From Narrative to Knowledge Graph | LLM-Driven Information Extraction in Cyber Threat Intelligence
ID: f74840ab-96a0-5a9a-9e8e-dd0e755ba2e6
STIX ID: report--f74840ab-96a0-5a9a-9e8e-dd0e755ba2e6
Date Published: 2026-03-09
Date Updated: 2026-07-27
Author: Aleksandar Milenkoski & Razvan Gabriel Cirstea
### Executive Summary This blog post presents a practical study on applying large language models to automatically extract and contextualize cyber threat intelligence from narrative CTI reports, detailing a three-phase pipeline (report sanitization, LLM-based extractors for infrastructure, executables, and playbooks, and knowledge-graph assembly), custom data models and evidence-grading prompts, and an empirical evaluation across multiple LLMs that measures selective IOC extraction, contextual attribute assignment, abstention behavior, processing time, ensembling potential, and playbook reconstruction; it finds substantial time-efficiency gains but highlights accuracy, ambiguity, and operational trade-offs requiring careful design and ongoing evaluation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
