logo

Inside the AI x Security Arsenal I’ve Built

ID: cfd73237-f4f9-58c1-9540-2f69796db261

STIX ID: report--cfd73237-f4f9-58c1-9540-2f69796db261

Feed Name: SecurityBreak

Date Published: 2025-05-15

Date Updated: 2026-04-19

Author: Thomas Roccia

...
...

This blog-style retrospective surveys a broad set of projects that fuse generative AI with threat intelligence and security operations, including IAT extraction tooling (IATelligence), report summarization via LLMs, a MSTICpy-based CTI agent, RAG over MITRE ATT&CK, multilingual leak exploration (ISOON) and ransomware leak triage (BlackBasta) with hybrid search, phishing analysis through browser/computer-use agents, a YARA-focused DocYara assistant, GraphRAG IOC enrichment, PCAP analysis with HYDE, and the NOVA prompt-pattern matching framework with MCP integrations and scanners; it concludes with reflections on GenAI’s practical value for CTI and a call for practitioners to adapt to evolving AI-driven workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.