June 2026Unreviewed
Benchmarking and Exploring the Capabilities of LLMs for Attack Investigations
Aniket Anand, Yiwei Hou, Daniel Fields, Alex Kantchelian, David Tao, Kurt Thomas, Grant Ho
Abstract
This paper presents AuditBench, a new benchmark dataset for evaluating the capabilities of LLMs at investigating security-related system audit logs. We design and use this benchmark to explore the performance of LLMs on four log-investigation tasks that incident response teams commonly perform, ranging from triaging alerts generated by detectors to identifying persistence mechanisms on compromised systems. AuditBench consists of system audit logs collected from Linux and Windows machines, and sp
Categories
Cite
@misc{anand2026benchmarking,
title = {{Benchmarking and Exploring the Capabilities of LLMs for Attack Investigations}},
author = {Aniket Anand and Yiwei Hou and Daniel Fields and Alex Kantchelian and David Tao and Kurt Thomas and Grant Ho},
year = {2026},
month = jun,
eprint = {2606.10281},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2606.10281}
}