Pith. sign in

Paper Citation Record · LEDGER

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models

As of 23 August 2026, this Paper Citation Record lists 81 of 81 outbound references and 0 inbound Pith citation observations for arXiv:2509.01271.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2509.01271 v1

Coverage vector

measured 81 of 81 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links, observed 2026-08-05T12:48:07.451736Z

measured 81 of 81 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-23T06:30:58.430688+00:00

measured 0 of 0 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links

measured 0 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: cited_works

Reference resolution

81 of 81 outbound references displayed

  • verified exact0
  • verified fuzzy63
  • unresolved18
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

No source-named external measurement is stored.

Outbound references

Observation d39dfd20-1f05-4bed-b6b9-ed95906ddfba · outbound

This paper cites https://www.cisa.gov/news-events/ alerts/2020/12/13/active-exploitation- solarwinds-software.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://www.cisa.gov/news-events/ alerts/2020/12/13/active-exploitation- solarwinds-software

Reference 1

Resolution
unresolved
no resolver link, observed 2026-08-05T12:48:07.247889Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T12:48:07.247889Z digest=sha256:882077a82ddf19ee849dac8a584e6930a955ebc390ce783765f12a421590e4d0

Observation 566a70af-17ad-475d-b846-4eae231ec2d6 · outbound

This paper cites https://anonymous.4open.science/r/Themis- LLM-B4EC.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://anonymous.4open.science/r/Themis- LLM-B4EC

Reference 2

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:08.134545Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.251045Z digest=sha256:2b3a43c82f5176a9cd962f1ad9a2fd15014a22fe13fb7be8c298673ef88b301d

Observation d8421e1a-7f89-4a23-8161-f9d845800ae5 · outbound

This paper cites https://docs.redhat.com/en/ documentation/red_hat_enterprise_linux/6/ html/security_guide/chap-system_auditing.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://docs.redhat.com/en/ documentation/red_hat_enterprise_linux/6/ html/security_guide/chap-system_auditing

Reference 3

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:08.125651Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.254267Z digest=sha256:2d0e054c3885ffbbb01f9a9991f921d7e38e4034dc2eaaf711655b14860fd11d

Observation f23285af-18a0-4873-9db4-14a40459aa51 · outbound

This paper cites https://www.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://www

Reference 4

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:08.116968Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.257627Z digest=sha256:64253fa8c0b92d6b2e119608090772bdeab3de77e7f8d1961124342410c1b08b

Observation bf70b4ad-b674-469e-90d9-120c6623cb43 · outbound

This paper cites https://csr.lanl.gov/data/.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://csr.lanl.gov/data/

Reference 5

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:08.108708Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.260461Z digest=sha256:ba15854f16b6dea428b3661e3a8346f6446b123a497b226a610ec9ff5ee97c2c

Observation c18ca003-851c-455c-b7b6-245d453c52ba · outbound

This paper cites https://community.broadcom.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://community.broadcom

Reference 6

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:08.099899Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.263494Z digest=sha256:4a1038c1cff87e113a005d7938f46eee8897bcee29f4d6e07e1cf7918cb156a8

Observation edfefce7-bbc0-41f7-81ce-81d83f22aa59 · outbound

This paper cites https://github.com/FiveDirections/OpTC- data.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://github.com/FiveDirections/OpTC- data

Reference 7

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:08.091575Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.266333Z digest=sha256:fc1710fd74e0d7ce7e4ac5a2bf442ecad33f2d8e2107b0ddc82fafff115aaf22

Observation 0d42a662-790e-449a-a1f5-dde928059aef · outbound

This paper cites https://github.com/ shramos/Awesome-Cybersecurity-Datasets.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://github.com/ shramos/Awesome-Cybersecurity-Datasets

Reference 8

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:08.082915Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.268832Z digest=sha256:d2aa08680485bfe00cec7fe4d86af6eff62a2b8ed11ecd7b63bd59f248f43d3c

Observation 94eef73f-62d1-4372-b87a-818ee1af2427 · outbound

This paper cites https://milvus.io/zh.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://milvus.io/zh

Reference 9

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:08.074186Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.271525Z digest=sha256:6f44b8e5f287c133e8f5c1c50b6d8898533a93e7e9b539a4170e6f0e1ad44972

Observation b9a97148-4748-42b6-b026-fafd046614d9 · outbound

This paper cites https: //sysdig.com/.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https: //sysdig.com/

