title":"H AWK-E YE: Holistic detection of APT command and control domains,","venue":null,"work_id":null,"year":2021},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.736564Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:e5cb8b1126778d4c0cc41d13067390cdce74dfe182d522e8f1806bee162f7cc6","observation_id":"9a5e5e43-6110-41df-8798-b63fc1c41146","resolution":{"observed_at":"2026-08-07T23:35:22.736564Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.740118Z","title":"Intelligence- driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains,","venue":null,"work_id":null,"year":2011},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.740118Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:50d8503c110e8d35f6bab575cf61465ba7dd10493a761376d86749674f7d9aa8","observation_id":"47d5f66f-b919-42db-b644-5d43cb3395ed","resolution":{"observed_at":"2026-08-07T23:35:22.740118Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.743064Z","title":"Sys- tems for detecting advanced persistent threats: A development roadmap using intelligent data analysis,","venue":null,"work_id":null,"year":2012},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.743064Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:0e0476694a8b52a598a4351111f89e136ca76bfffe73bae66d6cff93b8e766d6","observation_id":"b4a13848-5953-464f-b785-54af61e73208","resolution":{"observed_at":"2026-08-07T23:35:22.743064Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.745923Z","title":"A context-based detection framework for advanced persistent threats,","venue":null,"work_id":null,"year":2012},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.745923Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:eda47428f7d4ae57d062cad00f3962d10313609d5ba1ae61ea7b7ba5302f6e2b","observation_id":"2090bc96-4e18-4d54-a396-a3d4ff6a8375","resolution":{"observed_at":"2026-08-07T23:35:22.745923Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.748658Z","title":"Technical aspects of cyber kill chain,","venue":null,"work_id":null,"year":2015},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.748658Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:2e9f5a0f0fee8b344a33eeb188545032effec0dff357aa9ed634cc9c93efb688","observation_id":"e46e959e-cd60-447f-a63f-e819d33cfbea","resolution":{"observed_at":"2026-08-07T23:35:22.748658Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.751572Z","title":"A cyber kill chain based taxonomy of banking trojans for evolutionary computational intelligence,","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.751572Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:521329e77737f5c5c502280b24c4088adf10ad37ef2f4d0bbaaf4b036f06017d","observation_id":"ada5b21f-f2eb-4e27-92d5-f80e058aa7f1","resolution":{"observed_at":"2026-08-07T23:35:22.751572Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.754608Z","title":"A markov multi- phase transferable belief model: An application for predicting data exfiltration apts,","venue":null,"work_id":null,"year":2013},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.754608Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:95182120ac733fedf05aed66f05caf2bc24a38c5a07d3514cf24e3e5eed99fb1","observation_id":"00d5f55d-5360-484d-843c-85637fa2f2d9","resolution":{"observed_at":"2026-08-07T23:35:22.754608Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1810.01594","last_updated":"2019-01-17T23:08:35Z","snapshot_observed_at":"2026-07-06T07:05:47.165490Z","submitted_at":"2018-10-03T06:10:33Z","title":"HOLMES: Real-time APT Detection through Correlation of Suspicious Information Flows","version":2},"cited_work":{"arxiv_id":"1810.01594","doi":null,"metadata_source":"pith","pith_arxiv_id":"1810.01594","snapshot_observed_at":"2026-08-07T23:35:23.257043Z","title":"HOLMES: Real-time APT Detection through Correlation of Suspicious Information Flows","venue":"cs.CR","work_id":"57ec43b5-d00e-4c25-a36a-e9945e9d344f","year":2018},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.757252Z"},"links":{"cited_paper":"/paper/1810.01594","citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:f2f5faebb52f36bc1f5c165cb5fe4b152a7d8782d0edcb05007a7658c6ae0980","observation_id":"c4862444-ee8f-4b4e-be5a-73f610d7e804","resolution":{"observed_at":"2026-08-07T23:35:23.262031Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.760498Z","title":"Situation awareness of multistage cyber attacks by semantic event fusion,","venue":null,"work_id":null,"year":2010},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.760498Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:ce253c4d07f50eca5f42d84d4ce4d896334cb8465e97b5bf1035d651f300bbef","observation_id":"a2cc9170-4c33-457d-b7d6-746e6008df24","resolution":{"observed_at":"2026-08-07T23:35:22.760498Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.763445Z","title":"Dark matter: Uncovering the darkcomet rat ecosystem,","venue":null,"work_id":null,"year":2020},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.763445Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:2b3911fe5c338a5432c76c1f0d9d4c658ab042500fe7cee4745b0b965d14c9c1","observation_id":"5c7227f8-b9f5-4956-b997-4d339ced4343","resolution":{"observed_at":"2026-08-07T23:35:22.763445Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.766228Z","title":"Schrödinger’s