A SoK for SoCs: Reading the TI Leaves on AI for Cyber Threat Intelligence Generation and Sharing
cs.CR
Submitted: 2026-09-01
Updated: 2026-09-01
Code: https://github.com/kevoreilly/CAPEv2
Project page: https://weihang-wang.github.io/papers/mci_ndss18.pdf
Terminology
Sources
- From Alerts to Intelligence: A Novel LLM-Aided Framework for Host-based Intrusion Detection
- Time for aCTIon: Automated Analysis of Cyber Threat Intelligence in the Wild
- ThreatPilot: Attack-Driven Threat Intelligence Extraction
- Automated Retrieval of ATT&CK Tactics and Techniques for Cyber Threat Reports
- Cyber-Attack Technique Classification Using Two-Stage Trained Large Language Models
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs