SAGA: Synthetic Audit Log Generation for APT Campaigns
inforesearchPeer-Reviewed
researchsecurity
Source: IEEE Xplore (Security & AI Journals)December 5, 2025
Summary
SAGA is a tool that creates synthetic audit logs (detailed records of system activities) containing hidden Advanced Persistent Threats (APTs, which are long-term targeted cyberattacks) to help train and test detection systems. The tool mixes normal system activity logs with malicious activity based on known attack patterns from the MITRE ATT&CK framework (a database of real-world attack techniques), and researchers showed that machine learning models trained on these synthetic logs can identify new, previously unseen attack techniques.
Classification
Attack SophisticationModerate
Impact (CIA+S)
integrity
AI Component TargetedTraining Data
Monthly digest — independent AI security research
Original source: http://ieeexplore.ieee.org/document/11281529
First tracked: May 9, 2026 at 02:01 AM
Classified by LLM (prompt v3) · confidence: 75%