The Procedural Semantics Gap in Structured CTI: A Measurement-Driven STIX Analysis for APT Emulation
Fuente:
arXiv
Saved in:
| Main Authors: | Ferraz, Ágney Lopes Roth, Barbieri, Sidnei, de Souza, Murray Evangelista, Júnior, Lourenço Alves Pereira |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
PocketAgents: A Manifest-Driven Library of Autonomous Defense Agents
by: Barbieri, Sidnei, et al.
Published: (2026)
by: Barbieri, Sidnei, et al.
Published: (2026)
SOCpilot: Verifying Policy Compliance for LLM-Assisted Incident Response
by: Barbieri, Sidnei, et al.
Published: (2026)
by: Barbieri, Sidnei, et al.
Published: (2026)
When Connectivity Is Not Enough: Cross-Layer Attacks on UAV C2 over 5G
by: Sonaglio, Wagner Comin, et al.
Published: (2026)
by: Sonaglio, Wagner Comin, et al.
Published: (2026)
A Systematic Security Testing Approach for InterUSS-based environments
by: de Miranda, Henrique Curi, et al.
Published: (2026)
by: de Miranda, Henrique Curi, et al.
Published: (2026)
Grid-STIX: A STIX 2.1-Compliant Cyber-Physical Security Ontology for Power Grid
by: Blakely, Benjamin, et al.
Published: (2025)
by: Blakely, Benjamin, et al.
Published: (2025)
Enabling End-to-End APT Emulation in Industrial Environments: Design and Implementation of the SIMPLE-ICS Testbed
by: Pramadi, Yogha Restu, et al.
Published: (2026)
by: Pramadi, Yogha Restu, et al.
Published: (2026)
Slot: Provenance-Driven APT Detection through Graph Reinforcement Learning
by: Qiao, Wei, et al.
Published: (2024)
by: Qiao, Wei, et al.
Published: (2024)
Kitten or Panda? Measuring the Specificity of Threat Group Behaviors in Public CTI Knowledge Bases
by: Saha, Aakanksha, et al.
Published: (2025)
by: Saha, Aakanksha, et al.
Published: (2025)
From Text to Actionable Intelligence: Automating STIX Entity and Relationship Extraction
by: Lekssays, Ahmed, et al.
Published: (2025)
by: Lekssays, Ahmed, et al.
Published: (2025)
SynthCTI: LLM-Driven Synthetic CTI Generation to enhance MITRE Technique Mapping
by: Ruiz-Ródenas, Álvaro, et al.
Published: (2025)
by: Ruiz-Ródenas, Álvaro, et al.
Published: (2025)
CyberNER: A Harmonized STIX Corpus for Cybersecurity Named Entity Recognition
by: Ech-Chammakhy, Yasir, et al.
Published: (2025)
by: Ech-Chammakhy, Yasir, et al.
Published: (2025)
APT-MCL: An Adaptive APT Detection System Based on Multi-View Collaborative Provenance Graph Learning
by: Lv, Mingqi, et al.
Published: (2026)
by: Lv, Mingqi, et al.
Published: (2026)
Knowledge Transfer from LLMs to Provenance Analysis: A Semantic-Augmented Method for APT Detection
by: Zuo, Fei, et al.
Published: (2025)
by: Zuo, Fei, et al.
Published: (2025)
LLM-Driven APT Detection for 6G Wireless Networks: A Systematic Review and Taxonomy
by: Golec, Muhammed, et al.
Published: (2025)
by: Golec, Muhammed, et al.
Published: (2025)
SeCTIS: A Framework to Secure CTI Sharing
by: Arikkat, Dincy R., et al.
Published: (2024)
by: Arikkat, Dincy R., et al.
Published: (2024)
From IOCs to Regex: Automating CTI Operationalization for SOC with LLMs
by: Tseng, Pei-Yu, et al.
Published: (2026)
by: Tseng, Pei-Yu, et al.
Published: (2026)
Attackers reveal their arsenal: An investigation of adversarial techniques in CTI reports
by: Rahman, Md Rayhanur, et al.
Published: (2024)
by: Rahman, Md Rayhanur, et al.
Published: (2024)
reconCTI: A Proactive Approach to Cyber-Threat Intelligence
by: Rahman, Mohammed Mahir, et al.
Published: (2026)
by: Rahman, Mohammed Mahir, et al.
Published: (2026)
SAGA: Synthetic Audit Log Generation for APT Campaigns
by: Huang, Yi-Ting, et al.
Published: (2024)
by: Huang, Yi-Ting, et al.
Published: (2024)
SHIELD: APT Detection and Intelligent Explanation Using LLM
by: Gandhi, Parth Atulbhai, et al.
Published: (2025)
by: Gandhi, Parth Atulbhai, et al.
Published: (2025)
CTI-HAL: A Human-Annotated Dataset for Cyber Threat Intelligence Analysis
by: Della Penna, Sofia, et al.
Published: (2025)
by: Della Penna, Sofia, et al.
