arXiv AI By Yiran Gao, Juntao Chen, Tao Li

Hierarchical Agentic Incident Response with Digital-Twin-Validated Attack Inference

Read the original on arXiv AI →

arXiv:2608. 15016v1 Announce Type: cross Abstract: Network incident response remains slow and labor-intensive as the defender must infer multi-stage attacks from partial observations and translate recovery decisions into reliable system commands.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv AI.

arXiv AI
Jul 31

SecRespond: Benchmarking AI Agents for Real-World Post-Compromise Incident Response

arXiv:2607. 26791v1 Announce Type: cross Abstract: Large Language Model (LLM) agents are increasingly adopted in real-world security operations with access to host artifacts and command-line interfaces (CLIs), making it critical to thoroughly assess their security capabilities.

By Lehan Wang, Boli Chen, Ruixue Ding, Pengjun Xie, Jinwei Huang, Zhendong Liu, Shuo Wang, Tao Lei, Xin Ouyang, Xiaomeng Li
arXiv AI
Sep 25

Where Cyber Agents Struggle: Bottleneck Analysis of Multi-Stage LLM Agents

The paper presents a diagnostic study of a multi‑stage LLM‑based cyber agent system, examining its orchestrator, executor, and validator components in enterprise‑style lateral‑movement scenarios. Six advanced LLMs were tested across expert‑defined, self‑scaffolded, and fully autonomous modes, with metrics that include validator consistency, evidence grounding, token usage, retries, and runtime. Findings show that while validators are generally relevant, they are often nonspecific and overly optimistic, and the main bottlenecks lie in credential acquisition and lateral‑movement tasks, especially under full autonomy.

By Saeedeh Lohrasbi, Mohammad Mamun, Ahmed Yehia, Scott Buffett, Sherif Saad
arXiv AI
Aug 5

DiagChain: A Diagnostic Benchmark for Evaluating LLM Agents on Evidence-Grounded Attack Chain Reconstruction

arXiv:2608. 03591v1 Announce Type: cross Abstract: Large Language Model (LLM) agents offer a promising approach to attack chain reconstruction by retrieving and interpreting heterogeneous telemetry to infer ordered attacker actions.

By Xuyang Liu, Yibin Han, Zhenwei Zhang, Kai Chang, Zhiwei Xu, Tian Qiu, Weixian Deng, Jiabao Gao, Xiaolin Peng, Hai Wan, Xibin Zhao