Skip to content

Detection and Explanation of PowerShell Malware with Large Language Models

· 0 citations · 40 references

TL;DR

The application of LLMs for detecting malicious PowerShell scripts and producing human-interpretable explanations for their classification decisions are investigated, showing that LLMs are capable of identifying and explaining malicious PowerShell scripts, although performance varies across different models.

View source

Similar papers

#artificial intelligence Preprint Sep 2026

SCRIPTIOC-BENCH: A Benchmark for Recognizing Actionable Threat Intelligence from Script-Based Malware using LLMs

Script-based malware remains a prevalent attack technique. These scripts often contain indicators of compromise (IOCs) that provide actionable threat intelligence. However, statically recovering such indicators is challenging, as relevant values may be dispersed or transformed within code. Although large language model...

Hanna Kim, Jian Cui, Minkyoo Song et al. · 0 citations
Review Open access Aug 2026

To Compare Various Frameworks that Integrate XAI, GANs and LLMs for Dynamic Malware Behavior Analysis

A unified approach of malware analysis incorpo-rating XAI, GAN and LLM is proposed to enable the development of more effective malware detection tools with more transparency, deeper analytical insight and advanced forensic decision-making.

A. Verma, Neha Gupta, Akash Saxena et al. · 0 citations
Conference Jul 2026

LLM-Based Detection and Test Generation for Command Injection Vulnerabilities in Python

Command injection vulnerabilities remain a significant security threat in dynamic languages such as Python, particularly in widely used open-source projects. Recent advances in large language models (LLMs) have shown strong potential in code-related tasks, motivating their application to vulnerability detection.In this...

Yuxuan Wang, Jingshu Chen, Qingyang Wang · 0 citations
Preprint Aug 2026

Detecting Contaminated Code-Generation Prompt Batches via Influence Functions

Large language models (LLMs) are increasingly used for code generation, yet they remain vulnerable to prompts that elicit insecure implementations. Existing defenses typically rely on predefined threat models or known vulnerability patterns, limiting their effectiveness against novel attacks. We propose CodeSIFT, a thr...

Francesco Quinzan, Noor Munir, Yi-Shun Lu et al. · 0 citations
Preprint Aug 2026

MalTotal: Cost-Effective and Language-Agnostic Malicious Code Poisoning Detection for Millions of Repositories

MalTotal leverages LLM-assisted semantic reasoning to identify sensitive APIs, perform hybrid semantic slicing, and reconstruct malicious behavior contexts while reducing analysis overhead, demonstrating the effectiveness, scalability, and cost-efficiency of MalTotal in mitigating large-scale code poisoning attacks.

Jian Zhao, Shenao Wang, Qingyang Wu et al. · 1 citation · ⚡1

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.