PulseAugur
LIVE 06:28:20
research · [1 source] ·
0
research

OntoLogX uses LLMs to extract actionable threat intelligence from cybersecurity logs

Researchers have developed OntoLogX, an AI agent designed to extract Cyber Threat Intelligence (CTI) from raw cybersecurity logs. The system utilizes Large Language Models (LLMs) combined with a lightweight log ontology and Retrieval Augmented Generation (RAG) to transform unstructured log data into structured Knowledge Graphs (KGs). OntoLogX also predicts MITRE ATT&CK tactics, linking low-level log evidence to higher-level adversarial objectives, and has demonstrated robust KG generation and accurate mapping of adversarial activity on benchmark and real-world datasets. AI

Summary written by gemini-2.5-flash-lite from 1 source. How we write summaries →

IMPACT Enhances CTI extraction from logs, potentially improving threat detection and response capabilities.

RANK_REASON Academic paper detailing a new AI agent for cybersecurity log analysis.

Read on arXiv cs.AI →

COVERAGE [1]

  1. arXiv cs.AI TIER_1 · Luca Cotti, Idilio Drago, Anisa Rula, Devis Bianchini, Federico Cerutti ·

    OntoLogX: Ontology-Guided Knowledge Graph Extraction from Cybersecurity Logs with Large Language Models

    arXiv:2510.01409v2 Announce Type: replace Abstract: System logs represent a valuable source of Cyber Threat Intelligence (CTI), capturing attacker behaviors, exploited vulnerabilities, and traces of malicious activity. Yet their utility is often limited by lack of structure, sema…