Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-05T12:48:07.451736Z
Paper Citation Record · LEDGER
As of 23 August 2026, this Paper Citation Record lists 81 of 81 outbound references and 0 inbound Pith citation observations for arXiv:2509.01271.
A citation records a reference. It does not transfer a finding from one paper to another.
Typed states for the displayed outbound observations.
Source: paper_references, paper_reference_links, observed 2026-08-05T12:48:07.451736Z
One-hop event checks from named stored sources.
Source: scholarly_work_events, retraction_status_cache, observed 2026-08-23T06:30:58.430688+00:00
Pith citing papers itemized under the disclosed page cap.
Source: paper_references, paper_reference_links
A source-named dated measurement, never combined with another source.
Source: cited_works
81 of 81 outbound references displayed
External citation measurements
No source-named external measurement is stored.
Observation d39dfd20-1f05-4bed-b6b9-ed95906ddfba · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://www.cisa.gov/news-events/ alerts/2020/12/13/active-exploitation- solarwinds-software
Reference 1
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 566a70af-17ad-475d-b846-4eae231ec2d6 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://anonymous.4open.science/r/Themis- LLM-B4EC
Reference 2
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation d8421e1a-7f89-4a23-8161-f9d845800ae5 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://docs.redhat.com/en/ documentation/red_hat_enterprise_linux/6/ html/security_guide/chap-system_auditing
Reference 3
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation f23285af-18a0-4873-9db4-14a40459aa51 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://www
Reference 4
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation bf70b4ad-b674-469e-90d9-120c6623cb43 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://csr.lanl.gov/data/
Reference 5
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation c18ca003-851c-455c-b7b6-245d453c52ba · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://community.broadcom
Reference 6
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation edfefce7-bbc0-41f7-81ce-81d83f22aa59 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://github.com/FiveDirections/OpTC- data
Reference 7
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 0d42a662-790e-449a-a1f5-dde928059aef · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://github.com/ shramos/Awesome-Cybersecurity-Datasets
Reference 8
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 94eef73f-62d1-4372-b87a-818ee1af2427 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://milvus.io/zh
Reference 9
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation b9a97148-4748-42b6-b026-fafd046614d9 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https: //sysdig.com/
Reference 10
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation fe329758-00c6-4915-9456-93931d68526b · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https:// attack.mitre.org/campaigns/C0024/
Reference 11
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 5d2d4935-6f49-460b-b6a7-a2143726f9b5 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://cymulate.com/ cybersecurity-glossary/tactics-techniques- procedures/
Reference 12
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation a70018ae-0d73-4506-8a3f-9eb10b361f66 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://www.crowdstrike.com/en-us/ platform/threat-intelligence/
Reference 13
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 6f80c721-3e2e-4785-89a9-218c2d7ed472 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://en.wikipedia.org/ wiki/WannaCry_ransomware_attack
Reference 14
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 072cbf4c-c251-4748-bfc1-24377dedc1dd · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://www.crowdstrike.com/en-us/ cybersecurity-101/threat-intelligence/
Reference 15
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation ebaec913-5dca-4714-97d7-e05bc7799fd0 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://www.upguard.com/ blog/cyber-incident-reporting? [Accessed 11- 08-2025]
Reference 16
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation a0e59622-8690-4d81-9c33-10e5c5e35844 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models https://www.lockheedmartin.com/en-us/ capabilities/cyber/cyber-kill-chain.html,
Reference 17
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 4eef9ece-68b5-4d16-968f-c49ceb4e2fa5 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Berkay Celik, Xiangyu Zhang, and Dongyan Xu
Reference 18
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 15e8771b-a75f-424a-bd73-0fbf46cf3a77 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models ANY.RUN - Interactive Online Malware Sand- box — any.run
Reference 19
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 1eb6d527-c512-4407-81a2-a25eb9d8acc2 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Kairos: Practical intrusion detection and investigation using whole-system provenance
Reference 20
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 914fa0a4-d1e7-420e-9760-5a68487056ea · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models How to Use Threat Hunt- ing to Identify and Neutralize Advanced Per- sistent Threats — cloudoptics.ai
Reference 21
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 853a901b-59a3-45da-a222-b6a44c3c9274 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Cybersecurity study: SolarWinds attack cost affected companies an average of $12 million — techrepublic.com
Reference 22
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 44997b87-e6ac-47db-a9e1-a1cafb6f130b · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models AIRTAG: Towards automated attack investigation by unsupervised learning with log texts
Reference 23
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation e669144a-4663-4c7d-b7c1-4da23f8a3ebc · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Event Tracing for Windows (ETW) - Windows drivers — learn.microsoft.com
Reference 24
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation b888b42f-b692-40e9-991b-977c1bc7f682 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models {DISTDET}: A {Cost-Effective} distributed cyber threat detection system
Reference 25
