Delft Threat Intelligence Lab Delft University of Technology

Understanding cyber threats by studying the real world

Our research investigates how cyber attacks evolve in the wild. We focus on empirical research in threat intelligence, malware behavior, and digital forensics, using data from real incidents to drive actionable insights.

Research papers

2026

Decoys Cannot Go Everywhere: Mapping the Deception Surface in MITRE ATT&CK
Veronica Valeros, Carlos Catania, Viliam Lisý, Harm Griffioen
arXiv, 29 Jun 2026, arxiv:2606.27966
From Mirai to Gorilla: Deep Dive into a Long-Lasting DDoS-for-Hire Botnet
Maarten Weyns, Dario Ferrero, S.O. de Beek, Daniel Wagner, Georgios Smaragdakis, Harm Griffioen
35th USENIX Security Symposium (USENIX Security '26), 01 Jan 2026, [no id info]
Understanding Different Perspectives: Analyzing UDP Scanning Through Reactive Telescopes
Understanding Different Perspectives: Analyzing UDP Scanning Through Reactive Telescopes
Dario Ferrero, A. Sordello, Harm Griffioen, Idilio Drago, Georgios Smaragdakis, Marco Mellia
Proceedings of the 2026 ACM Internet Measurement Conference (IMC '26), 01 Jan 2026, [no id info]

2025

Decoy Databases: Analyzing Attacks on Public Facing Databases
Yuqian Song, Georgios Smaragdakis, Harm Griffioen
Proceedings of the 2025 ACM Internet Measurement Conference, 28 Oct 2025, doi:10.1145/3730567.3764481
Have you SYN What I See Analyzing TCP SYN Payloads in the Wild
Have you SYN What I See? Analyzing TCP SYN Payloads in the Wild
Dario Ferrero, Enrico Bassetti, Harm Griffioen, Georgios Smaragdakis
Proceedings of the 2025 ACM Internet Measurement Conference, 28 Oct 2025, doi:10.1145/3730567.3764498
Revealing Informed Scanners by Colocating Reactive and Passive Telescopes
Revealing Informed Scanners by Colocating Reactive and Passive Telescopes
Dario Ferrero, George Smaragdakis, Harm Griffioen
2025 28th International Symposium on Research in Attacks, Intrusions and Defenses (RAID), 19 Oct 2025, doi:10.1109/RAID67961.2025.00056
All that Glitters is not Gold: Uncovering Exposed Industrial Control Systems and Honeypots in the Wild
All that Glitters is not Gold: Uncovering Exposed Industrial Control Systems and Honeypots in the Wild
Martin Mladenov, László Erdődi, Georgios Smaragdakis
2025 IEEE 10th European Symposium on Security and Privacy (EuroS&P), 30 Jun 2025, doi:10.1109/EuroSP63326.2025.00017
Trust but Verify: An Assessment of Vulnerability Tagging Services
S.C. Huang, Harm Griffioen, M. van der Horst, Georgios Smaragdakis, Michel van Eeten
34th USENIX Security Symposium (USENIX Security 25), 01 Jan 2025, [no id info]
MoZombie: A Case Study of the Self-Sustaining Mozi Botnet Architecture
M. Mohammed, Georgios Smaragdakis, Harm Griffioen
28th International Symposium on Research in Attacks, Intrusions and Defenses (RAID), 01 Jan 2025, [no id info]

2024

Have you SYN me? Characterizing Ten Years of Internet Scanning
Harm Griffioen, Georgios Koursiounis, Georgios Smaragdakis, Christian Doerr
Proceedings of the 2024 ACM on Internet Measurement Conference, 04 Nov 2024, doi:10.1145/3646547.3688409

2023

How to Operate a Meta-Telescope in your Spare Time
Daniel Wagner, Sahil Ashish Ranadive, Harm Griffioen, Michalis Kallitsis, Alberto Dainotti, Georgios Smaragdakis, Anja Feldmann
Proceedings of the 2023 ACM on Internet Measurement Conference, 24 Oct 2023, doi:10.1145/3618257.3624831
Could you clean up the Internet with a Pit of Tar Investigating tarpit feasibility on Internet worms
Could you clean up the Internet with a Pit of Tar? Investigating tarpit feasibility on Internet worms
Harm Griffioen, Christian Doerr
2023 IEEE Symposium on Security and Privacy (SP), 01 May 2023, doi:10.1109/SP46215.2023.10179467

2022

Cyber Threat Intelligence: Analysis of adversaries and their methods
H.J. Griffioen
Delft University of Technology, 01 Jan 2022, doi:10.4233/uuid:37f7367f-bc5e-4cde-a7fd-47d12621f853

2021

Scan, Test, Execute: Adversarial Tactics in Amplification DDoS Attacks
Harm Griffioen, Kris Oosthoek, Paul van der Knaap, Christian Doerr
Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, 12 Nov 2021, doi:10.1145/3460120.3484747
SIP Bruteforcing in the Wild - An Assessment of Adversaries, Techniques and Tools
Harm Griffioen, Huancheng Hu, Christian Doerr
2021 IFIP Networking Conference (IFIP Networking), 21 Jun 2021, doi:10.23919/IFIPNetworking52078.2021.9472857
Analysis and Takeover of the Bitcoin-Coordinated Pony Malware
Tsuyoshi Taniguchi, Harm Griffioen, Christian Doerr
Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security, 24 May 2021, doi:10.1145/3433210.3437520

2020

Examining Mirai's Battle over the Internet of Things
Harm Griffioen, Christian Doerr
Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, 30 Oct 2020, doi:10.1145/3372297.3417277
Quantifying autonomous system IP churn using attack traffic of botnets
Harm Griffioen, Christian Doerr
Proceedings of the 15th International Conference on Availability, Reliability and Security, 25 Aug 2020, doi:10.1145/3407023.3407051
A Different Cup of TI? The Added Value of Commercial Threat Intelligence
Xander Bouwman, Harm Griffioen, J. Egbers, Christian Doerr, Bram Klievink, Michel van Eeten
29th USENIX Security Symposium (USENIX Security '20), 12 Aug 2020, [no id info]
Quantifying TCP SYN DDoS Resilience: A Longitudinal Study of Internet Services
Harm Griffioen, Christian Doerr
2020 IFIP Networking Conference (Networking), 01 Jun 2020, [no id info]
Discovering Collaboration: Unveiling Slow, Distributed Scanners based on Common Header Field Patterns
Harm Griffioen, Christian Doerr
NOMS 2020 - 2020 IEEE/IFIP Network Operations and Management Symposium, 01 Apr 2020, doi:10.1109/NOMS47738.2020.9110444
Quality Evaluation of Cyber Threat Intelligence Feeds
Harm Griffioen, Tim Booij, Christian Doerr
Lecture Notes in Computer Science, 01 Jan 2020, doi:10.1007/978-3-030-57878-7_14

2019

Fingerprinting Tooling used for SSH Compromisation Attempts
Vincent Ghiette, Harm Griffioen, Christian Doerr
22nd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2019), 23 Sep 2019, [no id info]
Taxonomy and Adversarial Strategies of Random Subdomain Attacks
Harm Griffioen, Christian Doerr
2019 10th IFIP International Conference on New Technologies, Mobility and Security (NTMS), 01 Jun 2019, doi:10.1109/NTMS.2019.8763820

2018

Scanners: Discovery of Distributed Slow Scanners in Telescope Data
Harm J. Griffioen
Master's thesis, Delft University of Technology, 01 Jan 2018, [no id info]