Reference 10

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:08.065735Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.273938Z digest=sha256:8312c642b11f1eb663eab39d80e9c0c02cd3b2478c04671bc252bf948e9242dd

Observation fe329758-00c6-4915-9456-93931d68526b · outbound

This paper cites https:// attack.mitre.org/campaigns/C0024/.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https:// attack.mitre.org/campaigns/C0024/

Reference 11

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:08.056296Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.276398Z digest=sha256:5bca5e69562bb52414ae515e66a235a9cebf38335b121852e03eab5abe6b014b

Observation 5d2d4935-6f49-460b-b6a7-a2143726f9b5 · outbound

This paper cites https://cymulate.com/ cybersecurity-glossary/tactics-techniques- procedures/.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://cymulate.com/ cybersecurity-glossary/tactics-techniques- procedures/

Reference 12

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:08.047715Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.279295Z digest=sha256:cd0b03a531c377d2aa9de3bd2ad3aaec086d963a89a416129a5b6dc1b3e94115

Observation a70018ae-0d73-4506-8a3f-9eb10b361f66 · outbound

This paper cites https://www.crowdstrike.com/en-us/ platform/threat-intelligence/.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://www.crowdstrike.com/en-us/ platform/threat-intelligence/

Reference 13

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:08.038485Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.281728Z digest=sha256:c099b852111be8e254c228858c3a40cbb20f49726121db671de493db25bf90b1

Observation 6f80c721-3e2e-4785-89a9-218c2d7ed472 · outbound

This paper cites https://en.wikipedia.org/ wiki/WannaCry_ransomware_attack.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://en.wikipedia.org/ wiki/WannaCry_ransomware_attack

Reference 14

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:08.029504Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.284177Z digest=sha256:f2f9d48e5b68e0b39ca2d2823dfb6894a3bf3c29386f332bc36e0020bfaba3df

Observation 072cbf4c-c251-4748-bfc1-24377dedc1dd · outbound

This paper cites https://www.crowdstrike.com/en-us/ cybersecurity-101/threat-intelligence/.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://www.crowdstrike.com/en-us/ cybersecurity-101/threat-intelligence/

Reference 15

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:08.020902Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.286465Z digest=sha256:b4a6a0cab234f0cdeba6fc9f1ab0bbcf7f8f1a46ec3a21172a9f61d2fc77bc88

Observation ebaec913-5dca-4714-97d7-e05bc7799fd0 · outbound

This paper cites https://www.upguard.com/ blog/cyber-incident-reporting? [Accessed 11- 08-2025].

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://www.upguard.com/ blog/cyber-incident-reporting? [Accessed 11- 08-2025]

Reference 16

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:08.011261Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.288761Z digest=sha256:a9441313c200699e114d553e4ac3c05622109b34ef3012ae5d4afcce0a5448af

Observation a0e59622-8690-4d81-9c33-10e5c5e35844 · outbound

This paper cites https://www.lockheedmartin.com/en-us/ capabilities/cyber/cyber-kill-chain.html,.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://www.lockheedmartin.com/en-us/ capabilities/cyber/cyber-kill-chain.html,

Reference 17

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:08.001914Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.290975Z digest=sha256:58d9ec513244c51488dc533298a1a8032bece11ea9b433be798d4f989697f6d2

Observation 4eef9ece-68b5-4d16-968f-c49ceb4e2fa5 · outbound

This paper cites Berkay Celik, Xiangyu Zhang, and Dongyan Xu.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Berkay Celik, Xiangyu Zhang, and Dongyan Xu

Reference 18

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.984303Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.295873Z digest=sha256:5bfa9447a7a6468cce6cfaa36ce1e38610fcd8378e796c3cc7555e79337f1e98

Observation 15e8771b-a75f-424a-bd73-0fbf46cf3a77 · outbound

This paper cites ANY.RUN - Interactive Online Malware Sand- box — any.run.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models ANY.RUN - Interactive Online Malware Sand- box — any.run

Reference 19

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.974529Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.298178Z digest=sha256:2770dafe612c386eaadc6ea2c408a1ed3f3852f4f3374d738e46131f057fcc22

Observation 1eb6d527-c512-4407-81a2-a25eb9d8acc2 · outbound

This paper cites Kairos: Practical intrusion detection and investigation using whole-system provenance.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Kairos: Practical intrusion detection and investigation using whole-system provenance