RAT: Profiling the stakeholders in the remote access trojan ecosystem,","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.766228Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:f244deb013b8a050d286cda3a28d064a5af94b1319909ff82bfe7df1329d09fd","observation_id":"088b0357-b5fb-463c-bcc9-8e04a8609b34","resolution":{"observed_at":"2026-08-07T23:35:22.766228Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.769772Z","title":"To catch a ratter: Monitoring the behavior of amateur darkcomet rat operators in the wild,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.769772Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:f4aec38176df78bab85a55fbef2ba862946e0e83ce06c62d67729d6e07bb5031","observation_id":"e9283908-d2d6-4fea-9648-5569fbdb7deb","resolution":{"observed_at":"2026-08-07T23:35:22.769772Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.773305Z","title":"Fin7.5: the infamous cybercrime rig “fin7","venue":null,"work_id":null,"year":2021},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":37,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.773305Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:327299155f379b8cddded944e95daaf4a744fd3c9539b21b4bbf5a5c9627dc79","observation_id":"b9c6c9eb-cd12-4c52-9248-fc2d6f6b9012","resolution":{"observed_at":"2026-08-07T23:35:22.773305Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.776681Z","title":"The elderwood project,","venue":null,"work_id":null,"year":2012},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.776681Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:fdf1b202e932499bac101c8002dd47554c50aa8734308130fe10e521a52aa702","observation_id":"6bef525e-c2bb-42aa-8b77-d86bda599683","resolution":{"observed_at":"2026-08-07T23:35:22.776681Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.779947Z","title":null,"venue":null,"work_id":null,"year":2014},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":39,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.779947Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:233a84677cc63d5d7c05e49b9f6bbf0affcb20937a1e7b12b4c0f3954c3d4f08","observation_id":"3d8e3262-c220-487b-a188-6db6bcbc8532","resolution":{"observed_at":"2026-08-07T23:35:22.779947Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.783373Z","title":"APT 3 adversary emulation plan,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":40,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.783373Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:14d1f2885a1ac30b427b6ded5f9921a0a0f94533e07088d49ac2d95524b44164","observation_id":"77f6cbda-f8c6-46e9-aa74-de57a6edfc9d","resolution":{"observed_at":"2026-08-07T23:35:22.783373Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.786811Z","title":"Opera- tion double tap","venue":null,"work_id":null,"year":2014},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":41,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.786811Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:7f71ef614c109c0ba28422dd71f5f04ed58bde0e5d6a78edfad6e9a6cf0fdf39","observation_id":"49ed2836-8205-4338-95db-2011fb6f1163","resolution":{"observed_at":"2026-08-07T23:35:22.786811Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.790463Z","title":"Yates, APT 3 Uncovered: The code evolution of Pirpi","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":42,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.790463Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:adc3e3ed90e25041db505bf62cbb1e9bdd49ecc54425d6df8a7bbd2c6a764c0e","observation_id":"96bfe9b6-781c-4f5a-bd9c-8c735eac2470","resolution":{"observed_at":"2026-08-07T23:35:22.790463Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.793979Z","title":"Operation cloud hopper,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":43,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.793979Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:7a2b46599a409e0bcb31adc047459e24a6a088c04fabcd096fa21869c61493a1","observation_id":"c7963bd8-b53d-4a05-93a8-4311f68bc303","resolution":{"observed_at":"2026-08-07T23:35:22.793979Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.797392Z","title":"Operation cloud hopper technical annex,","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":44,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.797392Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:d52e6809538a54287520fe048e9bcb1c8775953c180f6b43454dc031e6e407da","observation_id":"88499f63-3d13-4034-8301-66d667d8d828","resolution":{"observed_at":"2026-08-07T23:35:22.797392Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.800795Z","title":"Darwin’s favorite APT group","venue":null,"work_id":null,"year":2014},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":45,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.800795Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:9cd43b08c0dcea757dcb5286971804395e2a532b3976a07177458056fd51d6dc","observation_id":"f7791d48-2da0-4b79-aec7-3e8ee3cd59f7","resolution":{"observed_at":"2026-08-07T23:35:22.800795Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.804162Z","title":"Operation “ke3chang","venue":null,"work_id":null,"year":2014},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":46,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.804162Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:5dfa513cd408bf57bc2db57282ed2c68da93433f67a9d9ecd2c78b389e9e5233","observation_id":"889bef84-fd73-444b-90c6-b848f82f9e60","resolution":{"observed_at":"2026-08-07T23:35:22.804162Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.807430Z","title":"Apt15 is alive and strong: An analysis of royalcli and royaldns","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":47,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.807430Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:46254300af1657a8b600647dc9f5355f1e54f8b611d62fcd70e57f32ba4ba2cb","observation_id":"96eac31c-9585-4fca-b411-6de730f30820","resolution":{"observed_at":"2026-08-07T23:35:22.807430Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.810781Z","title":"The eps awakens - part 2","venue":null,"work_id":null,"year":2015},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":48,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.810781Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:3f81badbc4fa5a37c3c6c838e6d18de72f66a708b4d84778c54d4b4e600357a3","observation_id":"edda471e-64f2-44ff-a4d0-04db47b7f20d","resolution":{"observed_at":"2026-08-07T23:35:22.810781Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.813955Z","title":"The eps awakens","venue":null,"work_id":null,"year":2015},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":49,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.813955Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:1c7f2374922848ec3fa1031fd083020a769bbf4421d3572100c47f556cc9612f","observation_id":"089facba-2eed-4b2e-95b3-c7e5ab59c5da","resolution":{"observed_at":"2026-08-07T23:35:22.813955Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:24.058088Z","title":"Hiding in plain sight: Fireeye and microsoft expose,","venue":null,"work_id":"562232fa-ff2f-4bc1-930d-2899f60f65af","year":2015},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":50,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.817580Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:cbdafadbbf37653835d6875d8c0284048c83af6a2e23426c592933cb550aeb42","observation_id":"0162fc42-0a6d-4dd1-b79e-2f505ae2ecda","resolution":{"observed_at":"2026-08-07T23:35:24.061542Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:24.048176Z","title":"New attacks linked to c0d0so0 group","venue":null,"work_id":"01f4ce4e-f197-47df-94de-b68469eb9773","year":2019},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":51,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.820883Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:49e848c392bf8ac640a0bd98e6aeb6f4a56c17aac9ddd8c95750fa95a909d613","observation_id":"500366d1-ec44-4bc3-8ebc-21f2342a6558","resolution":{"observed_at":"2026-08-07T23:35:24.051434Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:24.038508Z","title":"Privileges and credentials: Phished at the request of counsel","venue":null,"work_id":"50a2c114-8515-429a-ae57-3989924a1486","year":2017},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":52,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.823961Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:bc29e286945dc984ffeb10c176187c7f46235d9bc24ca08c58fa2c5da4637c3e","observation_id":"46aa87c4-92af-4889-860c-c66bf966c382","resolution":{"observed_at":"2026-08-07T23:35:24.041928Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:24.029009Z","title":"Threat group 3390 cyberespionage","venue":null,"work_id":"a9cce89b-e30d-49db-9519-221433749951","year":2015},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":53,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.827255Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:b4a1a574a59f3f103a9016cca1f0da7c0411ae6bc6b2aef4d0e82b89cd0584d1","observation_id":"aea56fbd-b22c-4460-a3b5-e49925e0af0f","resolution":{"observed_at":"2026-08-07T23:35:24.032374Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:24.018807Z","title":"Bronze union cyberespionage persists despite dis- closures","venue":null,"work_id":"7738cf47-dc05-44f1-aaf1-7634505943f6","year":null},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":54,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.830548Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:29052798720a600cc4f888dbf57dfb94e55798da324d9a5762f5867ec6b31858","observation_id":"fd7412c8-96c1-41cd-ad2d-12edaedd2876","resolution":{"observed_at":"2026-08-07T23:35:24.022572Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:24.008998Z","title":"Luckymouse hits national data center to organize country- level waterholing campaign","venue":null,"work_id":"e09dbcd9-e9da-4836-b3fa-ee158244e23b","year":2018},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":55,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.837202Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:1fe0f60a7f39438b0dc56a4e0d39528e1c86faa1bf41ffa5acf375d4e0cb9c4c","observation_id":"14f3f2e3-b2de-4a70-8385-fef0e3fcf423","resolution":{"observed_at":"2026-08-07T23:35:24.012610Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.998739Z","title":"APT 