{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:AK4GVYHHQ3XM2TKKFPZWXWVHZF","short_pith_number":"pith:AK4GVYHH","canonical_record":{"source":{"id":"2607.26201","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-07-28T19:06:24Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"5d08e443036b0e6b3ea41647379ef9bf6dde9cff534d929aa98fb3f7fa093e68","abstract_canon_sha256":"e2e1ee5ea77b9c7d47cc9667dab3a5d108101d7b241c649913ffbc7a6d1d2735"},"schema_version":"1.0"},"canonical_sha256":"02b86ae0e786eecd4d4a2bf36bdaa7c94e47f4dcf032f2ee200bd56c826ce937","source":{"kind":"arxiv","id":"2607.26201","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2607.26201","created_at":"2026-07-30T00:08:42Z"},{"alias_kind":"arxiv_version","alias_value":"2607.26201v1","created_at":"2026-07-30T00:08:42Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2607.26201","created_at":"2026-07-30T00:08:42Z"},{"alias_kind":"pith_short_12","alias_value":"AK4GVYHHQ3XM","created_at":"2026-07-30T00:08:42Z"},{"alias_kind":"pith_short_16","alias_value":"AK4GVYHHQ3XM2TKK","created_at":"2026-07-30T00:08:42Z"},{"alias_kind":"pith_short_8","alias_value":"AK4GVYHH","created_at":"2026-07-30T00:08:42Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:AK4GVYHHQ3XM2TKKFPZWXWVHZF","target":"record","payload":{"canonical_record":{"source":{"id":"2607.26201","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-07-28T19:06:24Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"5d08e443036b0e6b3ea41647379ef9bf6dde9cff534d929aa98fb3f7fa093e68","abstract_canon_sha256":"e2e1ee5ea77b9c7d47cc9667dab3a5d108101d7b241c649913ffbc7a6d1d2735"},"schema_version":"1.0"},"canonical_sha256":"02b86ae0e786eecd4d4a2bf36bdaa7c94e47f4dcf032f2ee200bd56c826ce937","receipt":{"kind":"pith_receipt","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"02b86ae0e786eecd4d4a2bf36bdaa7c94e47f4dcf032f2ee200bd56c826ce937","last_reissued_at":"2026-07-30T00:08:42.215069Z","signature_status":"unsigned_v0","first_computed_at":"2026-07-30T00:08:42.215069Z"},"source_kind":"arxiv","source_id":"2607.26201","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-30T00:08:42Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"/ZpnpcgH5X7EjO4DMPODqeV+pxZ8ENbXVc7VTH94IJfT36sT3YKpYya9CRlVhgDzyyZzzZDm/ThB3OtWp7VUCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-05T15:36:15.668737Z"},"content_sha256":"7d4fd3f3199a567345721ff298f35b1475f94cc91f8f2ed251f5cf37673003d6","schema_version":"1.0","event_id":"sha256:7d4fd3f3199a567345721ff298f35b1475f94cc91f8f2ed251f5cf37673003d6"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:AK4GVYHHQ3XM2TKKFPZWXWVHZF","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"(EC)2: Event-Centric Explainability for Cybersecurity Through Multi-Agent LLM Investigations","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Andr\\'es Murillo, Asaf Shabtai, David Tayouri, Motoyoshi Sekiya, Neta Kirmayer, Rami Puzis","submitted_at":"2026-07-28T19:06:24Z","abstract_excerpt":"Security operations centers rely on anomaly detection systems to flag suspicious events. Feature-level explanations for anomaly detectors offer limited value for operational investigations. To effectively handle alerts, analysts need to know contextual relationships and need actionable understanding of the entities involved. This paper introduces an event-centric detector-agnostic approach for explaining cybersecurity alerts in small- to medium-sized enterprise networks. We present (EC)2, a multi-agent framework that performs structured, hypothesis-driven investigation to provide explanations "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2607.26201","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2607.26201/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-30T00:08:42Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"l5k4MjA/OLotpaPo3RTbW8JcJk7JLiodT5/tMBD10TT1QX9+p/uKX5xt8u2cIC4SInpDHl2EzOH2hoQm4BumAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-05T15:36:15.669682Z"},"content_sha256":"46402dbe283d288294adb615d64755bf93652079d40055bc67e155570b285322","schema_version":"1.0","event_id":"sha256:46402dbe283d288294adb615d64755bf93652079d40055bc67e155570b285322"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/AK4GVYHHQ3XM2TKKFPZWXWVHZF/bundle.json","state_url