4 papers
(EC)2: Event-Centric Explainability for Cybersecurity Through Multi-Agent LLM Investigations
Neta Kirmayer, David Tayouri, Andrés Murillo +3
Security operations centers rely on anomaly detection systems to flag suspicious events. Feature-level explanations for anomaly detectors offer limited value for operational invest…
COHORT: Collaborative Orchestration for Hardening via Offensive Replay on Emulated Topologies
Chen Frydman, Aviram Zilberman, Rubin Krief +6
Mitigating an observed adversary in an enterprise network typically takes weeks of expert work: an analyst derives a mitigation tailored to that adversary, validates it without bre…
SCyTAG: Scalable Cyber-Twin for Threat-Assessment Based on Attack Graphs
David Tayouri, Elad Duani, Abed Showgan +8
Understanding the risks associated with an enterprise environment is the first step toward improving its security. Organizations employ various methods to assess and prioritize the…
Labeling NIDS Rules with MITRE ATT&CK Techniques: Machine Learning vs. Large Language Models
Nir Daniel, Florian Klaus Kaiser, Shay Giladi +6
Analysts in Security Operations Centers (SOCs) are often occupied with time-consuming investigations of alerts from Network Intrusion Detection Systems (NIDS). Many NIDS rules lack…