Reference 20

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.965833Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.300891Z digest=sha256:adf5df3e9b732579b946bf95b74d2582069c174540cc0b48524df45d6cf36e93

Observation 914fa0a4-d1e7-420e-9760-5a68487056ea · outbound

This paper cites How to Use Threat Hunt- ing to Identify and Neutralize Advanced Per- sistent Threats — cloudoptics.ai.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models How to Use Threat Hunt- ing to Identify and Neutralize Advanced Per- sistent Threats — cloudoptics.ai

Reference 21

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.957524Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.303238Z digest=sha256:510226aa6f46bd59adb6a322d9c3c977e171cac77b777a2ff3c80331b5457b37

Observation 853a901b-59a3-45da-a222-b6a44c3c9274 · outbound

This paper cites Cybersecurity study: SolarWinds attack cost affected companies an average of $12 million — techrepublic.com.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Cybersecurity study: SolarWinds attack cost affected companies an average of $12 million — techrepublic.com

Reference 22

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.948944Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.305677Z digest=sha256:c08235f9948477ba3943fe811aaefbb788a68083b2343e0315b8ae5bd22e5de5

Observation 44997b87-e6ac-47db-a9e1-a1cafb6f130b · outbound

This paper cites AIRTAG: Towards automated attack investigation by unsupervised learning with log texts.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models AIRTAG: Towards automated attack investigation by unsupervised learning with log texts

Reference 23

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.940323Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.308074Z digest=sha256:9f6ced5df2848e2c1b9fbbd67d4d0e1e8fa6618d84c7d2936f0efd5d601c7af2

Observation e669144a-4663-4c7d-b7c1-4da23f8a3ebc · outbound

This paper cites Event Tracing for Windows (ETW) - Windows drivers — learn.microsoft.com.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Event Tracing for Windows (ETW) - Windows drivers — learn.microsoft.com

Reference 24

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.931873Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.310209Z digest=sha256:77b9b59defbdb49d295b1fabeec67aae5552ac553026b203e719b68961f888ba

Observation b888b42f-b692-40e9-991b-977c1bc7f682 · outbound

This paper cites {DISTDET}: A {Cost-Effective} distributed cyber threat detection system.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models {DISTDET}: A {Cost-Effective} distributed cyber threat detection system

Reference 25

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.924235Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.312449Z digest=sha256:ffc37e432d53b1634cadf316c3d0bf9511f361fe96d4b05573bc571a589a7469

Observation 85f6de31-c33f-4267-953a-b768ae811580 · outbound

This paper cites Deeplog: Anomaly detection and diagnosis from system logs through deep learning.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Deeplog: Anomaly detection and diagnosis from system logs through deep learning

Reference 26

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.916822Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.314837Z digest=sha256:639db40623d2ada5f4dcd1038856df61167ce70843a08cebc44271cd2ef28056

Observation 6284939f-372b-443f-8bad-82d90ffd64b9 · outbound

This paper cites {Back-Propagating} system dependency impact for attack investigation.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models {Back-Propagating} system dependency impact for attack investigation

Reference 27

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.909254Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.317490Z digest=sha256:89dceb658fd00576459bef8b5f5eb32695b7e1fa1f30bc65fd676aed588b6839

Observation 83b1ab74-8b76-4e2a-8aac-c9e5caacb720 · outbound

This paper cites DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-05T12:48:07.319845Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T12:48:07.319845Z digest=sha256:02699e76294695afb7f981bc3894eec75236a76e1b888f3f5275b0fce59a6b72

Observation 8601ab0e-4514-46d9-a344-f5b8501e39d3 · outbound

This paper cites UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats

Reference 29

Resolution
unresolved
no resolver link, observed 2026-08-05T12:48:07.322575Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T12:48:07.322575Z digest=sha256:1f988711c9053101f66acd4bbcb859a396087fe10358e9dbb30aad01abeed2e7

Observation 940a3319-46d5-411d-bf7e-9671b536ff43 · outbound

This paper cites Tac- tical provenance analysis for endpoint detection and response systems.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Tac- tical provenance analysis for endpoint detection and response systems

Reference 30

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.901784Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.325276Z digest=sha256:bc9cd7b071c9755a6b5b6d49c1283fa1deb623242b4ec50f2c5b8010e3484f01