":"https://pith.science/pith/AK4GVYHHQ3XM2TKKFPZWXWVHZF/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/AK4GVYHHQ3XM2TKKFPZWXWVHZF/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-08-05T15:36:15Z","links":{"resolver":"https://pith.science/pith/AK4GVYHHQ3XM2TKKFPZWXWVHZF","bundle":"https://pith.science/pith/AK4GVYHHQ3XM2TKKFPZWXWVHZF/bundle.json","state":"https://pith.science/pith/AK4GVYHHQ3XM2TKKFPZWXWVHZF/state.json","well_known_bundle":"https://pith.science/.well-known/pith/AK4GVYHHQ3XM2TKKFPZWXWVHZF/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:AK4GVYHHQ3XM2TKKFPZWXWVHZF","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e2e1ee5ea77b9c7d47cc9667dab3a5d108101d7b241c649913ffbc7a6d1d2735","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-07-28T19:06:24Z","title_canon_sha256":"5d08e443036b0e6b3ea41647379ef9bf6dde9cff534d929aa98fb3f7fa093e68"},"schema_version":"1.0","source":{"id":"2607.26201","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2607.26201","created_at":"2026-07-30T00:08:42Z"},{"alias_kind":"arxiv_version","alias_value":"2607.26201v1","created_at":"2026-07-30T00:08:42Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2607.26201","created_at":"2026-07-30T00:08:42Z"},{"alias_kind":"pith_short_12","alias_value":"AK4GVYHHQ3XM","created_at":"2026-07-30T00:08:42Z"},{"alias_kind":"pith_short_16","alias_value":"AK4GVYHHQ3XM2TKK","created_at":"2026-07-30T00:08:42Z"},{"alias_kind":"pith_short_8","alias_value":"AK4GVYHH","created_at":"2026-07-30T00:08:42Z"}],"graph_snapshots":[{"event_id":"sha256:46402dbe283d288294adb615d64755bf93652079d40055bc67e155570b285322","target":"graph","created_at":"2026-07-30T00:08:42Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2607.26201/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Security operations centers rely on anomaly detection systems to flag suspicious events. Feature-level explanations for anomaly detectors offer limited value for operational investigations. To effectively handle alerts, analysts need to know contextual relationships and need actionable understanding of the entities involved. This paper introduces an event-centric detector-agnostic approach for explaining cybersecurity alerts in small- to medium-sized enterprise networks. We present (EC)2, a multi-agent framework that performs structured, hypothesis-driven investigation to provide explanations ","authors_text":"Andr\\'es Murillo, Asaf Shabtai, David Tayouri, Motoyoshi Sekiya, Neta Kirmayer, Rami Puzis","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-07-28T19:06:24Z","title":"(EC)2: Event-Centric Explainability for Cybersecurity Through Multi-Agent LLM Investigations"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2607.26201","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:7d4fd3f3199a567345721ff298f35b1475f94cc91f8f2ed251f5cf37673003d6","target":"record","created_at":"2026-07-30T00:08:42Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e2e1ee5ea77b9c7d47cc9667dab3a5d108101d7b241c649913ffbc7a6d1d2735","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-07-28T19:06:24Z","title_canon_sha256":"5d08e443036b0e6b3ea41647379ef9bf6dde9cff534d929aa98fb3f7fa093e68"},"schema_version":"1.0","source":{"id":"2607.26201","kind":"arxiv","version":1}},"canonical_sha256":"02b86ae0e786eecd4d4a2bf36bdaa7c94e47f4dcf032f2ee200bd56c826ce937","receipt":{"builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"02b86ae0e786eecd4d4a2bf36bdaa7c94e47f4dcf032f2ee200bd56c826ce937","first_computed_at":"2026-07-30T00:08:42.215069Z","kind":"pith_receipt","last_reissued_at":"2026-07-30T00:08:42.215069Z","receipt_version":"0.3","signature_status":"unsigned_v0"},"source_id":"2607.26201","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:7d4fd3f3199a567345721ff298f35b1475f94cc91f8f2ed251f5cf37673003d6","sha256:46402dbe283d288294adb615d64755bf93652079d40055bc67e155570b285322"],"state_sha256":"dd15c19d8b02b56985b7f1c2d8a3f8b344b487f07c232e4e579207fbcf1412b9"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"iY+endpYM5Ruy7efW2JXFWWfCgqCvO3Ai25EyAG+IgBNei/PJBq2Hsw4bksa5scc4u6+XfrNez/hjvsF1oeLBA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-08-05T15:36:15.674942Z","bundle_sha256":"ce820baf26393d676e76ebb18fe21f8c2678ea8c192b89edef0afaf30e042a6e"}}