Skip to content
Search
paperSeptember 2026Unreviewed

SCRIPTIOC-BENCH: A Benchmark for Recognizing Actionable Threat Intelligence from Script-Based Malware using LLMs

Hanna Kim, Jian Cui, Minkyoo Song, Hwanjo Heo, Seungwon Shin, Kimin Lee, Xiaojing Liao

Abstract

Script-based malware remains a prevalent attack technique. These scripts often contain indicators of compromise (IOCs) that provide actionable threat intelligence. However, statically recovering such indicators is challenging, as relevant values may be dispersed or transformed within code. Although large language models (LLMs) have shown promise in security analysis, their ability to recover IOCs from malicious scripts remains underexplored. We present SCRIPTIOC-BENCH, a benchmark for measuring

Categories

Cite

@misc{kim2026scriptiocbench,
  title = {{SCRIPTIOC-BENCH: A Benchmark for Recognizing Actionable Threat Intelligence from Script-Based Malware using LLMs}},
  author = {Hanna Kim and Jian Cui and Minkyoo Song and Hwanjo Heo and Seungwon Shin and Kimin Lee and Xiaojing Liao},
  year = {2026},
  month = sep,
  eprint = {2609.06149},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2609.06149}
}