Observation 4908d3b7-cb86-4426-8ebf-ef6b36f57a51 · outbound

This paper cites Nodoze: Combatting threat alert fatigue with automated provenance triage.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Nodoze: Combatting threat alert fatigue with automated provenance triage

Reference 31

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.894153Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.327622Z digest=sha256:2fdfde3fac805ef722baca509a9fa332f8162c6d5eae48299720af7344abb2d1

Observation 44551808-0009-4be7-b618-0e73245d5afa · outbound

This paper cites In 26th USENIX Security Symposium (USENIX Security 17), pages 487–504, 2017.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models In 26th USENIX Security Symposium (USENIX Security 17), pages 487–504, 2017

Reference 32

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.886602Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.329826Z digest=sha256:37eff05e4ca241ec2284e58f4f189480c522800281be587c285ea092aba12ceb

Observation 6ba5029e-8021-460b-be67-307e28a55722 · outbound

This paper cites Sellafield apologises after guilty plea over string of cybersecurity failings — theguardian.com.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Sellafield apologises after guilty plea over string of cybersecurity failings — theguardian.com

Reference 33

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.878339Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.332169Z digest=sha256:72b52bba6217f844c99946c9334d331abfbc36816410bcf001ed956d67942deb

Observation 185d40a6-1f97-484b-b50b-02851f933121 · outbound

This paper cites Rain: Refinable attack investigation with on- demand inter-process information flow tracking.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Rain: Refinable attack investigation with on- demand inter-process information flow tracking

Reference 34

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.869694Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.334415Z digest=sha256:3cb18151194a214304e3ac55b1c55154032c6eec581e87131b8adaf05f6cd697

Observation 74593940-df9f-43cd-9eae-983c0c2d7f32 · outbound

This paper cites {MAGIC}: Detecting advanced per- sistent threats via masked graph representation learning.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models {MAGIC}: Detecting advanced per- sistent threats via masked graph representation learning

Reference 35

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.861894Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.336881Z digest=sha256:14d0f6f1295eb0bd965ef5cadc6277d9c5b47620d38160c76713948bb8275524

Observation 8fcf7285-79b2-4a5b-abb9-302727fc05e0 · outbound

This paper cites Orthrus: Achieving high quality of attribution in provenance-based intrusion de- tection systems.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Orthrus: Achieving high quality of attribution in provenance-based intrusion de- tection systems

Reference 36

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.854057Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.339198Z digest=sha256:0087f1c8d91cc30cc8abce487c43f5191f94abcdf579ac8c22ca4da1f6a3e382

Observation ebd3f98c-83c6-4785-9541-a5f32aea58fd · outbound

This paper cites Temporal decay loss for adaptive log anomaly detection in cloud environments.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Temporal decay loss for adaptive log anomaly detection in cloud environments

Reference 37

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.846345Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.341508Z digest=sha256:0bcf496701b9bec9e4cb6d7d753c673748095fc9578416a27a56caa89c203bc1

Observation 11aad21a-b419-478e-83a6-c1cdc6d25f66 · outbound

This paper cites Prov-gem: Au- tomated provenance analysis framework using graph embeddings.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Prov-gem: Au- tomated provenance analysis framework using graph embeddings

Reference 38

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.838344Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.343899Z digest=sha256:0b579e285f117a54e7fd16ad20e8e75a547dfec1653968377d1a7350df559d30

Observation 377460e7-a61c-4408-b004-d4459d32ff21 · outbound

This paper cites Measuring catastrophic forgetting in neural networks.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Measuring catastrophic forgetting in neural networks

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-05T12:48:07.346137Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T12:48:07.346137Z digest=sha256:f426048d56ff633c27aec6221fae88a5c6f65f92167e1a540ead150bea84e180

Observation 3405be81-eaa8-4802-9e60-acd6eb5420a9 · outbound

This paper cites High accuracy attack provenance via binary-based exe- cution partition.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models High accuracy attack provenance via binary-based exe- cution partition

Reference 40

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.825920Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.348923Z digest=sha256:19e06e590b0e93871e960ae7a4430b91489bc02a7a121ca614838278bdf9a976

Observation 67e3009d-f64a-4089-acc9-a9c8c13c4491 · outbound

This paper cites LevelBlue Labs Open Threat Exchange — levelblue.com.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models LevelBlue Labs Open Threat Exchange — levelblue.com

