כתבה
arXiv cs.AI ·
Evidence-Grounded Retrieval for Investigation Hunt Lead Generation from CTI Reports
תקציר מקורי באנגליתarXiv:2609.08790v1 Announce Type: cross Abstract: Threat hunting increasingly depends on converting unstructured knowledge (e.g., Cyber Threat Intelligence reports) into actionable hunt leads: concise, investigable hypotheses grounded in observable artifacts and adversary techniques. Producing such leads manually is a tedious and hard-to-scale task. Existing automated approaches stop at the entity layer, ignore the defender's operational environment, and analyze each report in isolation. To address these gaps, we introduce AHLERT, a system that automatically extracts relevant, environment-aware, and hunt leads from threat reports through (i) a hybrid retriever that combines dense vector search with multi-hop traversal over a knowledge graph seeded with MITRE ATT&CK; (ii) an ontology-ground
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית