AuditBench - Lab Lateral Movement: leaderboard

Metric: F1 (0-100) for lateral-movement identification on the Lab data (Linux and Windows audit logs recorded by the authors) (5 attack scenarios): the model reads the scenario's edge-representation (provenance-graph edges, 400-line chunks) audit logs in chunks with prompt v2 and flags the log lines of the lateral movement; recall counts the attack scenarios found and precision counts false-positive log lines; temperature 0 where available (GPT-5 models at the default medium reasoning effort); higher is better. Source: arxiv.org. Saturation forecast: Around 2031. 5 models tracked.

Top models

#ModelScore
1Llama 4 Maverick62
2GPT-5 Mini57
3Gemini 2.5 Flash48
4Gemini 2.5 Pro45
5GPT-533

Interactive version: theaggregate.ai/benchmark?slug=auditbench-lab-lateral-movement · How It Works · Data refreshed daily, snapshot 2026-09-29.