logo

From Narrative to Knowledge Graph | LLM-Driven Information Extraction in Cyber Threat Intelligence

Date Published: 2026-03-09

Date Updated: 2026-07-27

Author: Aleksandar Milenkoski & Razvan Gabriel Cirstea

...
...

### Executive Summary This blog post presents a practical study on applying large language models to automatically extract and contextualize cyber threat intelligence from narrative CTI reports, detailing a three-phase pipeline (report sanitization, LLM-based extractors for infrastructure, executables, and playbooks, and knowledge-graph assembly), custom data models and evidence-grading prompts, and an empirical evaluation across multiple LLMs that measures selective IOC extraction, contextual attribute assignment, abstention behavior, processing time, ensembling potential, and playbook reconstruction; it finds substantial time-efficiency gains but highlights accuracy, ambiguity, and operational trade-offs requiring careful design and ongoing evaluation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.