From IOCs to Regex: Automating CTI Operationalization for SOC with LLMs
Fuente:
arXiv
Salvato in:
| Autori principali: | Tseng, Pei-Yu, Zhang, Lan, Yeh, ZihDwo, Sun, Xiaoyan, Dai, Xushu, Liu, Peng |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2026
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
Documenti analoghi
Using LLMs to Automate Threat Intelligence Analysis Workflows in Security Operation Centers
di: Tseng, PeiYu, et al.
Pubblicazione: (2024)
di: Tseng, PeiYu, et al.
Pubblicazione: (2024)
LLMs in the SOC: An Empirical Study of Human-AI Collaboration in Security Operations Centres
di: Singh, Ronal, et al.
Pubblicazione: (2025)
di: Singh, Ronal, et al.
Pubblicazione: (2025)
LLMCloudHunter: Harnessing LLMs for Automated Extraction of Detection Rules from Cloud-Based CTI
di: Schwartz, Yuval, et al.
Pubblicazione: (2024)
di: Schwartz, Yuval, et al.
Pubblicazione: (2024)
SeCTIS: A Framework to Secure CTI Sharing
di: Arikkat, Dincy R., et al.
Pubblicazione: (2024)
di: Arikkat, Dincy R., et al.
Pubblicazione: (2024)
KnowHow: Automatically Applying High-Level CTI Knowledge for Interpretable and Accurate Provenance Analysis
di: Meng, Yuhan, et al.
Pubblicazione: (2025)
di: Meng, Yuhan, et al.
Pubblicazione: (2025)
Attackers reveal their arsenal: An investigation of adversarial techniques in CTI reports
di: Rahman, Md Rayhanur, et al.
Pubblicazione: (2024)
di: Rahman, Md Rayhanur, et al.
Pubblicazione: (2024)
reconCTI: A Proactive Approach to Cyber-Threat Intelligence
di: Rahman, Mohammed Mahir, et al.
Pubblicazione: (2026)
di: Rahman, Mohammed Mahir, et al.
Pubblicazione: (2026)
CTI-HAL: A Human-Annotated Dataset for Cyber Threat Intelligence Analysis
di: Della Penna, Sofia, et al.
Pubblicazione: (2025)
di: Della Penna, Sofia, et al.
Pubblicazione: (2025)
Kitten or Panda? Measuring the Specificity of Threat Group Behaviors in Public CTI Knowledge Bases
di: Saha, Aakanksha, et al.
Pubblicazione: (2025)
di: Saha, Aakanksha, et al.
Pubblicazione: (2025)
CTI-REALM: Benchmark to Evaluate Agent Performance on Security Detection Rule Generation Capabilities
di: Chakraborty, Arjun, et al.
Pubblicazione: (2026)
di: Chakraborty, Arjun, et al.
Pubblicazione: (2026)
SynthCTI: LLM-Driven Synthetic CTI Generation to enhance MITRE Technique Mapping
di: Ruiz-Ródenas, Álvaro, et al.
Pubblicazione: (2025)
di: Ruiz-Ródenas, Álvaro, et al.
Pubblicazione: (2025)
The Procedural Semantics Gap in Structured CTI: A Measurement-Driven STIX Analysis for APT Emulation
di: Ferraz, Ágney Lopes Roth, et al.
Pubblicazione: (2025)
di: Ferraz, Ágney Lopes Roth, et al.
Pubblicazione: (2025)
The CTI Echo Chamber: Fragmentation, Overlap, and Vendor Specificity in Twenty Years of Cyber Threat Reporting
di: Suarez-Roman, Manuel, et al.
Pubblicazione: (2026)
di: Suarez-Roman, Manuel, et al.
Pubblicazione: (2026)
Elevating Cyber Threat Intelligence against Disinformation Campaigns with LLM-based Concept Extraction and the FakeCTI Dataset
di: Cotroneo, Domenico, et al.
Pubblicazione: (2025)
di: Cotroneo, Domenico, et al.
Pubblicazione: (2025)
CTI Dataset Construction from Telegram
di: Arikkat, Dincy R., et al.
Pubblicazione: (2025)
di: Arikkat, Dincy R., et al.
Pubblicazione: (2025)
Hagenberg Risk Management Process (Part 3): Operationalization, Probabilities, and Causal Analysis
di: Hermann, Eckehard, et al.
Pubblicazione: (2026)
di: Hermann, Eckehard, et al.
Pubblicazione: (2026)
OpenSOC-AI: Democratizing Security Operations with Parameter Efficient LLM Log Analysis
di: Garware, Chaitanya Vilas, et al.
Pubblicazione: (2026)
di: Garware, Chaitanya Vilas, et al.
Pubblicazione: (2026)
RAGRank: Using PageRank to Counter Poisoning in CTI LLM Pipelines
di: Jia, Austin, et al.
Pubblicazione: (2025)
di: Jia, Austin, et al.
Pubblicazione: (2025)
Hide Your Malicious Goal Into Benign Narratives: Jailbreak Large Language Models through Carrier Articles
di: Wang, Zhilong, et al.
Pubblicazione: (2024)
di: Wang, Zhilong, et al.
Pubblicazione: (2024)
Can SOC Operators Explain their Decisions while Triaging Alarms? A Real-World Study
di: Moosmann, Jessica, et al.
Pubblicazione: (2026)
di: Moosmann, Jessica, et al.
Pubblicazione: (2026)
SQLaser: Detecting DBMS Logic Bugs with Clause-Guided Fuzzing
di: Wei, Jin, et al.
