LLM-Powered Proactive Cyber-Defense Framework Using Cyber-Threat Indicators Collected from X Platform
Abstract
1. Introduction
2. Background and Technical Foundations
2.1. Overview of OSINT Sources
2.2. Pre-Trained LLM and Adaptation Strategies
- Fine-tuning: This strategy involves further training a pre-trained LLM on task-specific data, allowing the model to adjust its internal parameters while retaining general language knowledge [2]. Fine-tuning can range from full-parameter updates for maximal domain alignment to parameter-efficient approaches which update only a small subset of parameters, reducing computational overhead. Another common approach involves attaching task-specific components, such as Bidirectional Long Short-Term Memory (BiLSTM) and Fully Connected (FC) layers, in addition to the LLM representations. In such configurations, the underlying LLM may be fully fine-tuned, partially frozen, or used as a fixed feature encoder, offering flexible trade-offs between performance, generalization, and computational efficiency.
- Prompt engineering: This technique entails crafting input prompts to guide the model toward producing accurate, relevant, and contextually appropriate outputs without modifying model parameters [9,21]. Prompt engineering enables rapid adaptation across tasks with minimal computational cost, making it well suited to resource-constrained environments. Common techniques include zero-shot, one-shot, and few-shot prompting, as well as chain-of-thought, role-based prompts, and attribute-based prompts that impose user-defined constraints (e.g., tone, length, or output format) to improve controllability and task specificity.
- In-context learning: This technique exploits the capacity of models to infer task structure and desired behavior directly from a small number of examples embedded within the input context. This technique enables the models to generalize from an exemplar without task descriptions or parameter updates, eliminating additional training costs.
- Reinforcement learning with human feedback: This method improves alignment between model outputs and individual expectations by incorporating reinforcement signals derived from human evaluators preferences [22]. This method penalizes undesirable behaviors and rewards responses that align with domain objectives, improving output quality and reliability.
- Retrieval-augmented generation (RAG): This strategy augments LLM with external knowledge sources, such as vector databases or curated document repositories, enabling the retrieval of relevant information at inference time [9]. By grounding generation on trusted external sources, RAG improves factual accuracy, reduces hallucinations, and enhances domain relevance without additional model training.
2.3. Metrics and Methods for Evaluating LLM Outputs
3. Related Work
3.1. ML-Enabled CTI Solutions
3.2. LLM-Enabled CTI Solutions
4. Methodology
4.1. Data Collection
4.2. Data Labeling
4.3. Data Augmentation and Enrichment
4.4. Data Preprocessing
- Duplicate removal: To mitigate redundancy and potential sampling bias, pairwise Jaccard similarity is computed between collected tweets. Tweets exhibiting a similarity score greater than are considered near-duplicates and removed. Tweets generated during the data augmentation phase are excluded from this process to preserve synthetic sample diversity. Following this step, unique tweets are retained. When combined with the synthetic samples introduced during data augmentation, the final dataset comprises tweets, including 7978 not reporting IoC samples and 8125 reporting IoC samples.
- Text cleaning: Raw tweets often contain noise such as special characters, emoticons, emojis. These elements are removed using Regex, ensuring tweet semantic integrity. Moreover, non-English tweets were filtered solely to ensure compatibility with the English-based LLM used in this study; this filtering was not based on the geographic origin of the tweets.
- Normalization: In the domain of cybersecurity, identical concepts are frequently expressed in heterogeneous lexical forms. For instance, the term “two-factor authentication” may appear as “2FA”, while “command and control” is often abbreviated to “C2” or “C&C.” To address this lexical variability, we adopted the domain-specific normalization lexicon proposed by [38]. This normalization strategy enforces a consistent representation of semantically equivalent terms, reducing vocabulary fragmentation and improving downstream NLP and ML reliability.
- Stop words and punctuation filtering: Stop words, which primarily serve grammatical functions and contribute limited semantic value in isolation, are removed, along with punctuation. The English stop words list from the NLTK (http://www.nltk.org/ (accessed on 10 January 2026)) “stopwords” corpus is used for this purpose.
4.5. Model Training
4.6. IoC Extraction
4.7. IoC Alert Report Generation
4.8. Custom User Interface
4.9. Evaluation Criteria
4.9.1. Performance
4.9.2. Output Quality
- Relevance: alignment of the generated tweet with the intent and constraints specified in the prompt.
- Coherence: logical flow and readability of the content.
- Fluency: Grammatical correctness and the naturalness of the language.
- Correctness: factual and contextual accuracy, including the appropriate defanging of any referenced IoCs where applicable.
4.9.3. Technology Acceptance
5. Results
5.1. Evaluate Synthetic Data
5.2. Evaluate ML Models
5.3. Evaluate IoC Alert Report Summary
5.4. Technology Acceptance Evaluation
5.5. Characteristics of Extracted IoCs
5.5.1. File Hashes
5.5.2. URLs
5.5.3. IP Addresses
5.6. Comparison with State-of-Art ML-Enabled Solutions
5.7. Comparison with LLM-Enabled Solutions
6. Discussion
6.1. Practical Applications
6.2. Limitations
7. Conclusions and Future Work
Funding
Data Availability Statement
Conflicts of Interest
Abbreviations
| AU | Actual Use |
| BERT | Bidirectional Encoder Representations from Transformers |
| BI | Behavioral Intention |
| BLEU | Bilingual Evaluation Understudy |
| CTI | Cyber Threat Intelligence |
| IoCs | Indicators of Compromise |
| NLI | Natural Language Inference |
| OSINT | Open-Source Intelligence |
| PEoU | Perceived Ease of Use |
| PR | Perceived Risk |
| PT | Perceived Trust |
| PU | Perceived Usefulness |
| RAG | Retrieval-Augmented Generation |
| Regex | Regular Expressions |
| ROUGE | Recall-Oriented Understudy for Gisting Evaluation |
| RTS | Reason-then-Score |
| SBERT | Sentence-BERT |
| SOCs | Security Operations Centers |
| STIX | Structured Threat Information eXpression |
| TAM | Technology Acceptance Model |
References
- Shin, H.; Shim, W.; Kim, S.; Lee, S.; Kang, Y.G.; Hwang, Y.H. # Twiti: Social listening for threat intelligence. In Proceedings of the Web Conference 2021, Ljubljana, Slovenia, 19–23 April 2021; Association for Computing Machinery: New York, NY, USA, 2021; pp. 92–104. [Google Scholar]
- Almutairi, N.; Coenen, F.; Elhanashi, A. Leveraging LLMs for Customized CTI Based on Indicators of Compromise From X: A Comparative Study with Traditional ML. IEEE Access 2025, 13, 206673–206694. [Google Scholar] [CrossRef]
- Dionísio, N.; Alves, F.; Ferreira, P.M.; Bessani, A. Towards end-to-end cyberthreat detection from Twitter using multi-task learning. In Proceedings of the 2020 International Joint Conference on Neural Networks (IJCNN), Glasgow, UK, 19–24 July 2020; IEEE: Piscataway, NJ, USA, 2020; pp. 1–8. [Google Scholar]
- Zhu, Z.; Dumitras, T. Chainsmith: Automatically learning the semantics of malicious campaigns by mining threat intelligence reports. In Proceedings of the 2018 IEEE European Symposium on Security and Privacy (EuroS&P), London, UK, 24–26 April 2018; IEEE: Piscataway, NJ, USA, 2018; pp. 458–472. [Google Scholar]
- Niakanlahiji, A.; Safarnejad, L.; Harper, R.; Chu, B.T. IoCMiner: Automatic extraction of indicators of compromise from twitter. In Proceedings of the 2019 IEEE International Conference on Big Data (Big Data), Los Angeles, CA, USA, 9–12 December 2019; IEEE: Piscataway, NJ, USA, 2019; pp. 4747–4754. [Google Scholar]
- Liao, X.; Yuan, K.; Wang, X.; Li, Z.; Xing, L.; Beyah, R. Acing the IoC game: Toward automatic discovery and analysis of open-source cyber threat intelligence. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security; ACM: New York, NY, USA, 2016; pp. 755–766. [Google Scholar] [CrossRef]
- Zhao, J.; Yan, Q.; Li, J.; Shao, M.; He, Z.; Li, B. TIMiner: Automatically extracting and analyzing categorized cyber threat intelligence from social data. Comput. Secur. 2020, 95, 101867. [Google Scholar] [CrossRef]
- Ghazi, Y.; Anwar, Z.; Mumtaz, R.; Saleem, S.; Tahir, A. A supervised machine learning based approach for automatically extracting high-level threat intelligence from unstructured sources. In Proceedings of the 2018 International Conference on Frontiers of Information Technology (FIT), Islamabad, Pakistan, 17–19 December 2018; IEEE: Piscataway, NJ, USA, 2018; pp. 129–134. [Google Scholar]
- French, W. Enhancing Threat Hunting Automation with Large Language Models. Master’s Thesis, North Carolina at Charlotte, Charlotte, NC, USA, 2024. [Google Scholar]
- Piazza, R.; Ratliff, E.; Relitz, S.; Studer, C. STIX Version 2.1 Errata 01. OASIS Committee Specification Draft 01, 2025. Latest Stage. Available online: https://docs.oasis-open.org/cti/stix/v2.1/stix-v2.1.html (accessed on 20 January 2026).
- Gong, S.; Cho, J.; Lee, C. A reliability comparison method for OSINT validity analysis. IEEE Trans. Ind. Inform. 2018, 14, 5428–5435. [Google Scholar] [CrossRef]
- IPVoid. 2024. Available online: https://www.ipvoid.com (accessed on 20 October 2024).
- Hybrid Analysis. 2024. Available online: https://www.hybrid-analysis.com (accessed on 20 October 2024).
- VirusTotal. 2024. Available online: https://www.virustotal.com/gui/home/upload (accessed on 20 October 2024).
- Peng, P.; Yang, L.; Song, L.; Wang, G. Opening the blackbox of virustotal: Analyzing online phishing scan engines. In Proceedings of the Internet Measurement Conference; ACM: New York, NY, USA, 2019; pp. 478–485. [Google Scholar] [CrossRef]
- Froudakis, E.; Avgetidis, A.; Frankum, S.T.; Perdisci, R.; Antonakakis, M.; Keromytis, A.D. Revealing the True Indicators: Understanding and Improving IoC Extraction From Threat Reports. arXiv 2025, arXiv:2506.11325. [Google Scholar] [CrossRef]
- 2024 Verizon Annual Data Breach Investigations Report. 2024. Available online: https://www.verizon.com/business/resources/reports/2024-dbir-data-breach-investigations-report.pdf (accessed on 13 March 2025).