Published: (2025)
OCR-APT: Reconstructing APT Stories from Audit Logs using Subgraph Anomaly Detection and LLMs
by: Aly, Ahmed, et al.
Published: (2025)
by: Aly, Ahmed, et al.
Published: (2025)
CTI-REALM: Benchmark to Evaluate Agent Performance on Security Detection Rule Generation Capabilities
by: Chakraborty, Arjun, et al.
Published: (2026)
by: Chakraborty, Arjun, et al.
Published: (2026)
Structuring Security: A Survey of Cybersecurity Ontologies, Semantic Log Processing, and LLMs Application
by: Lourenço, Bruno, et al.
Published: (2025)
by: Lourenço, Bruno, et al.
Published: (2025)
CICAPT-IIOT: A provenance-based APT attack dataset for IIoT environment
by: Ghiasvand, Erfan, et al.
Published: (2024)
by: Ghiasvand, Erfan, et al.
Published: (2024)
The CTI Echo Chamber: Fragmentation, Overlap, and Vendor Specificity in Twenty Years of Cyber Threat Reporting
by: Suarez-Roman, Manuel, et al.
Published: (2026)
by: Suarez-Roman, Manuel, et al.
Published: (2026)
KnowHow: Automatically Applying High-Level CTI Knowledge for Interpretable and Accurate Provenance Analysis
by: Meng, Yuhan, et al.
Published: (2025)
by: Meng, Yuhan, et al.
Published: (2025)
ProHunter: A Comprehensive APT Hunting System Based on Whole-System Provenance
by: Qiu, Xuebo, et al.
Published: (2026)
by: Qiu, Xuebo, et al.
Published: (2026)
TPPR: APT Tactic / Technique Pattern Guided Attack Path Reasoning for Attack Investigation
by: Sheng, Qi
Published: (2025)
by: Sheng, Qi
Published: (2025)
APT-ClaritySet: A Large-Scale, High-Fidelity Labeled Dataset for APT Malware with Alias Normalization and Graph-Based Deduplication
by: Yin, Zhenhao, et al.
Published: (2025)
by: Yin, Zhenhao, et al.
Published: (2025)
TFLAG:Towards Practical APT Detection via Deviation-Aware Learning on Temporal Provenance Graph
by: Jiang, Wenhan, et al.
Published: (2025)
by: Jiang, Wenhan, et al.
Published: (2025)
APT-CGLP: Advanced Persistent Threat Hunting via Contrastive Graph-Language Pre-Training
by: Qiu, Xuebo, et al.
Published: (2025)
by: Qiu, Xuebo, et al.
Published: (2025)
Elevating Cyber Threat Intelligence against Disinformation Campaigns with LLM-based Concept Extraction and the FakeCTI Dataset
by: Cotroneo, Domenico, et al.
Published: (2025)
by: Cotroneo, Domenico, et al.
Published: (2025)
CTI Dataset Construction from Telegram
by: Arikkat, Dincy R., et al.
Published: (2025)
by: Arikkat, Dincy R., et al.
Published: (2025)
A Cascade Approach for APT Campaign Attribution in System Event Logs: Technique Hunting and Subgraph Matching
by: Huang, Yi-Ting, et al.
Published: (2024)
by: Huang, Yi-Ting, et al.
Published: (2024)
Red Team Redemption: A Structured Comparison of Open-Source Tools for Adversary Emulation
by: Landauer, Max, et al.
Published: (2024)
by: Landauer, Max, et al.
Published: (2024)
Emulating OP_RAND in Bitcoin
by: Kurbatov, Oleksandr
Published: (2025)
by: Kurbatov, Oleksandr
Published: (2025)
APT-LLM: Embedding-Based Anomaly Detection of Cyber Advanced Persistent Threats Using Large Language Models
by: Benabderrahmane, Sidahmed, et al.
Published: (2025)
by: Benabderrahmane, Sidahmed, et al.
Published: (2025)
P3GNN: A Privacy-Preserving Provenance Graph-Based Model for APT Detection in Software Defined Networking
by: Nazari, Hedyeh, et al.
Published: (2024)
by: Nazari, Hedyeh, et al.
Published: (2024)
APT-Agent: Automated Penetration Testing using Large Language Models
by: Li, William Guanting, et al.
Published: (2026)
by: Li, William Guanting, et al.
Published: (2026)
Similar Items
-
PocketAgents: A Manifest-Driven Library of Autonomous Defense Agents
by: Barbieri, Sidnei, et al.
Published: (2026) -
SOCpilot: Verifying Policy Compliance for LLM-Assisted Incident Response
by: Barbieri, Sidnei, et al.
Published: (2026) -
When Connectivity Is Not Enough: Cross-Layer Attacks on UAV C2 over 5G
by: Sonaglio, Wagner Comin, et al.
Published: (2026) -
A Systematic Security Testing Approach for InterUSS-based environments
by: de Miranda, Henrique Curi, et al.
Published: (2026) -
Grid-STIX: A STIX 2.1-Compliant Cyber-Physical Security Ontology for Power Grid
by: Blakely, Benjamin, et al.
Published: (2025)