arXiv AI By Wenbo Hou, Ning Hu, Xueping Wang, Jiahao Gu, Wenjian Luo

An Automated Framework for Extracting Reachable Attack Chains from Cyber Threat Intelligence Reports

Read the original on arXiv AI →

arXiv:2607. 19742v1 Announce Type: cross Abstract: Cyber Threat Intelligence (CTI) reports richly describe real-world attack processes, but their unstructured narratives cannot be directly used for automated attack-path reasoning.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv AI.

arXiv AI
Aug 20

From Threat Intelligence to Detection: Knowledge-driven Enrichment and Template-based Rule Grounding for Automated Sigma Rule Generation

The paper introduces AUTOSIGMA, an automated system that converts unstructured cyber threat intelligence reports into Sigma detection rules. It enriches input data with a structured knowledge base, matches it against existing Sigma rule repositories, and uses a large language model as a judge to validate the generated rules. Experiments on real-world APT reports and security blogs show that AUTOSIGMA outperforms other methods in rule validity, relevancy, MITRE ATT&CK coverage, and robustness to input quality.

By Sepehr Ghaffarzadegan, Boubakr Nour, Makan Pourzandi, Mourad Debbabi, Chadi Assi