arXiv:2510. 11974v2 Announce Type: replace-cross Abstract: Cyber Threat Intelligence (CTI) is foundational to modern cybersecurity, enabling organizations to proactively defend against evolving threats.
By Yutong Cheng, Yang Liu, Changze Li, Dawn Song, Peng Gao
arXiv:2608.28394v1 Announce Type: cross
Abstract: Cyber threat intelligence (CTI) is foundational to modern cyber defense, yet much of it resides in unstructured reports whose volume and heterogeneit...
By Changze Li, Yutong Cheng, Tsania Camila Finnisa, Qian Cui, Wei Ding, Peng Gao
CTIFoundry is an agent‑native corpus scaffold designed to improve cyber threat intelligence (CTI) investigations by LLM agents. It transforms traditional CTI data—such as CVE, CWE, CAPEC, and ATT&CK—into a deterministic ontology graph with typed, traversable edges, a span‑grounded report layer that resolves entity aliases and provenance, and hybrid dense‑plus‑lexical retrieval surfaces. When integrated with a standard open‑source agent harness, CTIFoundry boosts overall F1 scores by 0.19 to 0.28 on the CTIConnect benchmark, achieving higher accuracy with fewer tool calls compared to agents using flat, retrieval‑augmented corpora.
By Yutong Cheng, Changze Li, Qian Cui, Wei Ding, Lingzhi Wang, Yan Chen, Peng Gao
MITRE‑SAGE is a multi‑agent retrieval‑augmented generation framework that combines semantic and structural cybersecurity knowledge to enhance large language model question‑answering. It decomposes tasks into query interpretation, evidence retrieval, and answer synthesis, supporting vulnerability assessment, threat profiling, and relationship extraction. The authors also introduce MITRE‑QA, a benchmark of 3,000 question‑answer pairs, and show that MITRE‑SAGE outperforms standalone LLMs and conventional RAG methods, with a lightweight configuration achieving top performance on most tasks.
By Ali Habibzadeh, Farid Feyzi, Reza Ebrahimi Atani
arXiv:2607. 19742v1 Announce Type: cross Abstract: Cyber Threat Intelligence (CTI) reports richly describe real-world attack processes, but their unstructured narratives cannot be directly used for automated attack-path reasoning.
By Wenbo Hou, Ning Hu, Xueping Wang, Jiahao Gu, Wenjian Luo
MITRE‑SAGE is a multi‑agent retrieval‑augmented generation framework that combines semantic and structural cybersecurity knowledge to enhance large language model question‑answering. It decomposes tasks into query interpretation, evidence retrieval, and answer synthesis, supporting vulnerability assessment, threat profiling, and relationship extraction. Experiments show that MITRE‑SAGE outperforms standalone LLMs and conventional RAG methods, with a lightweight Qwen2.5‑based configuration excelling on most benchmark tasks.
By Ali Habibzadeh, Farid Feyzi, Reza Ebrahimi Atani