28: A window into russia’s cyber espionage operations and a special report,","venue":null,"work_id":"f48bbc9f-f767-4e8a-a41a-90bc9db7a5f3","year":2014},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":56,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.840452Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:80375d488b560487af61903b21f3b1fddddfabbb38352e7f7d850f1d92711d04","observation_id":"b80f38af-a5c5-4f02-8a71-2d6c0d91256e","resolution":{"observed_at":"2026-08-07T23:35:24.002647Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.988601Z","title":"Anthe, P","venue":null,"work_id":"1d6e9095-195f-4b82-8925-c19b4a443fae","year":2015},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":57,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.843999Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:83d6acac339a780728f06b37bb253062239c02e68dc7501ccb9cd910542bae7b","observation_id":"bb1b8239-767e-4843-8643-4592ce52f6b1","resolution":{"observed_at":"2026-08-07T23:35:23.992106Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.978917Z","title":"APT 28: New espionage operations target mili- tary and government organizations","venue":null,"work_id":"ecd6153c-54e3-4737-9020-50ca3cb5daa8","year":2018},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":58,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.847334Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:532d4b3df9d5b9d857cf8980e4ab45455477ad451d5053558d905c4bff772b74","observation_id":"8b194009-b595-480b-97d3-77819e8de76d","resolution":{"observed_at":"2026-08-07T23:35:23.982385Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.968721Z","title":"Lab, En Route with Sednit Part 2: Observing the Comings and Goings, vol","venue":null,"work_id":"333f1084-5496-4e2c-82df-38e52cc514e9","year":2016},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":59,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.850748Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:7db27af7ab607d97b6c902ee979cc5577a15bbf49045b56047cd4c60b8d025df","observation_id":"1eed2df5-ef85-45b2-aef1-5299c4cf42a6","resolution":{"observed_at":"2026-08-07T23:35:23.972106Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.959400Z","title":"Grizzly steppe – russian malicious cyber activity,","venue":null,"work_id":"753f9ee7-32a5-4486-88cf-6048f30bd672","year":2016},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":60,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.854093Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:63f827695e7a588c2fd0180119b29cc1ecc57f136c0c34c7238b37a459025720","observation_id":"e72371ff-25c7-471d-91bd-08deacfa8704","resolution":{"observed_at":"2026-08-07T23:35:23.962776Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.949841Z","title":"Not so cozy: An uncomfortable examination of a suspected apt29 phishing campaign","venue":null,"work_id":"b1709610-81e5-4f52-b431-b7d2e5940cad","year":2018},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":61,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.857376Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:a314a9bab353c2546586c7585d61e0a789f431cc438667da466140671ce48182","observation_id":"11758e14-513e-4f5e-915f-e4de340eb31a","resolution":{"observed_at":"2026-08-07T23:35:23.953303Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.939865Z","title":"Labs, APT 30 and the mechanics of a long-running cyber espionage operation","venue":null,"work_id":"e6787278-ed0a-4d1e-83c9-6c4152fbceb8","year":2015},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":62,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.860736Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:e8a4f7ea18aeba37723f64c44bec8f82049cbe218cedf0f0a455b8a82dca98d7","observation_id":"2fa29983-8a0a-41e3-967a-676bdc3d8609","resolution":{"observed_at":"2026-08-07T23:35:23.943399Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.929370Z","title":"Fake or fake: Keeping up with oceanlotus decoys","venue":null,"work_id":"a397da32-3146-4612-af7e-5fc5bd529915","year":2019},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":63,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.864169Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:088108d9e296cbfc4c628d3d321c1881625a6920428938a6a89228cc8265486c","observation_id":"e6a66b9e-d591-4415-8621-6d2c6b4b5cfe","resolution":{"observed_at":"2026-08-07T23:35:23.933158Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.918764Z","title":"Cyber espionage is alive and well: APT 32 and the threat to global corporations","venue":null,"work_id":"0574e262-7ad3-4a33-90a0-5709ddd4e901","year":2017},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":64,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.867017Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:44ef30ef98254e6945a8c07d478067136454a98bc5aedfbef9d4af34f14ad907","observation_id":"b7f330ac-5d55-4299-a455-80e37500703c","resolution":{"observed_at":"2026-08-07T23:35:23.922770Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.908342Z","title":"Insights