Rule-ATT&CK Mapper (RAM): Mapping SIEM Rules to TTPs Using LLMs
Fuente:
arXiv
Saved in:
| Main Authors: | Wudali, Prasanna N., Kravchik, Moshe, Malul, Ehud, Gandhi, Parth A., Elovici, Yuval, Shabtai, Asaf |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
RuleGenie: SIEM Detection Rule Set Optimization
by: Shukla, Akansha, et al.
Published: (2025)
by: Shukla, Akansha, et al.
Published: (2025)
SHIELD: APT Detection and Intelligent Explanation Using LLM
by: Gandhi, Parth Atulbhai, et al.
Published: (2025)
by: Gandhi, Parth Atulbhai, et al.
Published: (2025)
RAPID: Robust APT Detection and Investigation Using Context-Aware Deep Learning
by: Amaru, Yonatan, et al.
Published: (2024)
by: Amaru, Yonatan, et al.
Published: (2024)
GenKubeSec: LLM-Based Kubernetes Misconfiguration Detection, Localization, Reasoning, and Remediation
by: Malul, Ehud, et al.
Published: (2024)
by: Malul, Ehud, et al.
Published: (2024)
KubeGuard: LLM-Assisted Kubernetes Hardening via Configuration Files and Runtime Logs Analysis
by: Cohen, Omri Sgan, et al.
Published: (2025)
by: Cohen, Omri Sgan, et al.
Published: (2025)
LLMCloudHunter: Harnessing LLMs for Automated Extraction of Detection Rules from Cloud-Based CTI
by: Schwartz, Yuval, et al.
Published: (2024)
by: Schwartz, Yuval, et al.
Published: (2024)
From Tool Orchestration to Code Execution: A Study of MCP Design Choices
by: Felendler, Yuval, et al.
Published: (2026)
by: Felendler, Yuval, et al.
Published: (2026)
SoK: Cybersecurity Assessment of Humanoid Ecosystem
by: Surve, Priyanka Prakash, et al.
Published: (2025)
by: Surve, Priyanka Prakash, et al.
Published: (2025)
Tag&Tab: Pretraining Data Detection in Large Language Models Using Keyword-Based Membership Inference Attack
by: Antebi, Sagiv, et al.
Published: (2025)
by: Antebi, Sagiv, et al.
Published: (2025)
ATAG: AI-Agent Application Threat Assessment with Attack Graphs
by: Gandhi, Parth Atulbhai, et al.
Published: (2025)
by: Gandhi, Parth Atulbhai, et al.
Published: (2025)
DOMBA: Double Model Balancing for Access-Controlled Language Models via Minimum-Bounded Aggregation
by: Segal, Tom, et al.
Published: (2024)
by: Segal, Tom, et al.
Published: (2024)
Tab-MIA: A Benchmark Dataset for Membership Inference Attacks on Tabular Data in LLMs
by: German, Eyal, et al.
Published: (2025)
by: German, Eyal, et al.
Published: (2025)
MIA-EPT: Membership Inference Attack via Error Prediction for Tabular Data
by: German, Eyal, et al.
Published: (2025)
by: German, Eyal, et al.
Published: (2025)
Real-World Adversarial Attacks on RF-Based Drone Detectors
by: Gazit, Omer, et al.
Published: (2025)
by: Gazit, Omer, et al.
Published: (2025)
Labeling NIDS Rules with MITRE ATT&CK Techniques: Machine Learning vs. Large Language Models
by: Daniel, Nir, et al.
Published: (2024)
by: Daniel, Nir, et al.
Published: (2024)
Rogue Cell: Adversarial Attack and Defense in Untrusted O-RAN Setup Exploiting the Traffic Steering xApp
by: Aizikovich, Eran, et al.
Published: (2025)
by: Aizikovich, Eran, et al.
Published: (2025)
LexiMark: Robust Watermarking via Lexical Substitutions to Enhance Membership Verification of an LLM's Textual Training Data
by: German, Eyal, et al.
Published: (2025)
by: German, Eyal, et al.
Published: (2025)
Detection of Compromised Functions in a Serverless Cloud Environment
by: Lavi, Danielle, et al.
Published: (2024)
by: Lavi, Danielle, et al.
Published: (2024)
QuantAttack: Exploiting Dynamic Quantization to Attack Vision Transformers
by: Baras, Amit, et al.
Published: (2023)
by: Baras, Amit, et al.
Published: (2023)
UEFI Memory Forensics: A Framework for UEFI Threat Analysis
by: Segal, Kalanit Suzan, et al.
Published: (2025)
by: Segal, Kalanit Suzan, et al.
Published: (2025)
Mind the Web: The Security of Web Use Agents
by: Shapira, Avishag, et al.
Published: (2025)
by: Shapira, Avishag, et al.
Published: (2025)
Peacock: UEFI Firmware Runtime Observability Layer for Detection and Response
by: Gorelik, Hadar Cochavi, et al.
