arXiv:2510. 11974v2 Announce Type: replace-cross Abstract: Cyber Threat Intelligence (CTI) is foundational to modern cybersecurity, enabling organizations to proactively defend against evolving threats.
By Yutong Cheng, Yang Liu, Changze Li, Dawn Song, Peng Gao
arXiv:2607. 19742v1 Announce Type: cross Abstract: Cyber Threat Intelligence (CTI) reports richly describe real-world attack processes, but their unstructured narratives cannot be directly used for automated attack-path reasoning.
By Wenbo Hou, Ning Hu, Xueping Wang, Jiahao Gu, Wenjian Luo
arXiv:2607. 24563v1 Announce Type: new Abstract: Security Operations Centers increasingly rely on automated mapping of Cyber Threat Intelligence reports to MITRE ATT&CK, yet extractor outputs remain fallible and are often stored without the evidence, provenance, and validation history needed to decide whether an individual mapping should be trusted.
By Federico Valletta, Giacomo Longo, Enrico Russo, Alessio Merlo
arXiv:2606. 31557v1 Announce Type: cross Abstract: In the evolving threat landscape, adversaries exploit software vulnerabilities to launch sophisticated attacks, challenging traditional defenses.
By Basant Agarwal, Dincy R. Arikkat, Swati Yadav, Serena Nicolazzo, Antonino Nocera, Vinod P
arXiv:2606. 18166v1 Announce Type: cross Abstract: Classifying Cyber Threat Intelligence (CTI) using MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) is essential for proactive defense, but historically required extensive human effort.
By Ahmed Ryan, Saad Sakib Noor, Md Erfan, Shaswata Mitra, Sudip Mittal, Md Rayhanur Rahman
arXiv:2606. 18190v1 Announce Type: cross Abstract: Multi-stage cyberattacks span system, network, and browser logs.
By Abir Ashab Niloy, Ahmed Ryan, Imamul Hossain Rafi, Md Erfan, Md Rayhanur Rahman
arXiv:2608. 13050v1 Announce Type: cross Abstract: When a security researcher publishes a report on a cyberattack, detection engineers are supposed to turn it into working detection rules.
By Atul Kabra, Prakhar Paliwal, Manjesh K. Hanawal
CTIFoundry is an agent‑native corpus scaffold designed to improve cyber threat intelligence (CTI) investigations by LLM agents. It transforms traditional CTI data—such as CVE, CWE, CAPEC, and ATT&CK—into a deterministic ontology graph with typed, traversable edges, a span‑grounded report layer that resolves entity aliases and provenance, and hybrid dense‑plus‑lexical retrieval surfaces. When integrated with a standard open‑source agent harness, CTIFoundry boosts overall F1 scores by 0.19 to 0.28 on the CTIConnect benchmark, achieving higher accuracy with fewer tool calls compared to agents using flat, retrieval‑augmented corpora.
By Yutong Cheng, Changze Li, Qian Cui, Wei Ding, Lingzhi Wang, Yan Chen, Peng Gao
arXiv:2608. 16775v1 Announce Type: cross Abstract: Large Language Models (LLMs) are increasingly being deployed in cybersecurity operations to assist cybersecurity analysts with rapid decision-making against emerging threats.
By Reza Fayyazi, Michael Zuzak, Shanchieh Jay Yang
The paper introduces DisCTI, a system that automatically maps cyber threat intelligence (CTI) events to relevant industry sectors using a multilabel classification approach. By creating a dataset of 872 sector‑labelled CTI events and applying a BERT transformer model, the authors achieve a macro‑averaged F1‑score of 0.89, correctly assigning 94.5% of sector labels. This demonstrates that embedding expert knowledge into machine learning can enable timely, sector‑aware CTI dissemination, improving defensive response.
By Fajar Wijitrisnanto (National Cyber and Crypto Agency, Jakarta, Indonesia), Alsharif Abuadbba (CSIRO, Sydney, Australia), Yansong Gao (CSIRO, Sydney, Australia, The University of Western Australia, Perth, Australia), Nan Wu (CSIRO, Sydney, Australia)
arXiv:2607. 05001v1 Announce Type: cross Abstract: Cyber Threat Intelligence (CTI) reports are predominantly unstructured, heterogeneous, and noisy, which limits their direct usability for automated analysis and reasoning.
By Mouhamed Amine Bouchiha, Gregory Blanc
The paper audits the reproducibility of knowledge‑graph extraction from threat reports by re‑implementing matching rules for only five of twelve systems and re‑scoring ten system outputs under eight protocols. The audit shows that different matching protocols can reverse most pairwise system rankings and that a fixed prediction set can vary from 0.16 to 0.70 F1. The authors also build CTIForge to isolate validation effects, finding that validation changes precision across backbones and increases entity‑type disputes, and they release the full pipeline, protocol suite, and audit records.
By Safayat Bin Hakim, Houbing Herbert Song