Researchers have introduced SCRIPTIOC-BENCH, a new benchmark designed to evaluate the capability of large language models (LLMs) in extracting actionable threat intelligence from script-based malware. The benchmark includes 634 manually verified samples of JavaScript, PowerShell, and VBScript, categorizing indicators of compromise (IOCs) such as URLs, domains, IP addresses, and filesystem artifacts. Initial evaluations show that even the most advanced LLMs struggle with static IOC recovery, achieving a maximum F1 score of 65.4%. The study also proposes a taxonomy for false positives to better understand model errors and explores mitigations like deterministic string utilities and task-specific adaptation, which show complementary gains in recovery and precision. AI
IMPACT Highlights limitations in current LLM capabilities for automated malware analysis and threat intelligence extraction.
RANK_REASON The cluster describes a new academic benchmark and evaluation of LLMs on a specific task within AI safety and security. [lever_c_demoted from research: ic=1 ai=1.0]
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →