2 papers
cs.CR2025
ActMiner: Applying Causality Tracking and Increment Aligning for Graph-based Cyber Threat Hunting
Mingjun Ma, Tiantian Zhu, Shuang Li +4
To defend against Advanced Persistent Threats on the endpoint, threat hunting employs security knowledge such as cyber threat intelligence to continuously analyze system audit logs…
cs.CR2025
OMNISEC: LLM-Driven Provenance-based Intrusion Detection via Retrieval-Augmented Behavior Prompting
Wenrui Cheng, Tiantian Zhu, Shunan Jing +4
Recently, Provenance-based Intrusion Detection Systems (PIDSes) have been widely used for endpoint threat analysis. These studies can be broadly categorized into rule-based detecti…