Abstract
Organizations struggle to convert raw Cyber Threat Intelligence (CTI) reports into actionable detection rules that can be deployed in Security Information and Event Management (SIEM) systems. The manual process of extracting Tactics, Techniques, and Procedures (TTPs) from unstructured CTI and transforming them into Sigma detection rules remains labor intensive and does not scale to meet the volume of emerging threats. We address this challenge by designing and developing an automated framework that leverages Large Language Models (LLMs) with a novel Reflective Beam Search (RBS) mechanism. Our approach iteratively refines candidate outputs through self correction, maintaining fidelity to the source intelligence while generating operationally viable detection rules. The system extracts TTPs from diverse CTI sources including government advisories, security vendor reports, and proprietary threat intelligence feeds. Evaluation across real world threat reports demonstrates that our method achieves an 88% F1 score for TTP extraction and produces Sigma rules with a 69% true positive score (TPS) when tested against production security logs. These results are obtained without requiring fine-tuned models, enabling organizations to rapidly operationalize threat intelligence using commercially available LLMs. The approach transforms security operations by automating detection engineering workflows that previously required extensive manual analyst effort.
| Original language | English |
|---|---|
| Pages (from-to) | 2130-2135 |
| Number of pages | 6 |
| Journal | Proceedings of the IEEE International Conference on Big Data, BigData |
| Issue number | 2025 |
| DOIs | |
| State | Published - 2025 |
| Event | 2025 IEEE International Conference on Big Data, BigData 2025 - Macau, China Duration: 8 Dec 2025 → 11 Dec 2025 |
Keywords
- Agentic AI
- Cyber Threat Intelligence
- Large Language Model
- Retrieval Augmented Generation
Fingerprint
Dive into the research topics of 'Reflective Beam Search for Automated TTP Extraction and Sigma Rule Generation from Cyber Threat Intelligence'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver