{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:HWKAD76UBG7DKC5ACD7X4E7B7I","short_pith_number":"pith:HWKAD76U","schema_version":"1.0","canonical_sha256":"3d9401ffd409be350ba010ff7e13e1fa361737d4033dc13cfe8ae03891441085","source":{"kind":"arxiv","id":"2409.02074","version":1},"attestation_state":"computed","paper":{"title":"RACONTEUR: A Knowledgeable, Insightful, and Portable LLM-Powered Shell Command Explainer","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.HC","cs.LG","cs.SE"],"primary_cat":"cs.CR","authors_text":"(2) Ant Group), Haiqin Weng (2), Jiangyi Deng (1), Tao Wei (2), Wenyuan Xu (1) ((1) Zhejiang University, Xinfeng Li (1), Yanjiao Chen (1), Yan Liu (2), Yijie Bai (1)","submitted_at":"2024-09-03T17:22:00Z","abstract_excerpt":"Malicious shell commands are linchpins to many cyber-attacks, but may not be easy to understand by security analysts due to complicated and often disguised code structures. Advances in large language models (LLMs) have unlocked the possibility of generating understandable explanations for shell commands. However, existing general-purpose LLMs suffer from a lack of expert knowledge and a tendency to hallucinate in the task of shell command explanation. In this paper, we present Raconteur, a knowledgeable, expressive and portable shell command explainer powered by LLM. Raconteur is infused with "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2409.02074","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-09-03T17:22:00Z","cross_cats_sorted":["cs.HC","cs.LG","cs.SE"],"title_canon_sha256":"6e04414c4009392543a7c00d07a3f5a7372630d8196da44c0f4128f68a112d45","abstract_canon_sha256":"873a4b4cd4668ce4c2fd778432dc6732d1bbad66833c3490b7fb59b37585bccd"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:02:38.326452Z","signature_b64":"2KQfk8y9hJwbr2IN35sgI/RvmoQHUi0/g6Zo+qzKqprT91m8aor2ZKnm4cQluFMTkhmbT6VJoM8bBYSPzfqQDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"3d9401ffd409be350ba010ff7e13e1fa361737d4033dc13cfe8ae03891441085","last_reissued_at":"2026-07-05T09:02:38.325836Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:02:38.325836Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"RACONTEUR: A Knowledgeable, Insightful, and Portable LLM-Powered Shell Command Explainer","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.HC","cs.LG","cs.SE"],"primary_cat":"cs.CR","authors_text":"(2) Ant Group), Haiqin Weng (2), Jiangyi Deng (1), Tao Wei (2), Wenyuan Xu (1) ((1) Zhejiang University, Xinfeng Li (1), Yanjiao Chen (1), Yan Liu (2), Yijie Bai (1)","submitted_at":"2024-09-03T17:22:00Z","abstract_excerpt":"Malicious shell commands are linchpins to many cyber-attacks, but may not be easy to understand by security analysts due to complicated and often disguised code structures. Advances in large language models (LLMs) have unlocked the possibility of generating understandable explanations for shell commands. However, existing general-purpose LLMs suffer from a lack of expert knowledge and a tendency to hallucinate in the task of shell command explanation. In this paper, we present Raconteur, a knowledgeable, expressive and portable shell command explainer powered by LLM. Raconteur is infused with "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2409.02074","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2409.02074/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2409.02074","created_at":"2026-07-05T09:02:38.325913+00:00"},{"alias_kind":"arxiv_version","alias_value":"2409.02074v1","created_at":"2026-07-05T09:02:38.325913+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2409.02074","created_at":"2026-07-05T09:02:38.325913+00:00"},{"alias_kind":"pith_short_12","alias_value":"HWKAD76UBG7D","created_at":"2026-07-05T09:02:38.325913+00:00"},{"alias_kind":"pith_short_16","alias_value":"HWKAD76UBG7DKC5A","created_at":"2026-07-05T09:02:38.325913+00:00"},{"alias_kind":"pith_short_8","alias_value":"HWKAD76U","created_at":"2026-07-05T09:02:38.325913+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.21773","citing_title":"HIDBench: Benchmarking Large Language Models for Host-Based Intrusion Detection","ref_index":14,"is_internal_anchor":false},{"citing_arxiv_id":"2512.12078","citing_title":"The Procedural Semantics Gap in Structured CTI: A Measurement-Driven STIX Analysis for APT Emulation","ref_index":13,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/HWKAD76UBG7DKC5ACD7X4E7B7I","json":"https://pith.science/pith/HWKAD76UBG7DKC5ACD7X4E7B7I.json","graph_json":"https://pith.science/api/pith-number/HWKAD76UBG7DKC5ACD7X4E7B7I/graph.json","events_json":"https://pith.science/api/pith-number/HWKAD76UBG7DKC5ACD7X4E7B7I/events.json","paper":"https://pith.science/paper/HWKAD76U"},"agent_actions":{"view_html":"https://pith.science/pith/HWKAD76UBG7DKC5ACD7X4E7B7I","download_json":"https://pith.science/pith/HWKAD76UBG7DKC5ACD7X4E7B7I.json","view_paper":"https://pith.science/paper/HWKAD76U","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2409.02074&json=true","fetch_graph":"https://pith.science/api/pith-number/HWKAD76UBG7DKC5ACD7X4E7B7I/graph.json","fetch_events":"https://pith.science/api/pith-number/HWKAD76UBG7DKC5ACD7X4E7B7I/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/HWKAD76UBG7DKC5ACD7X4E7B7I/action/timestamp_anchor","attest_storage":"https://pith.science/pith/HWKAD76UBG7DKC5ACD7X4E7B7I/action/storage_attestation","attest_author":"https://pith.science/pith/HWKAD76UBG7DKC5ACD7X4E7B7I/action/author_attestation","sign_citation":"https://pith.science/pith/HWKAD76UBG7DKC5ACD7X4E7B7I/action/citation_signature","submit_replication":"https://pith.science/pith/HWKAD76UBG7DKC5ACD7X4E7B7I/action/replication_record"}},"created_at":"2026-07-05T09:02:38.325913+00:00","updated_at":"2026-07-05T09:02:38.325913+00:00"}