Pith. sign in

REVIEW 3 cited by

Automated Retrieval of ATT&CK Tactics and Techniques for Cyber Threat Reports

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2004.14322 v1 pith:XWJXAQGS submitted 2020-04-29 cs.CR cs.LG

classification cs.CRcs.LG
keywords threatcybertacticstechniquesapproachesautomatedreportsttps
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Over the last years, threat intelligence sharing has steadily grown, leading cybersecurity professionals to access increasingly larger amounts of heterogeneous data. Among those, cyber attacks' Tactics, Techniques and Procedures (TTPs) have proven to be particularly valuable to characterize threat actors' behaviors and, thus, improve defensive countermeasures. Unfortunately, this information is often hidden within human-readable textual reports and must be extracted manually. In this paper, we evaluate several classification approaches to automatically retrieve TTPs from unstructured text. To implement these approaches, we take advantage of the MITRE ATT&CK framework, an open knowledge base of adversarial tactics and techniques, to train classifiers and label results. Finally, we present rcATT, a tool built on top of our findings and freely distributed to the security community to support cyber threat report automated analysis.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. TRACE-CTI: Auditable Post-Extraction Governance of TTP Claims with Knowledge Graphs

    cs.AI 2026-07 conditional novelty 6.0 of 10

    A knowledge-graph claim-governance layer raises gold-aligned precision of multi-setup TTP mappings from 25.3% to 90.6% while preserving full provenance and non-destructive trust history.

  2. From Text to Actionable Intelligence: Automating STIX Entity and Relationship Extraction

    cs.CR 2025-07 conditional novelty 6.0 of 10

    Fine-tuned LLMs extract STIX entities and relationships from threat reports with per-module F1 scores of 84.4%, 88.5%, 95.5%, and 84.6%, backed by a new 4,011-entity annotated dataset.

  3. SynthCTI: LLM-Driven Synthetic CTI Generation to enhance MITRE Technique Mapping

    cs.CR 2025-07 conditional novelty 5.0 of 10

    A clustering-guided LLM data augmentation pipeline raises macro-F1 for MITRE technique classification, e.g., ALBERT from 0.35 to 0.52 and SecureBERT to 0.66, across two CTI datasets.

Pith tools