Pubblicazione: (2024)
di: Wei, Jin, et al.
Pubblicazione: (2024)
Operationalizing Research Software for Supply Chain Security
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
di: Kalu, Kelechi G., et al.
Pubblicazione: (2026)
AgentSOC: A Multi-Layer Agentic AI Framework for Security Operations Automation
di: Roy, Joyjit, et al.
Pubblicazione: (2026)
di: Roy, Joyjit, et al.
Pubblicazione: (2026)
Operationalizing Cybersecurity Knowledge: Design, Implementation & Evaluation of a Knowledge Management System for CACAO Playbooks
di: Tsirakis, Orestis, et al.
Pubblicazione: (2025)
di: Tsirakis, Orestis, et al.
Pubblicazione: (2025)
HuntFUZZ: Enhancing Error Handling Testing through Clustering Based Fuzzing
di: Wei, Jin, et al.
Pubblicazione: (2024)
di: Wei, Jin, et al.
Pubblicazione: (2024)
How Does Naming Affect LLMs on Code Analysis Tasks?
di: Wang, Zhilong, et al.
Pubblicazione: (2023)
di: Wang, Zhilong, et al.
Pubblicazione: (2023)
ASTRA: An Automated Framework for Strategy Discovery, Retrieval, and Evolution for Jailbreaking LLMs
di: Liu, Xu, et al.
Pubblicazione: (2025)
di: Liu, Xu, et al.
Pubblicazione: (2025)
PROVEX: Enhancing SOC Analyst Trust with Explainable Provenance-Based IDS
di: Dhanuka, Devang, et al.
Pubblicazione: (2025)
di: Dhanuka, Devang, et al.
Pubblicazione: (2025)
Towards Small Language Models for Security Query Generation in SOC Workflows
di: Muzammil, Saleha, et al.
Pubblicazione: (2025)
di: Muzammil, Saleha, et al.
Pubblicazione: (2025)
From Text to Actionable Intelligence: Automating STIX Entity and Relationship Extraction
di: Lekssays, Ahmed, et al.
Pubblicazione: (2025)
di: Lekssays, Ahmed, et al.
Pubblicazione: (2025)
Operationalizing a Threat Model for Red-Teaming Large Language Models (LLMs)
di: Verma, Apurv, et al.
Pubblicazione: (2024)
di: Verma, Apurv, et al.
Pubblicazione: (2024)
SAGA: Synthetic Audit Log Generation for APT Campaigns
di: Huang, Yi-Ting, et al.
Pubblicazione: (2024)
di: Huang, Yi-Ting, et al.
Pubblicazione: (2024)
Operationalizing CaMeL: Strengthening LLM Defenses for Enterprise Deployment
di: Tallam, Krti, et al.
Pubblicazione: (2025)
di: Tallam, Krti, et al.
Pubblicazione: (2025)
Policy-Guided Threat Hunting: An LLM enabled Framework with Splunk SOC Triage
di: Sahay, Rishikesh, et al.
Pubblicazione: (2026)
di: Sahay, Rishikesh, et al.
Pubblicazione: (2026)
EMPalm: Exfiltrating Palm Biometric Data via Electromagnetic Side-Channel
di: Xu, Haowen, et al.
Pubblicazione: (2025)
di: Xu, Haowen, et al.
Pubblicazione: (2025)
KryptoPilot: An Open-World Knowledge-Augmented LLM Agent for Automated Cryptographic Exploitation
di: Liu, Xiaonan, et al.
Pubblicazione: (2026)
di: Liu, Xiaonan, et al.
Pubblicazione: (2026)
PrediQL: Automated Testing of GraphQL APIs with LLMs
di: Liu, Shaolun, et al.
Pubblicazione: (2025)
di: Liu, Shaolun, et al.
Pubblicazione: (2025)
Shell or Nothing: Real-World Benchmarks and Memory-Activated Agents for Automated Penetration Testing
di: Mai, Wuyuao, et al.
Pubblicazione: (2025)
di: Mai, Wuyuao, et al.
Pubblicazione: (2025)
You Can't Eat Your Cake and Have It Too: The Performance Degradation of LLMs with Jailbreak Defense
di: Mai, Wuyuao, et al.
Pubblicazione: (2025)
di: Mai, Wuyuao, et al.
Pubblicazione: (2025)
FDLLM: A Dedicated Detector for Black-Box LLMs Fingerprinting
di: Fu, Zhiyuan, et al.
Pubblicazione: (2025)
di: Fu, Zhiyuan, et al.
Pubblicazione: (2025)
Documenti analoghi
-
Using LLMs to Automate Threat Intelligence Analysis Workflows in Security Operation Centers
di: Tseng, PeiYu, et al.
Pubblicazione: (2024) -
LLMs in the SOC: An Empirical Study of Human-AI Collaboration in Security Operations Centres
di: Singh, Ronal, et al.
Pubblicazione: (2025) -
LLMCloudHunter: Harnessing LLMs for Automated Extraction of Detection Rules from Cloud-Based CTI
di: Schwartz, Yuval, et al.
Pubblicazione: (2024) -
SeCTIS: A Framework to Secure CTI Sharing
di: Arikkat, Dincy R., et al.
Pubblicazione: (2024) -
KnowHow: Automatically Applying High-Level CTI Knowledge for Interpretable and Accurate Provenance Analysis
di: Meng, Yuhan, et al.
Pubblicazione: (2025)