into iranian cyber espionage: APT 33 targets aerospace and energy sectors and has ties to destructive malware","venue":null,"work_id":"8bc72f9a-1a9e-4c6e-afa2-860f29497b8e","year":2017},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":65,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.870160Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:2576433f87f81602e73096aae9363ccf2eb27c6f310d08a68a9decaef3cbe9fc","observation_id":"a0ae1323-cb1c-4dbc-b5fe-425fd6ef6b24","resolution":{"observed_at":"2026-08-07T23:35:23.912076Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.898185Z","title":"Elfin: Relentless espionage group targets multiple organizations in saudi arabia and u.s","venue":null,"work_id":"6ed19837-55ee-45ee-a3fb-b1840f83bf86","year":2019},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":66,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.872986Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:3f7c7a2e3703f0f9bfefeb0ff9127c164f0649a34f2b27eacba627d8d9fc24dc","observation_id":"61e45b20-2335-43a6-8af8-3bba8a6314d9","resolution":{"observed_at":"2026-08-07T23:35:23.901734Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.887977Z","title":"Overruled: Containing a potentially destructive adversary","venue":null,"work_id":"60d0f789-60b9-4f16-9f13-f18a6f13a12f","year":2018},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":67,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.875829Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:625faacca78d707bfec03f24dda378f32a5493297993d303cf086fa8b0e78187","observation_id":"0a8f6610-9129-441f-9996-f2c81d277cbc","resolution":{"observed_at":"2026-08-07T23:35:23.891613Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.877969Z","title":"New targeted attack in the middle east by apt34, a suspected iranian threat group, using cve-2017-11882 ex- ploit","venue":null,"work_id":"cfa7bf3c-ba14-4b55-bfa1-025a17ce7fcf","year":2017},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":68,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.878540Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:f15f7d73e1d56d7beffb359093ec0b440235d2baa67df9f3539bbd48f3985ad7","observation_id":"b4bb269f-b664-4df3-a1fd-2d6697f220c8","resolution":{"observed_at":"2026-08-07T23:35:23.881723Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.867740Z","title":"Oilrig uses ismdoor variant; possibly linked to greenbug threat group","venue":null,"work_id":"7a5f7a7b-3d6e-4081-9362-c462244bde20","year":2019},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":69,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.881175Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:1b8c08b65e9778a17606ff559f35172138477c96edada0da96cc6a5a458a02e4","observation_id":"8e3fe395-ecda-46bc-8daa-2b70cc747902","resolution":{"observed_at":"2026-08-07T23:35:23.871471Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.857267Z","title":"Rocket kitten: A campaign with 9 lives,","venue":null,"work_id":"75294dfc-4617-4976-b564-048f597885f9","year":2015},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":70,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.883773Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:e1509d1d5bc938bb8b404b959ac1ac35de012a08d5f9db2cedfa241f566df309","observation_id":"9b6c96bb-146b-4133-ae9d-b5fdaa4c0409","resolution":{"observed_at":"2026-08-07T23:35:23.861016Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.846934Z","title":"China-based cyber threat group uses drop- box for malware communications and targets hong kong media outlets","venue":null,"work_id":"ed06592f-d4b5-4202-a19b-67c82a6a67ca","year":2015},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":71,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.886414Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:564c6c1f111c564ae7007d63f3ba5867adf6c32e970a566b4924ee39e488b34b","observation_id":"5772b97e-7a4f-4946-94b5-84d52341687a","resolution":{"observed_at":"2026-08-07T23:35:23.850743Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.835895Z","title":"Operation blockbuster: Unraveling the long thread of the sony attack,","venue":null,"work_id":"32fe7d07-d8a7-4ee2-84c6-d10dfeaf40a0","year":2017},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":72,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.889071Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:d16a9c6dc0fb87bba3b7c0657f4d8ffe641cf5e9a3cd80556890a33ab8c1beb4","observation_id":"87db63c7-14e6-495d-baa7-f2634fef91f1","resolution":{"observed_at":"2026-08-07T23:35:23.840073Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.825288Z","title":"Operation blockbuster: Remote administration tools and content staging malware report,","venue":null,"work_id":"7a3671f7-40ff-4c21-bb4e-7f2b4ea30f9b","year":2017},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":73,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.891980Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:a6493e694e98e19a29021f43b7ccbacc351115f9acb9e3cab71deb92641c7c4e","observation_id":"6da56f66-73b6-431e-acbe-0412ec9bb551","resolution":{"observed_at":"2026-08-07T23:35:23.828861Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.815262Z","title":"Colbat