Pith. sign in

Kairos: Practical intrusion detection and investigation using whole-system provenance

2 Pith papers cite this work, alongside 5 external citations. Polarity classification is still indexing.

2 Pith papers citing it
5 external citations · external index

fields

cs.CR 2

years

2026 2

verdicts

UNVERDICTED 2

representative citing papers

ARuleCon: Agentic Security Rule Conversion

cs.CR · 2026-04-08 · unverdicted · novelty 6.0

ARuleCon uses AI agents plus execution-based checks to convert SIEM rules across vendors with 15% higher fidelity than standard LLM translation.

citing papers explorer

Showing 2 of 2 citing papers.

  • HIDBench: Benchmarking Large Language Models for Host-Based Intrusion Detection cs.CR · 2026-05-20 · unverdicted · none · ref 26

    HIDBench unifies DARPA-E3, DARPA-E5, and NodLink datasets with a data pipeline to benchmark LLMs for host-based intrusion detection, showing high precision on simple logs but sharp drops in MCC and rises in false positives on complex noisy data.

  • ARuleCon: Agentic Security Rule Conversion cs.CR · 2026-04-08 · unverdicted · none · ref 7

    ARuleCon uses AI agents plus execution-based checks to convert SIEM rules across vendors with 15% higher fidelity than standard LLM translation.