Reference 41

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.818146Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.351277Z digest=sha256:10608ec811ed629de6ad5593761b2c38aaee2f407d2ec0ad176929171332466b

Observation 6efee85d-0cbf-4456-858e-eeb02c1ccf10 · outbound

This paper cites Retrieval-augmented generation for knowledge- intensive nlp tasks.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Retrieval-augmented generation for knowledge- intensive nlp tasks

Reference 42

Resolution
unresolved
no resolver link, observed 2026-08-05T12:48:07.353626Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T12:48:07.353626Z digest=sha256:b9dd70c51ec768912f94a91241757488e57d7a9cf40727ed3a5f4f462010a6b5

Observation 231becc9-b191-4442-9b27-a5d36a799e1e · outbound

This paper cites A hierarchical approach for advanced persis- tent threat detection with attention-based graph neu- ral networks.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models A hierarchical approach for advanced persis- tent threat detection with attention-based graph neu- ral networks

Reference 43

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.805522Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.355982Z digest=sha256:0a1b72b30392f90c1f914d4b2e69c8e81cff71648985605f162a48379b9c678e

Observation e442ad01-c6b9-41d4-a5e7-17b44508d8d2 · outbound

This paper cites Log2vec: A heteroge- neous graph embedding based approach for detecting cyber threats within enterprise.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Log2vec: A heteroge- neous graph embedding based approach for detecting cyber threats within enterprise

Reference 44

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.797692Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.358233Z digest=sha256:267af666cfc0f8d2e21758d2f7aace118eb48a9c9b935e0a3e80ed87b5d48ec2

Observation 8d871bd8-247a-4a75-a61c-82bfcb225c13 · outbound

This paper cites APT28 Cyber Espionage Campaign Targets Logistics and Tech Compa- nies, CISA Warns — reveal.security.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models APT28 Cyber Espionage Campaign Targets Logistics and Tech Compa- nies, CISA Warns — reveal.security

Reference 45

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.789833Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.360560Z digest=sha256:c2acd2d386a6a52b6d091804c4eb2312eab8c897d7df33bb028a0bfebde96a8d

Observation 6f42ffc6-917e-4372-b41c-8ea60ce04eca · outbound

This paper cites Pro- tracer: Towards practical provenance tracing by alter- nating between logging and tainting.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Pro- tracer: Towards practical provenance tracing by alter- nating between logging and tainting

Reference 46

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.781920Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.362841Z digest=sha256:b42641a49b86d09aa2e4d139e47f6ffb541fc1dbf0a2eb55e8bd2b3a50f8a1bb

Observation fd4527df-aad0-4547-931e-e308a6dea680 · outbound

This paper cites Sysmon - Sysinternals — learn.microsoft.com.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Sysmon - Sysinternals — learn.microsoft.com

Reference 47

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.774436Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.365066Z digest=sha256:551d8898c683599a9694e76d2abe25ff5a17b1a34fe4c185d21f28994a8e2def

Observation 279c288e-d136-426a-92d6-a7de29592c4d · outbound

This paper cites Poirot: Aligning attack be- havior with kernel audit records for cyber threat hunting.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Poirot: Aligning attack be- havior with kernel audit records for cyber threat hunting

Reference 49

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.766547Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.369806Z digest=sha256:69952e3aa0661c7c607b1243b324ec1afc3d1c3468c05cbc1c2d187b8c847bf6

Observation 0dd9298b-2955-4b4b-a81d-909b38f66427 · outbound

This paper cites Holmes: real-time apt detection through correlation of suspicious information flows.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Holmes: real-time apt detection through correlation of suspicious information flows

Reference 50

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.758683Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.372347Z digest=sha256:14fc8f4bbfb9a6691fb53d95e2224f362746321e5d0fd210e16a5ac3564bfde4

Observation a8f0fffc-094d-429e-acb0-f37e8e9f6b73 · outbound

This paper cites Mitre att&ck, 2020.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Mitre att&ck, 2020

Reference 51

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.751027Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.375043Z digest=sha256:73e86bea303ec5d41f475f28489804127642570f0884a1d7dabb4329e1de2b93

Observation 3712e7f3-bb65-4faa-8da5-82be9d03861f · outbound

This paper cites Custos: Practical tamper-evident auditing of operating systems using trusted execution.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Custos: Practical tamper-evident auditing of operating systems using trusted execution