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 85f6de31-c33f-4267-953a-b768ae811580 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Deeplog: Anomaly detection and diagnosis from system logs through deep learning
Reference 26
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 6284939f-372b-443f-8bad-82d90ffd64b9 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models {Back-Propagating} system dependency impact for attack investigation
Reference 27
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 83b1ab74-8b76-4e2a-8aac-c9e5caacb720 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning
Reference 28
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 8601ab0e-4514-46d9-a344-f5b8501e39d3 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models UNICORN: Runtime Provenance-Based Detector for Advanced Persistent Threats
Reference 29
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 940a3319-46d5-411d-bf7e-9671b536ff43 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Tac- tical provenance analysis for endpoint detection and response systems
Reference 30
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 4908d3b7-cb86-4426-8ebf-ef6b36f57a51 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Nodoze: Combatting threat alert fatigue with automated provenance triage
Reference 31
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 44551808-0009-4be7-b618-0e73245d5afa · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models In 26th USENIX Security Symposium (USENIX Security 17), pages 487–504, 2017
Reference 32
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 6ba5029e-8021-460b-be67-307e28a55722 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Sellafield apologises after guilty plea over string of cybersecurity failings — theguardian.com
Reference 33
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 185d40a6-1f97-484b-b50b-02851f933121 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Rain: Refinable attack investigation with on- demand inter-process information flow tracking
Reference 34
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 74593940-df9f-43cd-9eae-983c0c2d7f32 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models {MAGIC}: Detecting advanced per- sistent threats via masked graph representation learning
Reference 35
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 8fcf7285-79b2-4a5b-abb9-302727fc05e0 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Orthrus: Achieving high quality of attribution in provenance-based intrusion de- tection systems
Reference 36
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation ebd3f98c-83c6-4785-9541-a5f32aea58fd · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Temporal decay loss for adaptive log anomaly detection in cloud environments
Reference 37
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 11aad21a-b419-478e-83a6-c1cdc6d25f66 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Prov-gem: Au- tomated provenance analysis framework using graph embeddings
Reference 38
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 377460e7-a61c-4408-b004-d4459d32ff21 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Measuring catastrophic forgetting in neural networks
Reference 39
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 3405be81-eaa8-4802-9e60-acd6eb5420a9 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models High accuracy attack provenance via binary-based exe- cution partition
Reference 40
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 67e3009d-f64a-4089-acc9-a9c8c13c4491 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models LevelBlue Labs Open Threat Exchange — levelblue.com
Reference 41
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 6efee85d-0cbf-4456-858e-eeb02c1ccf10 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Retrieval-augmented generation for knowledge- intensive nlp tasks
Reference 42
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 231becc9-b191-4442-9b27-a5d36a799e1e · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models A hierarchical approach for advanced persis- tent threat detection with attention-based graph neu- ral networks
Reference 43
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation e442ad01-c6b9-41d4-a5e7-17b44508d8d2 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Log2vec: A heteroge- neous graph embedding based approach for detecting cyber threats within enterprise
Reference 44
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 8d871bd8-247a-4a75-a61c-82bfcb225c13 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models APT28 Cyber Espionage Campaign Targets Logistics and Tech Compa- nies, CISA Warns — reveal.security
Reference 45
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 6f42ffc6-917e-4372-b41c-8ea60ce04eca · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Pro- tracer: Towards practical provenance tracing by alter- nating between logging and tainting
Reference 46
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation fd4527df-aad0-4547-931e-e308a6dea680 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Sysmon - Sysinternals — learn.microsoft.com
Reference 47
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 279c288e-d136-426a-92d6-a7de29592c4d · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Poirot: Aligning attack be- havior with kernel audit records for cyber threat hunting
Reference 49
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 0dd9298b-2955-4b4b-a81d-909b38f66427 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Holmes: real-time apt detection through correlation of suspicious information flows
Reference 50
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation a8f0fffc-094d-429e-acb0-f37e8e9f6b73 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Mitre att&ck, 2020
Reference 51
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 3712e7f3-bb65-4faa-8da5-82be9d03861f · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Custos: Practical tamper-evident auditing of operating systems using trusted execution
Reference 52
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 4934948f-1f05-48e7-84d7-f63155e134ef · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Logging to the danger zone: Race condition attacks and defenses on system audit frameworks
Reference 53
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation a85c0ba7-2f2d-4d29-a7d8-9979881c246e · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Hercule: Attack story re- construction via community discovery on correlated log graph
Reference 54
