LLM-Driven Alert Correlation and Lifecycle Prediction With Threat Intelligence for Attack Forensics
Security Operations Centers face overwhelming volumes of alerts from firewalls, intrusion detection systems, and other sources. These alerts often lack temporal and semantic coherence, hindering analysts from reconstructing full MITRE ATT&CK lifecycles or anticipating subsequent techniques. To address this, we propose...