Reference 52

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.743217Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.377676Z digest=sha256:58aae64c6cd17061a84f4a68c7c2c90eb6a64e02c72b7a23100b2adea1c47eda

Observation 4934948f-1f05-48e7-84d7-f63155e134ef · outbound

This paper cites Logging to the danger zone: Race condition attacks and defenses on system audit frameworks.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Logging to the danger zone: Race condition attacks and defenses on system audit frameworks

Reference 53

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.734923Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.380549Z digest=sha256:3ee7fac8505922dcd6d84e15b5788c0994301ba0a9bd016a864370b4d66344f0

Observation a85c0ba7-2f2d-4d29-a7d8-9979881c246e · outbound

This paper cites Hercule: Attack story re- construction via community discovery on correlated log graph.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Hercule: Attack story re- construction via community discovery on correlated log graph

Reference 54

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.725726Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.382917Z digest=sha256:98484d879af6a218704d399178242493a6f105e96e0fa7f5b8bf3a8e7818d74b

Observation 64bd88ab-a129-431c-96a9-a27234b10e16 · outbound

This paper cites No-doubt: Attack attribution based on threat intelligence reports.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models No-doubt: Attack attribution based on threat intelligence reports

Reference 55

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.718021Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.385642Z digest=sha256:fc1924ba620f0337eff913606796fdb96910113f2849f0012fd24b6f3544c6ee

Observation 7feceb49-1ae2-4f45-9cfb-6c507b9ec103 · outbound

This paper cites {ATTACK2VEC}: Leveraging temporal word embeddings to understand the evolution of cyberattacks.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models {ATTACK2VEC}: Leveraging temporal word embeddings to understand the evolution of cyberattacks

Reference 56

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.709927Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.388152Z digest=sha256:6becfb8d022a806c4aaad663c6bd7099930235e315010fcec63d4dfa699d90fe

Observation 2d2eb9ac-2c2b-49a1-8b52-dba7c3edfb38 · outbound

This paper cites APT and financial attacks on industrial organizations in Q4 2024 | Kaspersky ICS CERT — ics-cert.kaspersky.com.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models APT and financial attacks on industrial organizations in Q4 2024 | Kaspersky ICS CERT — ics-cert.kaspersky.com

Reference 57

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.701410Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.390414Z digest=sha256:7cf879bf6f718e3d7879d1f4055e5a6e93b9e8d9968d15b94a3f72c70fc37d80

Observation 879316ac-d833-4932-813e-e9aef8cc8ab3 · outbound

This paper cites Survey on Factuality in Large Language Models: Knowledge, Retrieval and Domain-Specificity.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Survey on Factuality in Large Language Models: Knowledge, Retrieval and Domain-Specificity

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-05T12:48:07.392732Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T12:48:07.392732Z digest=sha256:f438a8e2f1b468e321008f3bd05cb6ac899f773fc0eaa1b030dd5bb99473803a

Observation 0c5dfbd1-1f29-4326-8193-5c1fbf893a64 · outbound

This paper cites Threatrace: Detecting and tracing host-based threats in node level through provenance graph learn- ing.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Threatrace: Detecting and tracing host-based threats in node level through provenance graph learn- ing

Reference 59

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.692043Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.395655Z digest=sha256:76a9c7fd3610244999fc692b737581d620753380fa0562b6d910a7c89a04384d

Observation dfb394dc-7140-4c49-a405-dc11cf2d0382 · outbound

This paper cites Chain-of-thought prompting elicits reasoning in large language models.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Chain-of-thought prompting elicits reasoning in large language models

Reference 60

Resolution
unresolved
no resolver link, observed 2026-08-05T12:48:07.398055Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T12:48:07.398055Z digest=sha256:cd4d5a468c54edc1c410f7d811ae9ba3d8b190761b77d8a058ca013672eaa023

Observation 0080c2c1-7b22-48a5-a399-f2fca9acf62c · outbound

This paper cites On the ef- fectiveness of log representation for log-based anomaly detection.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models On the ef- fectiveness of log representation for log-based anomaly detection

Reference 61

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.677733Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.400495Z digest=sha256:a41e3d363c4920dae7585bd4d632e2ad8296550ff37c380a7aec9314cc9acf4c

