Anyone can run malware against a security product. Anyone can execute a suspicious file and see if it gets blocked. But this type of basic testing doesn’t determine whether a product can detect and stop the types of attacks that real adversaries are using. That’s where our Threat Series comes into play.
Each series is a structured set of advanced attack techniques and tactics based on real-world threat groups that share a common theme or operational relevance. It’s how we transform our threat intelligence into repeatable, relevant cyber security tests.
Some threat series focus on state-sponsored activity. Others may combine groups because they target similar sectors, use comparable infrastructure, or focus on particular attack techniques like social engineering. In some circumstances, our testing team may also mix Threat Series if it’s an appropriate approach to testing a product.
For example, ransomware testing may use relevant techniques from multiple series, pulling out individual APTs or attack behaviours known to include ransomware or ransomware-like activity. This gives us flexibility because the Threat Series provides structure, but the test remains driven by its goal – in this example, extorting victims.
Dynamic change as threats evolve
The Threat Series are not static. They are not “set and forget” threat menus that remain unchanged year after year. We continually update them as new intelligence emerges, as attackers change their methods, and as defensive technology evolves.
While some techniques used by a group five years ago may still be relevant, they may not be enough by themselves to truly test a cyber security product. Groups adapt their delivery methods, tooling, evasion techniques and post-compromise actions, and our tests need to reflect that evolution to remain relevant.
SE Labs’ Advanced Security Tests are built around full attack chains. We don’t simply drop malware onto an endpoint and wait to see what happens. Our testers behave like real attackers. So real, in fact, the UK police once contacted us because someone in China reported us as a very dangerous, malicious group!
We use relevant routes into a target environment and then attempt to continue the attack through its later stages. That can include phishing, malicious attachments, exploit activity, external remote services, supply chain-style compromise, command execution, reconnaissance, privilege escalation, lateral movement, data collection, data exfiltration and destructive actions.
This allows us to create valid, controlled and repeatable tests that reflects how attackers actually behave today and in the near future. Our Threat Series are central to that process.
Threat Series 11 – State Sponsored Hacking
The latest Fortinet FortiEndpoint Advanced Security Test Report uses Threat Series 11. This series is based on attacks inspired by the behaviour of four Advanced Threat Groups (APTs):
Gamaredon Group
Ember Bear
Evasive Panda
DPRK
These groups were selected because they are associated with state-sponsored hacking, but they don’t all operate in the same way. This allows us to test a product using a diverse set of realistic attack behaviours.
Gamaredon Group is associated with spear phishing attachments and template injection-style delivery. Ember Bear and Evasive Panda bring supply chain and infrastructure-focused behaviours into scope. DPRK activity introduces external remote services and ransomware-relevant techniques, including actions associated with financial motivation and destructive impact.
Across Threat Series 11, the attack chains include a broad range of tactics and techniques mapped to stages such as delivery, execution, action, privilege escalation, post-escalation activity, lateral movement and lateral action.
This structure allows us to measure more than a simple “blocked” or “missed” result. It shows where a product acted.
Did it detect the delivery?
Did it allow execution?
Did the attacker achieve reconnaissance?
Could the attacker escalate privileges?
Was lateral movement possible?
Could data be collected, exfiltrated or destroyed?
These details are important because not all security outcomes are equal.
A product that blocks an attack before execution has performed differently from one that allows the attack to run, notices later, and then attempts to clean up. Both may eventually prevent a breach, but the level of risk, disruption and operational confidence is not the same.
Why Relevance is Key
Security buyers are often presented with bold claims about a product’s ability to stop advanced attacks. Products claim to detect ransomware. They claim to identify nation-state techniques. They claim to provide visibility across the attack chain.
Threat Series testing gives those claims a harder surface to hit.
Instead of relying on marketing language or narrow demonstrations, buyers can look at SE Labs reports to see how a product responded to attacks based on real adversary behaviour. They can see whether attacks were detected, where they were stopped, and whether the product made mistakes with legitimate software.
This matters because real-world testing is not about finding the most exotic way to break a product. It is about testing against attacks that are relevant, credible and operationally meaningful.
SE Labs’ threat intelligence goes much deeper than any single Threat Series. Our research tracks attacker behaviour, emerging techniques and future-facing developments across the threat landscape. But effective public testing has to be selective. It must focus on the techniques that matter to defenders now, while remaining informed by what is likely to matter next.
That is the role of the Threat Series. They provide a structured way to surface the parts of our threat intelligence that are most relevant to a specific test, sector or attacker profile.
Threat Series 11 reflects SE Labs’ broader principle: testing needs to evolve because attackers do. APTs reuse what works, retire what doesn’t, borrow from other groups and adapt to defensive controls.
A credible testing programme has to do the same: observing, updating and emulating attacker behaviour as it develops, while keeping the test grounded in the threats that security teams are most likely to face.
Download the latest Fortinet FortiEndpoint Advanced Security Test Report to see how Threat Series 11 was used in practice.