- Basheer, R.; Alkhatib, B. Threats from the dark: A review over dark web investigation research for cyber threat intelligence. J. Comput. Netw. Commun. 2021, 2021, 1302999. [Google Scholar] [CrossRef]
- Mischinger, M.; Pastrana, S.; Suarez-Tangil, G. IoC Stalker: Early detection of Indicators of Compromise. In Proceedings of the Annual Computer Security Applications Conference, Honolulu, HI, USA, 9–13 December 2024. [Google Scholar]
- Hutchings, A.; Holt, T.J. A Crime Script Analysis of the Online Stolen Data Market. Br. J. Criminol. 2014, 55, 596–614. [Google Scholar] [CrossRef]
- Shenoy, N.; Mbaziira, A.V. An Extended Review: LLM Prompt Engineering in Cyber Defense. In Proceedings of the 2024 International Conference on Electrical, Computer and Energy Technologies (ICECET), Sydney, Australia, 25–27 July 2024; pp. 1–6. [Google Scholar] [CrossRef]
- Wang, X.; Peng, J.; Xu, K.; Yao, H.; Chen, T. Reinforcement learning-driven llm agent for automated attacks on llms. In Proceedings of the Fifth Workshop on Privacy in Natural Language Processing; Association for Computational Linguistics: Sidney, Australia, 2024; pp. 170–177. [Google Scholar]
- van Schaik, T.A.; Pugh, B. A Field Guide to Automatic Evaluation of LLM-Generated Summaries. In Proceedings of the 47th International ACM SIGIR Conference on Research and Development in Information Retrieval; Association for Computing Machinery: New York, NY, USA, 2024; SIGIR ’24; pp. 2832–2836. [Google Scholar] [CrossRef]
- Papineni, K.; Roukos, S.; Ward, T.; Zhu, W.J. Bleu: A Method for Automatic Evaluation of Machine Translation. In Proceedings of the 40th Annual Meeting of the Association for Computational Linguistics; Isabelle, P., Charniak, E., Lin, D., Eds.; Association for Computational Linguistics: Philadelphia, PA, USA, 2002; pp. 311–318. [Google Scholar] [CrossRef]
- Lin, C.Y. ROUGE: A Package for Automatic Evaluation of Summaries. In Proceedings of the Text Summarization Branches Out; The Association for Computational Linguistics: Barcelona, Spain, 2004; pp. 74–81. [Google Scholar]
- Laban, P.; Schnabel, T.; Bennett, P.N.; Hearst, M.A. SummaC: Re-visiting NLI-based models for inconsistency detection in summarization. Trans. Assoc. Comput. Linguist. 2022, 10, 163–177. [Google Scholar] [CrossRef]
- Kryściński, W.; McCann, B.; Xiong, C.; Socher, R. Evaluating the factual consistency of abstractive text summarization. In Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing (EMNLP); The Association for Computational Linguistics: Barcelona, Spain, 2020; pp. 9332–9346. [Google Scholar]
- Beresneva, D. Computer-generated text detection using machine learning: A systematic review. In Proceedings of the International Conference on Applications of Natural Language to Information Systems; Springer: Berlin/Heidelberg, Germany, 2016; pp. 421–426. [Google Scholar]
- Cachola, I.; Khashabi, D.; Dredze, M. Evaluating the Evaluators: Are readability metrics good measures of readability? In Proceedings of the 2025 Conference on Empirical Methods in Natural Language Processing; Christodoulopoulos, C., Chakraborty, T., Rose, C., Peng, V., Eds.; Association for Computational Linguistics: Suzhou, China, 2025; pp. 24011–24027. [Google Scholar] [CrossRef]
- Zhou, S.; Long, Z.; Tan, L.; Guo, H. Automatic Identification of Indicators of Compromise using Neural-Based Sequence Labelling. arXiv 2018, arXiv:1810.10156. [Google Scholar] [CrossRef]
- Long, Z.; Tan, L.; Zhou, S.; He, C.; Liu, X. Collecting Indicators of Compromise from Unstructured Text of Cybersecurity Articles using Neural-Based Sequence Labelling. In Proceedings of the 2019 International Joint Conference on Neural Networks (IJCNN), Budapest, Hungary, 14–19 July 2019; pp. 1–8. [Google Scholar] [CrossRef]
- Arikkat, D.R.; Vinod, P.; Rehiman, K.A.R.; Sorbo, A.D.; Visaggio, C.A.; Conti, M. Discerning Reliable Cyber Threat Indicators for Timely Cyber Threat Intelligence. J. Comput. Virol. Hacking Tech. 2025, 21, 25. [Google Scholar] [CrossRef]
- Gharibshah, J.; Li, T.C.; Castro, A.; Pelechrinis, K.; Papalexakis, E.E.; Faloutsos, M. Mining actionable information from security forums: The case of malicious IP addresses. In From Security to Community Detection in Social Networking Platforms; Springer: Cham, Switzerland, 2019; pp. 193–211. [Google Scholar] [CrossRef]
- Preuveneers, D.; Joosen, W. Sharing Machine Learning Models as Indicators of Compromise for Cyber Threat Intelligence. J. Cybersecur. Priv. 2021, 1, 140–163. [Google Scholar] [CrossRef]
- State of Threat Detection Report 2023. 2023. Available online: https://www.vectra.ai/resources/2023-state-of-threat-detection (accessed on 22 February 2026).