Observation c410fdea-c40f-46c4-88e3-0cc947031a2c · outbound

This paper cites Depcomm: Graph sum- marization on system audit logs for attack investigation.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Depcomm: Graph sum- marization on system audit logs for attack investigation

Reference 62

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.669098Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.402836Z digest=sha256:1a5458d5d8b053042239d80fa5b2b73545988e5aa55e92dd5098cb67a9b823c0

Observation e04404d3-a97b-4662-9d97-8b4366b5a1f2 · outbound

This paper cites {PROGRAPHER}: An anomaly detection system based on provenance graph embedding.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models {PROGRAPHER}: An anomaly detection system based on provenance graph embedding

Reference 63

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.661294Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.405213Z digest=sha256:4263145fe86a21caa18f48293cee23ed0d36622769d589068a8b2552b5eb1470

Observation c4e561c6-1196-4bbe-a167-33a5cdf3f7a6 · outbound

This paper cites Shadewatcher: Recommendation-guided cyber threat analysis using system audit records.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Shadewatcher: Recommendation-guided cyber threat analysis using system audit records

Reference 64

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.653064Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.407700Z digest=sha256:051a3d79ecb98553d56b6d216b62f0412edd27797b176a533486c6b709210129

Observation 9e7944e7-65e5-4d65-894f-07d4d016cb6c · outbound

This paper cites A Survey of Large Language Models.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models A Survey of Large Language Models

Reference 65

Resolution
unresolved
no resolver link, observed 2026-08-05T12:48:07.410186Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T12:48:07.410186Z digest=sha256:93df1af3f4ea8e10745ad89ddca48dec974af4e5b762b2f155f81e4c4f67db4b

Observation c20d7be6-0d52-471e-aa1e-004deba1e0cd · outbound

This paper cites Attack pattern discovery in forensic inves- tigation of network attacks.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Attack pattern discovery in forensic inves- tigation of network attacks

Reference 66

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.645136Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.412846Z digest=sha256:855cce98230181a2fddb17edf675b0cdc8fbbaaa0d59dd5cf8a10fcfba40d942

Observation d2be9051-687b-4a51-8837-61c68c681660 · outbound

This paper cites an unresolved cited work.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work

Reference 68

Resolution
unresolved
raw_fallback, observed 2026-08-05T12:48:07.637039Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.415250Z digest=sha256:3bcd1d13c0c69b798a44aaf1439ef3a1c7fb08f82e5a4994a836c2637e6c5f53

Observation fd4b94c7-3eda-44ca-8503-e69145080066 · outbound

This paper cites an unresolved cited work.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work

Reference 69

Resolution
unresolved
raw_fallback, observed 2026-08-05T12:48:07.628742Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.417726Z digest=sha256:6748e4ba6b8d65183343513087c7ea32c63df9f853764b773b5ea2a81408c800

Observation eb2c672f-5494-4979-b07a-16728645668b · outbound

This paper cites an unresolved cited work.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work

Reference 70

Resolution
unresolved
raw_fallback, observed 2026-08-05T12:48:07.620451Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.420363Z digest=sha256:02ab99b7a030f82ae4d5598ab2a0ece20e7a4897cf0ed44d923ed705b02df12b

Observation 1edb5423-01da-425b-8c05-757af8f3d33c · outbound

This paper cites an unresolved cited work.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work

Reference 71

Resolution
unresolved
raw_fallback, observed 2026-08-05T12:48:07.611827Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.422877Z digest=sha256:41266c54e57e3c1bc0513aaeceec025a9cca8284de103f25edda48d0627e5a34

Observation 0c48c3c6-1469-4c7c-a5e5-3d747905e3ba · outbound

This paper cites Strictly preserve the original temporal order.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Strictly preserve the original temporal order

Reference 72

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.602086Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.425477Z digest=sha256:b8668e2f90c20c3877d9e30467ddd464c48ecd879c2034a1d439000fc2f05db2

Observation 8e3a427b-ba20-4319-9e69-ab4a29588e46 · outbound

This paper cites an unresolved cited work.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work

Reference 73

Resolution
unresolved
raw_fallback, observed 2026-08-05T12:48:07.593664Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.428708Z digest=sha256:626885562945af4951091db46d85333f5768fe4eeef364f4894ecbc3c9724130

Observation 43ca30f1-6b56-4452-a1d8-b0ca31476ac2 · outbound

This paper cites an unresolved cited work.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work