snatch,","venue":null,"work_id":"790464cc-045a-40d7-9e5c-b3653eea91c1","year":2016},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":74,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.895278Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:c819b21917ca9a12250694398b9d0ccdd80d59935c0ffb61062120ad49ff1a2a","observation_id":"c8b69a9a-06f0-4ab4-818e-953b481e1133","resolution":{"observed_at":"2026-08-07T23:35:23.818659Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.805246Z","title":"Multiple cobalt personality disorder","venue":null,"work_id":"2b915559-a727-4451-98a7-d4417df67660","year":2018},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":75,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.898577Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:6fcacd3fd2d4162e6ec5bd99d5bbebe9d6446565f1e0b49930045b18f00f3265","observation_id":"2489ca3f-ae9b-453c-a730-ff681d7a3a09","resolution":{"observed_at":"2026-08-07T23:35:23.808745Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.795146Z","title":null,"venue":null,"work_id":"52955320-f33c-4091-a935-9cbec263280d","year":2014},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":76,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.901815Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:2ed645b90743f9d218005e821c3a8a33adc7b97d21dbd5165abbdbe4ec98c3b2","observation_id":"26d72547-846e-4908-af9b-09d501c1d25a","resolution":{"observed_at":"2026-08-07T23:35:23.798555Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.785293Z","title":"Lab, The Duqu 2.0 technical details","venue":null,"work_id":"4ea33e51-ab5c-4fd1-abd9-2a4a2e81c16a","year":2015},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":77,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.905135Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:eafead83703591454cbb66c270d2a8d00b5ec05c9584f3c70bd986c375304440","observation_id":"5d7598b6-5354-4284-aa3e-1e0391a0efc2","resolution":{"observed_at":"2026-08-07T23:35:23.788767Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.775339Z","title":"On the hunt for fin7: Pursuing an enigmatic and evasive global crimi- nal operation","venue":null,"work_id":"8042cd23-d7da-44dc-84e8-f7ef78c90de8","year":2018},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":78,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.908308Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:53310b510e334a98885b8b80bc6e71b656e19815354c77a423f20bfd31d324af","observation_id":"7435171a-e55f-4d9a-b87b-54c77b0cf040","resolution":{"observed_at":"2026-08-07T23:35:23.778828Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.765097Z","title":"Apt40: Examining a china-nexus espionage actor","venue":null,"work_id":"ee7084c7-7dd2-49db-8ca2-5663bcc22b02","year":2019},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":79,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.911607Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:8a62c54452dbcc718407b76a3165cbc6e92fb407d11dd8faac2ee35fddd54c01","observation_id":"57b1a906-7079-4bbb-baa5-2667201d5cf3","resolution":{"observed_at":"2026-08-07T23:35:23.768727Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.754509Z","title":"Suspected chinese cyber espionage group (temp.periscope) targeting u.s. engineering and maritime industries","venue":null,"work_id":"eed33502-dd95-46e6-9239-a0cef7645b61","year":2018},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":80,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.914940Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:e3e207c08921d1ea0e6b393836bf144b4a34aca506ad83f63d3c6778f26d0b4d","observation_id":"f5f5250c-67e9-49f2-a93d-184cb4bab181","resolution":{"observed_at":"2026-08-07T23:35:23.758543Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.744119Z","title":"The msnmm campaigns the earliest naikon APT campaigns,","venue":null,"work_id":"d767ae06-a878-496a-8e7f-5a3d272db507","year":2015},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":81,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.918583Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:5ef6b421baef4749bc4484d90fb10cae7bf985b14c1b293f8b5e3ea04dd072ff","observation_id":"edea8532-ed1a-468b-a6ac-cd8beaef5996","resolution":{"observed_at":"2026-08-07T23:35:23.747946Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.733154Z","title":"Camerashy closing the aperture on china’s unit 78020,","venue":null,"work_id":"f1bfed3f-669c-4856-af10-1105e4717458","year":2015},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":82,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.921971Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:0cc4f8977ef16c5ba4797cecd3b2b6efc2c9aa837fbd32af9f908331a65d6fa2","observation_id":"0204b5d1-df61-4757-89b0-f545db9a2f10","resolution":{"observed_at":"2026-08-07T23:35:23.736936Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.722552Z","title":"Untangling the patchwork cyberespionage