- Balasubramanian, P.; Nazari, S.; Kholgh, D.K.; Mahmoodi, A.; Seby, J.; Kostakos, P. A cognitive platform for collecting cyber threat intelligence and real-time detection using cloud computing. Decis. Anal. J. 2025, 14, 100545. [Google Scholar] [CrossRef]
- X Search API, 2024. Available online: https://developer.x.com/en/docs/twitter-api/v1/tweets/search/overview (accessed on 20 January 2024).
- Marinho, R.; Holanda, R. Automated emerging cyber threat identification and profiling based on natural language processing. IEEE Access 2023, 11, 58915–58936. [Google Scholar] [CrossRef]
- Songailaitė, M.; Kankevičiūtė, E.; Zhyhun, B.; Mandravickaitė, J. BERT-based models for phishing detection. In Proceedings of the 28th Conference on Information Society and University Studies (IVUS’2023), Kaunas, Lithuania, 12 May 2023; CEUR Workshop Proceedings; CEUR-WS: Aachen, Germany, 2023. [Google Scholar]
- Elsadig, M.; Ibrahim, A.O.; Basheer, S.; Alohali, M.A.; Alshunaifi, S.; Alqahtani, H.; Alharbi, N.; Nagmeldin, W. Intelligent deep machine learning cyber phishing url detection based on bert features extraction. Electronics 2022, 11, 3647. [Google Scholar] [CrossRef]
- Demirol, D.; Das, R.; Hanbay, D. A Novel Approach for Cyber Threat Analysis Systems Using BERT Model from Cyber Threat Intelligence Data. Symmetry 2025, 17, 587. [Google Scholar] [CrossRef]
- InQuest. IoC-Extractor, 2024. Available online: https://github.com/InQuest/iocextract (accessed on 14 August 2024).
- Davis, F.D. Technology acceptance model: TAM. Al-Suqri MN Al-Aufi AS Inf. Seek. Behav. Technol. Adopt. 1989, 205, 5. [Google Scholar]
- Almutairi, N.; Elhanashi, A. Leveraging IoT and dedicated social networks to enhance mosque role and activities management in Saudi Arabia. Digit. Bus. 2025, 5, 100151. [Google Scholar] [CrossRef]
- Alshammari, M.M.; Al-Mamary, Y.H. User acceptance of AI-powered training: Extending the technology acceptance model (TAM). Future Bus. J. 2025, 11, 239. [Google Scholar] [CrossRef]
- Zhang, T.; Tao, D.; Qu, X.; Zhang, X.; Lin, R.; Zhang, W. The roles of initial trust and perceived risk in public’s acceptance of automated vehicles. Transp. Res. Part C Emerg. Technol. 2019, 98, 207–220. [Google Scholar] [CrossRef]
- Im, I.; Kim, Y.; Han, H.J. The effects of perceived risk and technology type on users’ acceptance of technologies. Inf. Manag. 2008, 45, 1–9. [Google Scholar] [CrossRef]
- Choung, H.; David, P.; Ross, A. Trust in AI and its role in the acceptance of AI technologies. Int. J. Hum.–Comput. Interact. 2023, 39, 1727–1739. [Google Scholar] [CrossRef]
- Field, A. Discovering Statistics Using IBM SPSS Statistics; Sage Publications Limited: New York, NY, USA, 2024. [Google Scholar]
- Kaspersky. Kaspersky Threat Intelligence Portal, 2025. Available online: https://opentip.kaspersky.com/ (accessed on 23 January 2025).
