Reference 74

Resolution
unresolved
raw_fallback, observed 2026-08-05T12:48:07.585798Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.431482Z digest=sha256:ca95f936c14ce82b47f5f1a42454f7ebc51f598b91594150023aa4e56e8b9e22

Observation 57acd3f4-166c-426a-9a2e-9bf0dba643fc · outbound

This paper cites 18 5.evidence_set must fully retain the original log en- tries.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models 18 5.evidence_set must fully retain the original log en- tries

Reference 75

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.575947Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.433911Z digest=sha256:17545ed246d50e2be17b73f7bde446d52ee2095be973363df1065ed2517a2ed4

Observation 961782f0-c9fe-47f2-9550-2925ea34090a · outbound

This paper cites an unresolved cited work.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work

Reference 76

Resolution
unresolved
raw_fallback, observed 2026-08-05T12:48:07.567072Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.436675Z digest=sha256:bff784b10ca8c440cb9ca726ad9c8ede9ee853fbe7f4830d65d32f03f5ec9146

Observation 91595eaa-7e8e-4224-9e43-d953224e29a9 · outbound

This paper cites A.2 Prompt for Causal Reasoning Prompt for Causal Reasoning You are a cyber forensic analyst investigating poten- tial attacks in preprocessed system logs.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models A.2 Prompt for Causal Reasoning Prompt for Causal Reasoning You are a cyber forensic analyst investigating poten- tial attacks in preprocessed system logs

Reference 77

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.557883Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.439212Z digest=sha256:f11f4afa6b163f9db3cf407d1f3c4eb7a8f405acaed5e7439870376fb527a497

Observation 6c32db01-e95f-4a92-8421-9ce618ab31da · outbound

This paper cites an unresolved cited work.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work

Reference 78

Resolution
unresolved
raw_fallback, observed 2026-08-05T12:48:07.548215Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.441644Z digest=sha256:f7d5dcd54cf7fa8505eeda2f7fc430b6af300c218003d9eab512b4882f647959

Observation 4a0c8a3e-4017-407e-814e-62db82fe7849 · outbound

This paper cites 3.Infer causality between the current and previous window based on behavioral continuity.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models 3.Infer causality between the current and previous window based on behavioral continuity

Reference 79

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.539658Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.444055Z digest=sha256:cd7cf0724ffef73b94fd8b333924fdfc623782cdc5dfcb09a992854ec9703cf9

Observation 64164020-2bc0-41ed-beb8-3e8639827c05 · outbound

This paper cites 3.Summarize abnormal behaviors and their causal relationships, highlighting how each suspicious entity contributed to the attack progression.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models 3.Summarize abnormal behaviors and their causal relationships, highlighting how each suspicious entity contributed to the attack progression

Reference 80

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.530539Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.446662Z digest=sha256:af40c68a49dc063f4da023ae0f7c6a6eeabe9f1dae7dcea8952a1d7340d95f6a

Observation beefd86a-2d65-4180-9f36-58f7dba7708f · outbound

This paper cites an unresolved cited work.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work

Reference 81

Resolution
unresolved
raw_fallback, observed 2026-08-05T12:48:07.521374Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.449218Z digest=sha256:82db4f5924c46c2e85ebffe5cc47a7c7cfe84fb9c736ad0b02d1737583e25070

Observation 6129fb3d-b32a-42b0-a477-8648a89fab98 · outbound

This paper cites The final report should provide clear forensic evidence for each phase and conclude with a concise explanation of the overall attack chain and its implications for defense.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models The final report should provide clear forensic evidence for each phase and conclude with a concise explanation of the overall attack chain and its implications for defense

Reference 82

Resolution
verified fuzzy
raw_fallback, observed 2026-08-05T12:48:07.512742Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.451736Z digest=sha256:f140c02d23b69fcc1ed7afd436a13c1fdadbecb24c98b952227e7f69a394e9a9

Observation 647f18cd-4095-4cdc-b84d-0f7fc248a68c · outbound

This paper cites an unresolved cited work.

An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work

Reference 2025

Resolution
unresolved
raw_fallback, observed 2026-08-05T12:48:07.993286Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.

source=pdf_text observed=2026-08-05T12:48:07.293447Z digest=sha256:833674d4204cc5af999303afcc6088374a69d7be8e4b68cea7efbc7eff73c728

Pith citing papers

No inbound Pith citation observations are available.