Published: (2026)
by: Gorelik, Hadar Cochavi, et al.
Published: (2026)
GPT in Sheep's Clothing: The Risk of Customized GPTs
by: Antebi, Sagiv, et al.
Published: (2024)
by: Antebi, Sagiv, et al.
Published: (2024)
DeSparsify: Adversarial Attack Against Token Sparsification Mechanisms in Vision Transformers
by: Yehezkel, Oryan, et al.
Published: (2024)
by: Yehezkel, Oryan, et al.
Published: (2024)
KillChainGraph: ML Framework for Predicting and Mapping ATT&CK Techniques
by: Singh, Chitraksh, et al.
Published: (2025)
by: Singh, Chitraksh, et al.
Published: (2025)
Context-Aware Web Attack Detection in Open-Source SIEM Systems via MITRE ATT&CK-Enriched Behavioral Profiling
by: Alboushy, Badr, et al.
Published: (2026)
by: Alboushy, Badr, et al.
Published: (2026)
AgentGuardian: Learning Access Control Policies to Govern AI Agent Behavior
by: Abaev, Nadya, et al.
Published: (2026)
by: Abaev, Nadya, et al.
Published: (2026)
Towards an End-to-End (E2E) Adversarial Learning and Application in the Physical World
by: Biton, Dudi, et al.
Published: (2025)
by: Biton, Dudi, et al.
Published: (2025)
SecMate: Multi-Agent Adaptive Cybersecurity Troubleshooting with Tri-Context Personalization
by: Meidan, Yair, et al.
Published: (2026)
by: Meidan, Yair, et al.
Published: (2026)
An Alignment Between the CRA's Essential Requirements and the ATT&CK's Mitigations
by: Ruohonen, Jukka, et al.
Published: (2025)
by: Ruohonen, Jukka, et al.
Published: (2025)
Your ATs to Ts: MITRE ATT&CK Attack Technique to P-SSCRM Task Mapping
by: Hamer, Sivana, et al.
Published: (2025)
by: Hamer, Sivana, et al.
Published: (2025)
A Proactive Decoy Selection Scheme for Cyber Deception using MITRE ATT&CK
by: Zambianco, Marco, et al.
Published: (2024)
by: Zambianco, Marco, et al.
Published: (2024)
Observability and Incident Response in Managed Serverless Environments Using Ontology-Based Log Monitoring
by: Ben-Shimol, Lavi, et al.
Published: (2024)
by: Ben-Shimol, Lavi, et al.
Published: (2024)
Security Logs to ATT&CK Insights: Leveraging LLMs for High-Level Threat Understanding and Cognitive Trait Inference
by: Hans, Soham, et al.
Published: (2025)
by: Hans, Soham, et al.
Published: (2025)
Decoding the MITRE Engenuity ATT&CK Enterprise Evaluation: An Analysis of EDR Performance in Real-World Environments
by: Shen, Xiangmin, et al.
Published: (2024)
by: Shen, Xiangmin, et al.
Published: (2024)
Enhancing cybersecurity defenses: a multicriteria decision-making approach to MITRE ATT&CK mitigation strategy
by: Mohamed, Ihab, et al.
Published: (2024)
by: Mohamed, Ihab, et al.
Published: (2024)
Constructing Multi-label Hierarchical Classification Models for MITRE ATT&CK Text Tagging
by: Crossman, Andrew, et al.
Published: (2026)
by: Crossman, Andrew, et al.
Published: (2026)
ISADM: An Integrated STRIDE, ATT&CK, and D3FEND Model for Threat Modeling Against Real-world Adversaries
by: Hasan, Khondokar Fida, et al.
Published: (2025)
by: Hasan, Khondokar Fida, et al.
Published: (2025)
SCyTAG: Scalable Cyber-Twin for Threat-Assessment Based on Attack Graphs
by: Tayouri, David, et al.
Published: (2025)
by: Tayouri, David, et al.
Published: (2025)
An Evaluation Framework for Network IDS/IPS Datasets: Leveraging MITRE ATT&CK and Industry Relevance Metrics
by: Tori, Adrita Rahman, et al.
Published: (2025)
by: Tori, Adrita Rahman, et al.
Published: (2025)
Similar Items
-
RuleGenie: SIEM Detection Rule Set Optimization
by: Shukla, Akansha, et al.
Published: (2025) -
SHIELD: APT Detection and Intelligent Explanation Using LLM
by: Gandhi, Parth Atulbhai, et al.
Published: (2025) -
RAPID: Robust APT Detection and Investigation Using Context-Aware Deep Learning
by: Amaru, Yonatan, et al.
Published: (2024) -
GenKubeSec: LLM-Based Kubernetes Misconfiguration Detection, Localization, Reasoning, and Remediation
by: Malul, Ehud, et al.
Published: (2024) -
KubeGuard: LLM-Assisted Kubernetes Hardening via Configuration Files and Runtime Logs Analysis
by: Cohen, Omri Sgan, et al.
Published: (2025)