group,","venue":null,"work_id":"cf1e9b41-7c26-49bf-961a-51b68b2da380","year":2018},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":83,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.925373Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:a16ee245cbf63958838f381cad407e2f742ff10d1e6c6bbbdadd45f9f32c244a","observation_id":"39772987-f61e-46dc-8670-e4f75e83ab75","resolution":{"observed_at":"2026-08-07T23:35:23.726252Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.712064Z","title":"Patchwork APT group targets us think tanks","venue":null,"work_id":"92cb602b-68c1-4d06-a6a6-bc943ef5f3e4","year":2018},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":84,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.928745Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:ebe46e0a45ea065ec677827ba5be746c3c7205e2394b85e03af38188e20c3d8a","observation_id":"34281caf-502a-4748-948e-060c7698e179","resolution":{"observed_at":"2026-08-07T23:35:23.715621Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.702021Z","title":null,"venue":null,"work_id":"d6716a2a-9c55-4c11-b9b0-4a47d9dbf9cc","year":2016},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":85,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.931939Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:5c1ab6764aa23ef85c33385d2a733179aca4e9b46f32268e43c3c2b1f265e299","observation_id":"107b30b3-282e-4ea5-a2b7-a504a43abaec","resolution":{"observed_at":"2026-08-07T23:35:23.705455Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.692129Z","title":null,"venue":null,"work_id":"ee498a8e-e24d-4445-a219-cf07142d598f","year":2014},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":86,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.935267Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:6cdc7f8343d3776a5d97e7e11a70923423e1aef6ec86e4d7d9ca414411caa5eb","observation_id":"9fc688c2-64c1-4cd2-9f81-8d02d02b44de","resolution":{"observed_at":"2026-08-07T23:35:23.695515Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.682140Z","title":"Research and A","venue":null,"work_id":"7231d794-3aed-4651-9be4-622223abcc2f","year":2016},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":87,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.938573Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:dd2804a01c4c7ea70beff0ecae520778d2d402f99cd1151a2357126288b04487","observation_id":"f74b8225-dd93-4d68-b3e7-deaa48ffe059","resolution":{"observed_at":"2026-08-07T23:35:23.685534Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.671873Z","title":"Backdoor.remsec indicators of compromise,","venue":null,"work_id":"eaf85928-a602-4714-964c-8ed12b16ebbb","year":2016},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":88,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.942010Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:90ef18c327ae4e7ef4908052add7c625291935c9e37a54b002788479e35fe3be","observation_id":"ab481c5b-e7b6-434a-adfd-ff3b7d4b4a94","resolution":{"observed_at":"2026-08-07T23:35:23.675798Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.661737Z","title":null,"venue":null,"work_id":"34be2e39-1eaf-47b6-a009-a91e327f42c9","year":2014},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":89,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.945800Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:10b19d7cd3cc46be3de58246c7ff61c531d4dcc8a73c369c4c20cc3290d98810","observation_id":"2700a7fd-5650-404a-a591-dddfc8a18edc","resolution":{"observed_at":"2026-08-07T23:35:23.665293Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.651872Z","title":"Research and A","venue":null,"work_id":"729d6570-bef2-4473-847b-5268d8691c96","year":2014},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":90,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.949152Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:13a4b9ec25a1844354383946afeee756b9f317b556f199f45f9ab246c25b1ef3","observation_id":"727c4c86-f6fd-4c8b-8623-b9f66d615f91","resolution":{"observed_at":"2026-08-07T23:35:23.655165Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.641764Z","title":"Research and A","venue":null,"work_id":"4b2ca8bd-86c8-4a5f-87e6-d8b7f8e17d4d","year":2013},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":91,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.952630Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:beb5191f9a4aa1f086240ad46a6cd128899b3e30e53f909d0bad95fa2688e8c4","observation_id":"59e892a6-cb81-4d24-802e-6542aaad63dc","resolution":{"observed_at":"2026-08-07T23:35:23.645208Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.631604Z","title":"Research and A","venue":null,"work_id":"0009b5ea-767e-4c3e-9f95-17e42b372f2f","year":2013},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":92,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.956120Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:f95642d5dc409d8c89c0e2ac63fbcd8f0520c19ac25fb15c0ec61327bdf70b39","observation_id":"c198da4d-9740-4cb4-b4ff-3aa91ff8b993","resolution":{"observed_at":"2026-08-07T23:35:23.635008Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.621942Z","title":"Puttering into the