STAIR: Effective Incident Response Using an End-to-End Agentic Planning Framework
arXiv:2608. 09524v1 Announce Type: cross Abstract: Incident response planning is critical for restoring compromised software systems after cyberattacks.
arXiv:2608. 15016v1 Announce Type: cross Abstract: Network incident response remains slow and labor-intensive as the defender must infer multi-stage attacks from partial observations and translate recovery decisions into reliable system commands.
arXiv:2608. 09524v1 Announce Type: cross Abstract: Incident response planning is critical for restoring compromised software systems after cyberattacks.
arXiv:2607. 26791v1 Announce Type: cross Abstract: Large Language Model (LLM) agents are increasingly adopted in real-world security operations with access to host artifacts and command-line interfaces (CLIs), making it critical to thoroughly assess their security capabilities.
arXiv:2607. 16199v1 Announce Type: new Abstract: Multi-agent LLM systems increasingly rely on a Planner to decompose goals into sub-task sequences that downstream Executor and Critic agents execute and audit.
The paper presents a diagnostic study of a multi‑stage LLM‑based cyber agent system, examining its orchestrator, executor, and validator components in enterprise‑style lateral‑movement scenarios. Six advanced LLMs were tested across expert‑defined, self‑scaffolded, and fully autonomous modes, with metrics that include validator consistency, evidence grounding, token usage, retries, and runtime. Findings show that while validators are generally relevant, they are often nonspecific and overly optimistic, and the main bottlenecks lie in credential acquisition and lateral‑movement tasks, especially under full autonomy.
arXiv:2608. 03591v1 Announce Type: cross Abstract: Large Language Model (LLM) agents offer a promising approach to attack chain reconstruction by retrieving and interpreting heterogeneous telemetry to infer ordered attacker actions.
arXiv:2608.21423v1 Announce Type: cross Abstract: Agentic security uses large-language-model (LLM) agents to plan, dispatch, and interpret security tools. As these systems move from demonstrations to...
arXiv:2606. 30479v1 Announce Type: cross Abstract: Mitigating an observed adversary in an enterprise network typically takes weeks of expert work: an analyst derives a mitigation tailored to that adversary, validates it without breaking production, and verifies it disrupts the specific attack.
arXiv:2509. 20008v2 Announce Type: replace Abstract: Penetration testing, the simulation of cyberattacks to identify security vulnerabilities, presents a sequential decision-making problem well-suited for reinforcement learning (RL) automation.
arXiv:2609.23894v1 Announce Type: cross Abstract: Agentic AI extends LLM security beyond generated content to persistent state, autonomous actions, tool use, and interactions with humans and other ag...
arXiv:2609. 07344v1 Announce Type: cross Abstract: Large language model (LLM) based agents are increasingly applied to cybersecurity tasks such as vulnerability discovery and automated penetration testing.
arXiv:2604. 09523v2 Announce Type: replace Abstract: Training reinforcement-learning agents for cyber defense requires an environment that reflects the operational setting: noisy, partial observations, several defenders coordinating across a network, and an adaptive adversary realized through self-play.
arXiv:2609.00595v1 Announce Type: cross Abstract: Safe agents can fail together. Multi-agent LLM systems (MAS) move information, state, decisions, and authority across principal boundaries, creating...