Pith. sign in

REVIEW 2 cited by

CTI-HAL: A Human-Annotated Dataset for Cyber Threat Intelligence Analysis

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2504.05866 v1 pith:WVV74OGR submitted 2025-04-08 cs.CR

classification cs.CR
keywords datasetcyberintelligencelanguagereportsthreataccordingadvanced
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Organizations are increasingly targeted by Advanced Persistent Threats (APTs), which involve complex, multi-stage tactics and diverse techniques. Cyber Threat Intelligence (CTI) sources, such as incident reports and security blogs, provide valuable insights, but are often unstructured and in natural language, making it difficult to automatically extract information. Recent studies have explored the use of AI to perform automatic extraction from CTI data, leveraging existing CTI datasets for performance evaluation and fine-tuning. However, they present challenges and limitations that impact their effectiveness. To overcome these issues, we introduce a novel dataset manually constructed from CTI reports and structured according to the MITRE ATT&CK framework. To assess its quality, we conducted an inter-annotator agreement study using Krippendorff alpha, confirming its reliability. Furthermore, the dataset was used to evaluate a Large Language Model (LLM) in a real-world business context, showing promising generalizability.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. From Text to Actionable Intelligence: Automating STIX Entity and Relationship Extraction

    cs.CR 2025-07 conditional novelty 6.0 of 10

    Fine-tuned LLMs extract STIX entities and relationships from threat reports with per-module F1 scores of 84.4%, 88.5%, 95.5%, and 84.6%, backed by a new 4,011-entity annotated dataset.

  2. SynthCTI: LLM-Driven Synthetic CTI Generation to enhance MITRE Technique Mapping

    cs.CR 2025-07 conditional novelty 5.0 of 10

    A clustering-guided LLM data augmentation pipeline raises macro-F1 for MITRE technique classification, e.g., ALBERT from 0.35 to 0.52 and SecureBERT to 0.66, across two CTI datasets.

Pith tools