| Feature | Description | Type |
|---|---|---|
| Tweet ID | Tweets unique identifier | Numerical |
| Tweet text | Textual content of the tweet | Text |
| Keywords | Keywords used for tweet retrieval | Categorical |
| User Account | Author account name | Text |
| Keywords Type | No. of Tweets | Class Label | |
|---|---|---|---|
| Tweets Report IoCs | Tweets Not Report IoCs | ||
| General | 5791 | 2302 | 3489 |
| Domain | 3813 | 2980 | 833 |
| Expert account | 4790 | 457 | 4333 |
| Total | 5739 | 8655 | |
| Topics | Phishing awareness training, ransomware trends, privileged access security, social engineering prevention, employee cybersecurity awareness, LLM jailbreaks, patch management, cloud misconfigurations, insider threats, insider data leaks, AI in cybersecurity, IoT device security, malware detection techniques, DDoS attack mitigation, email spoofing, and threat intelligence sharing. |
| Parameter | Value |
|---|---|
| Model | ChatGPT-4o |
| Sample size | 5000 tweets |
| Batch size | 10 per API call |
| Temperature | , , (to encourage diversity) |
| Top-p | |
| Max token | 120 |
| Model ID | Model Name | Description/Modification |
|---|---|---|
| M1 | Hybrid BERT–BiLSTM (Full Model) | The complete model that integrates BERT sequence embeddings and the CLS pooler output, followed by BiLSTM, attention layer, and FC layers. |
| M2 | Hybrid BERT (Sequence output)–BiLSTM | Same as the full hybrid model but removes the CLS pooler output branch, using only sequence embeddings processed through BiLSTM, attention layer, and FC layers. |
| M3 | BERT (Pooler output) | Only the CLS pooler output representation is retained and passed to FC layers, without incorporating sequence embeddings, BiLSTM components, or an intention layer. |
| Metric | Relevance | Correctness | Coherence | Fluency | Overall |
|---|---|---|---|---|---|
| Mean score | |||||
| Agreement () |
| Model | Using Original and Synthetic Data | ||||
| Accuracy | Precision | Recall | Specification | F1-Score | |
| M1 | |||||
| M2 | |||||
| M3 | |||||
| Using Original Data | |||||
| Accuracy | Precision | Recall | Specification | F1-Score | |
| M1 | 0.9825 | 0.9793 | 0.9863 | 0.9786 | 0.9828 |
| M2 | 0.9836 | 0.9807 | 0.9870 | 0.9801 | 0.9839 |
| M3 | 0.9369 | 0.9292 | 0.9476 | 0.9259 | 0.9383 |
| Category | Metrics | Value |
|---|---|---|
| Reference-based | SBERT | |
| Entailment | ||
| FactCC | ||
| Reference-free | Perplexity | |
| Readability | ||
| RTS |
| Variable | Category | Number of Participants (%) |
|---|---|---|
| Year of Experience | Less than 3 years | 8 (%) |
| 3–9 years | 35 (%) | |
| 10+ years | 35 (%) | |
| Age Group (Years) | 21–26 | 9 (%) |
| 27–35 | 32 (%) | |
| 36+ | 37 (%) | |
| Gender | Male | 40 (%) |
| Female | 38 (%) |
| Test/Variable | PEoU | PU | PT | PR | BI | AU |
|---|---|---|---|---|---|---|
| Cronbach’s Alpha | ||||||
| Skewness | ||||||
| Kurtosis |
| H1 | H2 | H3 | H4 | H5 | H6 | H7 | H8 | |
|---|---|---|---|---|---|---|---|---|
| PEoU→PU | PEoU→BI | PU→BI | PT→PU | PT→BI | PT→PR | PR→BI | BI→AU | |
| p | <0.05 | <0.05 | <0.05 | <0.05 | <0.05 | |||
| Decision | Rejected | Rejected | Supported | Supported | Supported | Supported | Supported | Supported |
| Collected Artifacts | Total | Unique | Verified (%) 1 |
|---|---|---|---|
| Hashes | 938 | 879 | 825 (%) |
| URLs | 5630 | 4747 | 4533 (%) |
| IPs | 2455 | 1665 | 1178 (%) |
| Overall | 9023 | 7291 | 6536 (%) |
