This review provides a novel synthesis of recent Large Language Model applications in threat hunting and identifies critical research gaps, and presents a refined perspective on the practical implementation and future trajectory of these technologies.
To improve cybersecurity across industries, Cyber Threat Intelligence (CTI) is becoming increasingly crucial. This systematic review explores how CTI practices are evolving in response to advancements in Artificial Intelligence (AI), particularly in the context of Large Language Models (LLMs). We examined 61 peer-reviewed studies using the PRISMA methodology, which demonstrates a strict selection procedure founded on specified inclusion, exclusion, and quality standards. This approach aligns with the scope of similar systematic reviews in the field of cyber threat intelligence. The review provides a comparative synthesis of CTI research capabilities across threat detection and prediction, attribution, forecasting, and automated reporting. We classify these approaches into three categories: conventional methods, those enhanced by AI and Machine Learning, and those based on LLMs. Our findings indicate that LLMs offer significant advantages in contextual reasoning, processing unstructured threat intelligence, and generating actionable mitigation plans. However, challenges such as model explainability, data privacy, system interoperability, and standardization impede their integration into operational environments. In addition to highlighting the potential and practical limitations of LLMs in CTI, this study identifies research gaps and proposes methods to create scalable, secure, and flexible CTI systems that support real-time cyber defense.
Hilalah Alturkistani, Abdul Ghafar Jaafar, S. Chuprat et al.· International journal of res...· 0 citations
The reviewed literature indicates that AI-based methodologies often demonstrate superior detection capabilities for intricate and previously unseen attack patterns compared to traditional methods; however, direct performance comparisons are complicated due to discrepancies in datasets, experimental designs, and evaluation protocols.
Jaswanth Garugu· International Journal for Re...· 0 citations
A structured taxonomy is proposed to organize various dimensions of AI-driven cybersecurity; review them critically; and finally, discuss key challenges, open problems, and emerging trends.
Artificial intelligence (AI) has emerged as a transformative force in cybersecurity, offering capabilities that extend far beyond the static, rule-based defenses of the past. Machine learning, deep learning, and natural language processing techniques are increasingly embedded in intrusion detection systems, threat intelligence platforms, and automated incident response tools, enabling organizations to identify and neutralize threats with greater speed and precision. However, the same interconnectedness that drives digital transformation—spanning IoT ecosystems, cloud infrastructures, and 5G networks—has also expanded the attack surface available to malicious actors, giving rise to increasingly sophisticated, adaptive, and often AI-enabled threats such as adversarial machine learning attacks, deepfake-driven social engineering, and automated supply chain exploits. This paper examines the dual role of AI as both a defensive asset and a potential vector of risk within modern cybersecurity ecosystems. Drawing on a review of existing AI-driven security solutions, comparative analysis of AI-based versus traditional defense mechanisms, and case study evaluation, the study assesses the effectiveness, limitations, and ethical implications of AI integration in cyber defense. Findings indicate that while AI substantially improves threat detection accuracy and response times, challenges related to explainability, adversarial vulnerability, and regulatory oversight remain significant barriers to widespread adoption. The paper concludes with practical recommendations for organizations and policymakers seeking to harness AI's defensive potential while mitigating its associated risks, emphasizing the need for explainable AI frameworks, human-AI collaboration, and adaptive governance structures in an increasingly interconnected digital age.
Nicolas Guzman Camacho· Journal of Artificial Intell...· 0 citations
The increasing sophistication of cyber threats poses serious challenges to national security (NS) and critical infrastructure (CI), requiring adaptive and intelligence-driven cyber defense mechanisms. While recent artificial intelligence (AI)-based methods have improved detection capabilities, many existing solutions focus on isolated threat categories or rely on single-layer detection models, limiting their robustness and deployment feasibility. This work presents a unified and adaptive artificial intelligence (AI)-enabled cyber threats detection framework that simultaneously addresses intrusion detection, malware detection and phishing detection within a cyber warfare context. The proposed framework integrates hybrid detection strategies with a threshold-based decision mechanism to balance detection effectiveness, false positive control and computational efficiency. A formal mathematical formulation supports feature representation, classification and evaluation. The framework is evaluated using multiple publicly available benchmark datasets under a consistent experimental setup. The experimental results demonstrate strong performance across threat categories, achieving detection accuracy above 96%, F1-scores exceeding 95% and false positive rates below 2%, highlighting the framework's effectiveness and deployment suitability for mission-critical cyber defense applications.
Krishan Berwal, D. Makhija, R. Bodade· 2026 6th International Confe...· 0 citations
Nigeria faces escalating cybersecurity challenges, recording an average of 4,200 weekly cyberattacks per
organization-the highest in Africa and 60% above the global average [1]. The weaponization of Artificial Intelligence (AI)
by threat actors, including terrorist organizations using frontier AI models for operational planning and tactical decisionmaking [2], has fundamentally transformed the threat landscape. Traditional security frameworks, designed for static,
pattern-based threats, are increasingly inadequate against AI-driven intrusions such as automated phishing, identity
exploitation, and multi-vector ransomware [1]. This paper presents the design, implementation, and evaluation of an AIassisted cybersecurity intelligence platform integrating the DeepSeek API to detect, analyze, and mitigate digital threats in
the Nigerian context. The platform employs a Python-based architecture that ingests threat indicators, classifies and explains
attacks using DeepSeek's natural language processing capabilities, and delivers actionable mitigation recommendations with
confidence scoring. The system is made available as open-source code on GitHub and deployed via Streamlit Cloud for
practical adoption.
Orji, Cyrus Ebere, Paul Nosike, O. C. et al.· International Journal of Inn...· 0 citations