future","venue":null,"work_id":"9a28a0b1-57ff-4987-a049-0af5eda8cb9c","year":2016},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":93,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.959287Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:b2002522049911b5d61de9748553aa339a41217e896b916f45dea34a7db1e989","observation_id":"cdc5bc10-b304-4028-9bfc-2fba28dc5687","resolution":{"observed_at":"2026-08-07T23:35:23.625336Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.612014Z","title":"Decoding network data from a gh0st rat variant","venue":null,"work_id":"f52d025a-aa8a-4040-84ab-d6123ba90c77","year":2018},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":94,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.962440Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:9defe3744bb975077318287f0d4fcf17a5d05ab7697c968621b629981dfdb58c","observation_id":"168c5707-e4a1-4271-b00a-13b51e48ac63","resolution":{"observed_at":"2026-08-07T23:35:23.615417Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.592610Z","title":"New wekby attacks use dns requests as command and control mechanism","venue":null,"work_id":"9fd3dbfa-c826-4cd9-ba08-64c6c8f78208","year":2014},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":95,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.968827Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:aafec5abb42ffc7a766e9bb1c2a13d1eb340c5b0d9c076ca15dd5a1bf704b51e","observation_id":"f8a14192-bc5e-4ae9-8746-77381b450aec","resolution":{"observed_at":"2026-08-07T23:35:23.596492Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.582466Z","title":"Emissary panda – a potential new malicious tool","venue":null,"work_id":"832f2112-394b-4b98-afc2-bb4ac464f0ce","year":2018},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":96,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.972334Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:96e191bbc077a5ed70d59c26e87ee9296dc587ef82f5f8c7275f08a49f2c73a7","observation_id":"62d26c5a-632e-4f66-b3d4-b0027902170a","resolution":{"observed_at":"2026-08-07T23:35:23.586135Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.571393Z","title":"Apt29 domain fronting with tor","venue":null,"work_id":"c81d7ee8-397c-4330-98d1-6653eed7c51b","year":2017},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":97,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.978895Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:0b8d8e5d6d2284ed5b7c1ebaca6789136df658c005213524f66bcf163e6ef258","observation_id":"628574dd-e1e9-4da6-8ed7-23e747313a5a","resolution":{"observed_at":"2026-08-07T23:35:23.575360Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.559758Z","title":"Oceanlotus blossoms: Mass digital surveillance and attacks targeting asean, asian nations, the me- dia, human rights groups, and civil society","venue":null,"work_id":"a8ff4196-1166-4cff-903b-78a2988c80bf","year":2017},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":98,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.982363Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:39a794f632c2df2b6bc4ec233916aa60e435004f99d1bbaaf0d7af7a3250dde1","observation_id":"84fa5327-eb9c-439d-a787-7fa95ea8672a","resolution":{"observed_at":"2026-08-07T23:35:23.563790Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:23.548250Z","title":"Oceanlotus old techniques, new backdoor,","venue":null,"work_id":"a8fab6c6-79e9-41e1-89e3-b095d8fde915","year":2018},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":99,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.985699Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:50f04840c6bde76e6611ce8adb737df20c7d781b779374e953d9fc5a51000579","observation_id":"6e7442a8-efa1-495b-975c-ee41c91c7012","resolution":{"observed_at":"2026-08-07T23:35:23.552338Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-13T06:32:02.005865+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-07T23:35:22.975872Z","title":null,"venue":null,"work_id":null,"year":2019},"citing_paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures","version":1},"reference_index":100,"source":"pdf_text","source_observed_at":"2026-08-07T23:35:22.975872Z"},"links":{"citing_paper":"/paper/2502.08830"},"observation_digest":"sha256:efbfef146ee0a82a577a1284541364e644fb8159620b10d73ebd411164967752","observation_id":"cb642fd1-b3dc-49e6-a666-061a9c921127","resolution":{"observed_at":"2026-08-07T23:35:22.975872Z","resolver_source":null,"status":"parse_uncertain"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"paper":{"arxiv_id":"2502.08830","last_updated":"2025-02-12T22:38:50Z","latest_version":1,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-07T23:30:31.038259Z","submitted_at":"2025-02-12T22:38:50Z","title":"Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures"},"reference_resolution":{"displayed":100,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":1,"unresolved":52,"verified_exact":1,"verified_fuzzy":46},"total_outbound_references":129},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-13T06:32:02.005865+00:00","source":"crossref"},{"observed_at":"2026-08-13T06:31:53.387327+00:00","source":"retraction_watch"}],"thesis":"As of 13 August 2026, this Paper Citation Record lists 100 of 129 outbound references and 1 inbound Pith citation observation for arXiv:2502.08830."}