| Properties | iACE | TIMiner | ChainSmith | IoCMiner | MTL-CTI | IoC-Collector | LLM-Powered | |
|---|---|---|---|---|---|---|---|---|
| [6] | [7] | [4] | [5] | [3] | [2] | |||
| Algorithm | Data source | Technical blog | Social media | Security articles | X | Social media | X | X |
| ML Classifier | LR | CNN | LDA | RF | RNN | SVM | hybrid | |
| Feature | NER | Word2Vec & syntactic dependencies | Embedding & NER | BoW | Embedding& NER | Unigram/bigram ∪ IoC-centric ∪ sentiment scores | Contextualized BERT embeddings | |
| Task | Mining | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ |
| Extracting | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ | |
| Operational integration | OpenIoC items | Threat-Index | ✕ | ✕ | ✕ | ✕ | STIX | |
| Advanced feature | ✕ | ✕ | ✕ | ✕ | ✕ | Prioritization | Alerting with contextual summary | |
| Perf. | Accuracy | NR | % | NR | % | NR | % | % |
| Precision | % | NR | % | NR | NR | % | % | |
| Recall | % | 9200 | % | NR | NR | % | % | |
| F1-score | % | % | NR | NR | % | % | % | |
| Acceptance Evaluation | ✕ | ✕ | ✕ | ✕ | ✕ | ✕ | TAM | |
| Property | LANCE [16] | TSTEM [36] | AIThreatAttack with RAG [9] | IoC-Collector [2] | LLM-Powered |
|---|---|---|---|---|---|
| Data Source (Size) | CTI reports (50) | Online sources ( training 1000 testing and 600 validation) | X (71 unique tweets) | X (3148 unique tweets) | X ( unique tweets) |
| LLM | ChatGPT-4o | BERT | ChatGPT-4 | BERT | BERT |
| Adoption Strategy | Prompt zero-shot | Fine-tuned BERT | RAG & prompt | Fine-tuned BERT with classification head and extended tokenizer | Fine-tuned with hybrid classification head |
| Tasks | Mining & Extraction | Mining & extraction | Extraction, ElasticSearch, & Kibana query generation | Mining, extraction, prioritization, & verifying | Mining, extraction, reporting, & verifying |
| Extracted Artifacts | Total: 1791 Unique: 1791 | Total: 163 Unique: 79 | Total: 336 Unique: 336 | Total: 1855 Unique: 1529 | Total: 9023 Unique: 7291 |
| Advanced LLM-enabled functionalities (if any) | Color-coded visual cues for IoC interpretation | None | None | None | Alerting with contextual summary |
| Performance | Precision: % F1: % | Accuracy: % Precision: % Recall % F1: % | 45% IoCs were missed & % hallucination rate | Accuracy: % Precision: % Recall: % F1: % | Accuracy: % Precision: % Recall: % F1: % |
| Efficiency | NR | High computational cost | NR | Training: min. Testing: min. | Training: min. Testing: min. |
| Acceptance Evaluation | ✕ | ✕ | ✕ | ✕ | TAM |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the author. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Almutairi, N. LLM-Powered Proactive Cyber-Defense Framework Using Cyber-Threat Indicators Collected from X Platform. Electronics 2026, 15, 1305. https://doi.org/10.3390/electronics15061305
Almutairi N. LLM-Powered Proactive Cyber-Defense Framework Using Cyber-Threat Indicators Collected from X Platform. Electronics. 2026; 15(6):1305. https://doi.org/10.3390/electronics15061305
Chicago/Turabian StyleAlmutairi, Nawal. 2026. "LLM-Powered Proactive Cyber-Defense Framework Using Cyber-Threat Indicators Collected from X Platform" Electronics 15, no. 6: 1305. https://doi.org/10.3390/electronics15061305
APA StyleAlmutairi, N. (2026). LLM-Powered Proactive Cyber-Defense Framework Using Cyber-Threat Indicators Collected from X Platform. Electronics, 15(6), 1305. https://doi.org/10.3390/electronics15061305