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 64bd88ab-a129-431c-96a9-a27234b10e16 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models No-doubt: Attack attribution based on threat intelligence reports
Reference 55
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 7feceb49-1ae2-4f45-9cfb-6c507b9ec103 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models {ATTACK2VEC}: Leveraging temporal word embeddings to understand the evolution of cyberattacks
Reference 56
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 2d2eb9ac-2c2b-49a1-8b52-dba7c3edfb38 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models APT and financial attacks on industrial organizations in Q4 2024 | Kaspersky ICS CERT — ics-cert.kaspersky.com
Reference 57
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 879316ac-d833-4932-813e-e9aef8cc8ab3 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Survey on Factuality in Large Language Models: Knowledge, Retrieval and Domain-Specificity
Reference 58
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0c5dfbd1-1f29-4326-8193-5c1fbf893a64 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Threatrace: Detecting and tracing host-based threats in node level through provenance graph learn- ing
Reference 59
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation dfb394dc-7140-4c49-a405-dc11cf2d0382 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Chain-of-thought prompting elicits reasoning in large language models
Reference 60
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation 0080c2c1-7b22-48a5-a399-f2fca9acf62c · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models On the ef- fectiveness of log representation for log-based anomaly detection
Reference 61
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation c410fdea-c40f-46c4-88e3-0cc947031a2c · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Depcomm: Graph sum- marization on system audit logs for attack investigation
Reference 62
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation e04404d3-a97b-4662-9d97-8b4366b5a1f2 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models {PROGRAPHER}: An anomaly detection system based on provenance graph embedding
Reference 63
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation c4e561c6-1196-4bbe-a167-33a5cdf3f7a6 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Shadewatcher: Recommendation-guided cyber threat analysis using system audit records
Reference 64
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 9e7944e7-65e5-4d65-894f-07d4d016cb6c · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models A Survey of Large Language Models
Reference 65
Source-reported events for the cited work
Unavailable: canonical work link unavailable.
Observation c20d7be6-0d52-471e-aa1e-004deba1e0cd · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Attack pattern discovery in forensic inves- tigation of network attacks
Reference 66
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation d2be9051-687b-4a51-8837-61c68c681660 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work
Reference 68
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation fd4b94c7-3eda-44ca-8503-e69145080066 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work
Reference 69
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation eb2c672f-5494-4979-b07a-16728645668b · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work
Reference 70
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 1edb5423-01da-425b-8c05-757af8f3d33c · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work
Reference 71
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 0c48c3c6-1469-4c7c-a5e5-3d747905e3ba · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Strictly preserve the original temporal order
Reference 72
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 8e3a427b-ba20-4319-9e69-ab4a29588e46 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work
Reference 73
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 43ca30f1-6b56-4452-a1d8-b0ca31476ac2 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work
Reference 74
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 57acd3f4-166c-426a-9a2e-9bf0dba643fc · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models 18 5.evidence_set must fully retain the original log en- tries
Reference 75
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 961782f0-c9fe-47f2-9550-2925ea34090a · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work
Reference 76
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 91595eaa-7e8e-4224-9e43-d953224e29a9 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models A.2 Prompt for Causal Reasoning Prompt for Causal Reasoning You are a cyber forensic analyst investigating poten- tial attacks in preprocessed system logs
Reference 77
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 6c32db01-e95f-4a92-8421-9ce618ab31da · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work
Reference 78
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 4a0c8a3e-4017-407e-814e-62db82fe7849 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models 3.Infer causality between the current and previous window based on behavioral continuity
Reference 79
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 64164020-2bc0-41ed-beb8-3e8639827c05 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models 3.Summarize abnormal behaviors and their causal relationships, highlighting how each suspicious entity contributed to the attack progression
Reference 80
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation beefd86a-2d65-4180-9f36-58f7dba7708f · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work
Reference 81
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 6129fb3d-b32a-42b0-a477-8648a89fab98 · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models The final report should provide clear forensic evidence for each phase and conclude with a concise explanation of the overall attack chain and its implications for defense
Reference 82
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
Observation 647f18cd-4095-4cdc-b84d-0f7fc248a68c · outbound
An Automated Attack Investigation Approach Leveraging Threat-Knowledge-Augmented Large Language Models Unresolved cited work
Reference 2025
Source-reported events for the cited work
No event found in the named queried sources as of 2026-08-23T06:30:58.430688+00:00.
No inbound Pith citation observations are available.