Skip to content
Review Open access

Auto Threat AI: An Agentic and Explainable Framework for Automated Cyber Threat Intelligence Extraction

Jul 2026 · International Journal for Research in Applied Science and Engineering Technology · 0 citations

Abstract

Cyber Threat Intelligence (CTI) enables Security Operations Centers (SOCs) to understand adversary behavior, prioritize risks, and respond to cyber threats. However, cur-rent CTI workflows still depend heavily on manual analysis of unstructured threat reports, vulnerability advisories, open-source intelligence, social media posts, and structured feeds. This creates operational latency, inconsistent extraction quality, weak provenance, and limited scalability. This paper presents Auto Threat AI, an agentic and explainable framework for automated CTI extraction, correlation, scoring, and analyst-governed SOC operationalization. The proposed framework integrates determin-istic indicator extraction, Natural Language Processing (NLP), schema-guided Large Language Model (LLM) agents, graph-aware threat correlation, bounded risk scoring, evidence-first explainability, and Human-in-the-Loop (HITL) governance. The system ingests heterogeneous CTI sources, extracts entities and relations such as IOCs, CVEs, malware, campaigns, threat actors, tools, and techniques, constructs a threat knowledge graph, gen-erates campaign candidates, and presents risk-ranked intelligence through a SOC dashboard. Experimental evaluation on safe demonstration CTI data shows that the implemented prototype ingested 6 sources, extracted 36 entities, generated 33 relations, detected 11 threat events, identified 5 campaign candidates, and routed 8 items for HITL review. The results demonstrate that Auto Threat AI can reduce manual CTI processing effort while improving traceability, explainability, and analyst trust.

Read PDF

Similar papers

Preprint Aug 2026

STINER: Automated Extraction of Strategic Cyber Threat Intelligence from X

STINER, a taxonomy and expert-annotated corpus for extracting strategic intelligence from social media streams is introduced, and how social-media-driven extraction can surface early signals of the SafePay ransomware campaign prior to its retrospective characterization in vendor threat landscape reports is illustrated.

Yasir Ech-Chammakhy, Oussama Azrara, J. Chbili et al. · 0 citations
Conference Jul 2026

LLM Fine-Tuned Threat Intelligence Summarization Agent for CVE Report Automation

In this paper, an intelligent cyber threat intelligence framework involving automated vulnerability severity assessment, contextual risk interpretation and generation of mitigation recommendation is presented. The proposed system has been designed to analyze the CVE-related description of vulnerabilities and the security metadata related to them, classify the level of severity of the threat and estimate its relevance to risk with the help of a transformer-based natural language processing model. To build contextual awareness beyond classification, it adds a retrieval-augmented mechanism to recognize semantically similar vulnerability records for contextual evidence-based threat interpretation. It is additionally fortified with vulnerability analysis, like CVE retrieval, client qualifications, record following, and even visualisation as a web application platform. The two processes, one involving the severities of the transformers, and the other the retrieval of threat intelligence and mitigation advice, into a single operational flow, thus reducing the manual reliance on Vulnerability Triage and aiding security analysts in prioritizing cyber risks. The proposed framework allows for the automatic processing of textual information on vulnerabilities and the comparison of such information and a contextual analysis with previous vulnerabilities discovered. Unlike conventional vulnerability assessment approaches that perform severity classification independently of contextual threat interpretation, the proposed framework integrates transformer-based semantic analysis, retrieval-augmented vulnerability intelligence, cyber-risk estimation, and mitigation recommendation generation within a unified analytical workflow. By combining predictive language modelling with contextual vulnerability retrieval, the framework supports evidence-driven cyber threat analysis and structured decision support for security analysts. The proposed architecture provides a scalable approach for automated vulnerability prioritization and contextual cyber threat intelligence that is suitable for modern cybersecurity operations involving large volumes of vulnerability reports.

Someru Kuruva Giriraju, Shaik Khaja Baba, F. Mahammad et al. · 0 citations
Review Open access Jul 2026

Artificial Intelligence-Based Insider-Threat Detection: A Hybrid Explainable Framework with Automated Response and Privilege Containment

This paper introduces an explainable AI-based Insider-Threat Detection (AIB-ITD) model that integrates enterprise telemetry—including email, web, logon/VPN, and file events—into a unified behavioral framework and shows superior robustness, stability, and operational effectiveness to classical methods.

Abdel Rahman Alkharabsheh, Ghaya Binsalma, Mahra Alharmi et al. · 0 citations

An Automated Framework for Extracting Reachable Attack Chains from Cyber Threat Intelligence Reports

This paper proposes an automated framework that extracts reachable attack chains by modeling each attack step as an attack unit of preconditions, an attack behavior, and postconditions, and produces attack units that are more complete and consistent than those generated by end-to-end LLM baselines.

Wenbo Hou, N. Hu, Xueping Wang et al. · 0 citations
Review Open access 2026

Evolving Cyber Threat Intelligence: A Systematic Review and Comparative Analysis

To improve cybersecurity across industries, Cyber Threat Intelligence (CTI) is becoming increasingly crucial. This systematic review explores how CTI practices are evolving in response to advancements in Artificial Intelligence (AI), particularly in the context of Large Language Models (LLMs). We examined 61 peer-reviewed studies using the PRISMA methodology, which demonstrates a strict selection procedure founded on specified inclusion, exclusion, and quality standards. This approach aligns with the scope of similar systematic reviews in the field of cyber threat intelligence. The review provides a comparative synthesis of CTI research capabilities across threat detection and prediction, attribution, forecasting, and automated reporting. We classify these approaches into three categories: conventional methods, those enhanced by AI and Machine Learning, and those based on LLMs. Our findings indicate that LLMs offer significant advantages in contextual reasoning, processing unstructured threat intelligence, and generating actionable mitigation plans. However, challenges such as model explainability, data privacy, system interoperability, and standardization impede their integration into operational environments. In addition to highlighting the potential and practical limitations of LLMs in CTI, this study identifies research gaps and proposes methods to create scalable, secure, and flexible CTI systems that support real-time cyber defense.

Hilalah Alturkistani, Abdul Ghafar Jaafar, S. Chuprat et al. · 0 citations