SecLM SOC copilot: a retrieval-augmented large language model copilot for APT alert analysis in security operations centers
Security operations center (SOC) analysts must interpret large volumes of alerts under severe time pressure, and this burden grows more demanding when advanced persistent threat (APT) activity is distributed across endpoint telemetry, network indicators, host context, and threat intelligence. This paper presents SecLM,...