{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2020:XWJXAQGSWZDEZ67FWXJ7NPQS7L","short_pith_number":"pith:XWJXAQGS","schema_version":"1.0","canonical_sha256":"bd937040d2b6464cfbe5b5d3f6be12faf6745d358f6608706d4d9796f42f966f","source":{"kind":"arxiv","id":"2004.14322","version":1},"attestation_state":"computed","paper":{"title":"Automated Retrieval of ATT&CK Tactics and Techniques for Cyber Threat Reports","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Andreas Peter, Christin Seifert, Marco Caselli, Valentine Legoy","submitted_at":"2020-04-29T16:45:14Z","abstract_excerpt":"Over the last years, threat intelligence sharing has steadily grown, leading cybersecurity professionals to access increasingly larger amounts of heterogeneous data. Among those, cyber attacks' Tactics, Techniques and Procedures (TTPs) have proven to be particularly valuable to characterize threat actors' behaviors and, thus, improve defensive countermeasures. Unfortunately, this information is often hidden within human-readable textual reports and must be extracted manually. In this paper, we evaluate several classification approaches to automatically retrieve TTPs from unstructured text. To "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2004.14322","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2020-04-29T16:45:14Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"081fe065979ecc6d639c23b2f0bbad199ede5812cff662ec137440fede0b5096","abstract_canon_sha256":"aa1e22faf58af4ca2e7e9bcb7bbe6fc205917df6ec62ae80dccba0e34af1e526"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:59:19.520724Z","signature_b64":"UwyNoH/3LIgfMj0WLBXAKkCc5EgQn4rB/x8xnLc7we7mpiFMgYKAOPNuT33wxpwaitoKtY1r8DFvCAUVnaQTAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"bd937040d2b6464cfbe5b5d3f6be12faf6745d358f6608706d4d9796f42f966f","last_reissued_at":"2026-07-05T00:59:19.520310Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:59:19.520310Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Automated Retrieval of ATT&CK Tactics and Techniques for Cyber Threat Reports","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Andreas Peter, Christin Seifert, Marco Caselli, Valentine Legoy","submitted_at":"2020-04-29T16:45:14Z","abstract_excerpt":"Over the last years, threat intelligence sharing has steadily grown, leading cybersecurity professionals to access increasingly larger amounts of heterogeneous data. Among those, cyber attacks' Tactics, Techniques and Procedures (TTPs) have proven to be particularly valuable to characterize threat actors' behaviors and, thus, improve defensive countermeasures. Unfortunately, this information is often hidden within human-readable textual reports and must be extracted manually. In this paper, we evaluate several classification approaches to automatically retrieve TTPs from unstructured text. To "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2004.14322","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2004.14322/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2004.14322","created_at":"2026-07-05T00:59:19.520368+00:00"},{"alias_kind":"arxiv_version","alias_value":"2004.14322v1","created_at":"2026-07-05T00:59:19.520368+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2004.14322","created_at":"2026-07-05T00:59:19.520368+00:00"},{"alias_kind":"pith_short_12","alias_value":"XWJXAQGSWZDE","created_at":"2026-07-05T00:59:19.520368+00:00"},{"alias_kind":"pith_short_16","alias_value":"XWJXAQGSWZDEZ67F","created_at":"2026-07-05T00:59:19.520368+00:00"},{"alias_kind":"pith_short_8","alias_value":"XWJXAQGS","created_at":"2026-07-05T00:59:19.520368+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.18190","citing_title":"Multi-Source Cybersecurity Logs: An ATT&CK-Labeled Dataset and SLM Evaluation","ref_index":27,"is_internal_anchor":false},{"citing_arxiv_id":"2606.18166","citing_title":"Evaluating Open-Source LLMs for Multi-Label ATT&CK Technique Classification on CTI Reports","ref_index":20,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/XWJXAQGSWZDEZ67FWXJ7NPQS7L","json":"https://pith.science/pith/XWJXAQGSWZDEZ67FWXJ7NPQS7L.json","graph_json":"https://pith.science/api/pith-number/XWJXAQGSWZDEZ67FWXJ7NPQS7L/graph.json","events_json":"https://pith.science/api/pith-number/XWJXAQGSWZDEZ67FWXJ7NPQS7L/events.json","paper":"https://pith.science/paper/XWJXAQGS"},"agent_actions":{"view_html":"https://pith.science/pith/XWJXAQGSWZDEZ67FWXJ7NPQS7L","download_json":"https://pith.science/pith/XWJXAQGSWZDEZ67FWXJ7NPQS7L.json","view_paper":"https://pith.science/paper/XWJXAQGS","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2004.14322&json=true","fetch_graph":"https://pith.science/api/pith-number/XWJXAQGSWZDEZ67FWXJ7NPQS7L/graph.json","fetch_events":"https://pith.science/api/pith-number/XWJXAQGSWZDEZ67FWXJ7NPQS7L/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/XWJXAQGSWZDEZ67FWXJ7NPQS7L/action/timestamp_anchor","attest_storage":"https://pith.science/pith/XWJXAQGSWZDEZ67FWXJ7NPQS7L/action/storage_attestation","attest_author":"https://pith.science/pith/XWJXAQGSWZDEZ67FWXJ7NPQS7L/action/author_attestation","sign_citation":"https://pith.science/pith/XWJXAQGSWZDEZ67FWXJ7NPQS7L/action/citation_signature","submit_replication":"https://pith.science/pith/XWJXAQGSWZDEZ67FWXJ7NPQS7L/action/replication_record"}},"created_at":"2026-07-05T00:59:19.520368+00:00","updated_at":"2026-07-05T00:59:19.520368+00:00"}