Fighting Cyberattacks Through Adversary Behavior Analysis: Insights From Our Research Team
Download resourcesAbout this session
Andréanne Bergeron, director of cybersecurity research at GoSecure, opens a panel of four short talks from her research team, built on three years of data from an RDP honeypot instrumented with the open-source tool PyRDP: 190 million events, over 100 hours of attacker session video, and 454 recorded compromises. Jeremy O'Boyle presents a sophistication score for attackers who used the Windows command line instead of the GUI, finding only 8% did so and most scored poorly, mostly limited to changing a password. Bergeron then presents, in her absence, Sophie Marchand's research on attacker browser preferences, showing Chrome dominates and Tor is essentially unused inside compromised sessions, likely because the breach itself already hides them. Constance Prévost closes with an analysis of proxy use among 1529 unique attacking IPs over three months, finding 42% relied on a proxy, that proxy users chose longer passwords and skipped known credential-leak lists, and that Russia- and China-attributed traffic often routed through in-country proxies. A long audience Q&A covers methodology limits and the ethics of retrieving files attackers copy onto the honeypot.
Understanding your cyber adversaries is important in strengthening your organization's defenses against evolving threats in the digital landscape. In traditional warfare as well as in cybersecurity, knowledge of enemy tactics, strategies, and motivations is crucial for victory.
We built a honeynet that is composed of several RDP Windows servers exposed on the cloud. Over a span of three years, this infrastructure collected a staggering dataset, encompassing over 190 million events, 100 hours of video footage, and 470 files procured from threat actors. This wealth of data facilitated a comprehensive analysis of attacker behavior.
During this presentation panel, the GoSecure research team will present three distinct aspects of attacker behavior, shedding light on their modus operandi across various dimensions. The short presentations will encompass (1) their preferences and tendencies concerning Command-Line Interface versus Graphical User Interface usage, (2) their browser preferences, and (3) the intricate geopolitical nuances associated with their IP addresses of origin.
By examining these multifaceted aspects of attacker behavior, we aim to provide comprehensive insights into the tactics, strategies, and motivations driving malicious actors in the cyber landscape.
Key takeaways
- Treat command-line sophistication as rare: in this honeypot only 8% of sessions used it, so monitor GUI-driven activity as closely as terminal activity.
- Expect Chrome, not Tor, from attackers already inside a compromised host; the breach itself already gives them anonymity, so Tor absence is a weak signal.
- Flag proxy-originated logins for extra scrutiny: proxy users in this dataset chose longer passwords and avoided known leaked-credential lists, suggesting more deliberate attackers.
- Do not infer country of origin from IP alone; a large share of Russia- and China-attributed traffic routed through proxies hosted in the same country.
- Set ethical guardrails before running a research honeypot: decide in advance what you will and will not do with files or tools attackers leave behind.
Speakers

Andréanne Bergeron, Ph.D., is the director of research at GoSecure, specializing in online attackers' behaviors. Her expertise delves into the intersection of criminology and cybersecurity. In addition, Andréanne holds an esteemed position as an… Read moreRead less
Andréanne Bergeron, Ph.D., is the director of research at GoSecure, specializing in online attackers' behaviors. Her expertise delves into the intersection of criminology and cybersecurity. In addition, Andréanne holds an esteemed position as an affiliated professor in the Department of Criminology of Montreal University, bridging academia and industry. Involved in the cybersecurity community, she is a board member of the Canadian Cybersecurity Network and the co-VP of engagement and outreach for Northsec.
