Skip to content
Open access

Time-Series and Social-Media Threat Analytics over a Deployed Cyber-Threat Knowledge Graph

Aug 2026 · Information · 0 citations · 19 references

TL;DR

EdgeGuard, a deployed cyber-threat knowledge graph that merges eleven public threat feeds into one Neo4j database via MISP and the STIX 2.1 exchange format, is measured, showing that half of the vulnerabilities known to have been exploited were listed as exploited within five days of their publication, and that a large ingestion spike in early 2026 came from a single feed rather than a real attack wave.

Abstract

Security teams decide which vulnerabilities to patch first, which alerts to trust, and whether social media warns of new threats earlier than the official feeds. We answer these questions by directly measuring EdgeGuard, a deployed cyber-threat knowledge graph that merges eleven public threat feeds into one Neo4j database via MISP (an open threat-sharing platform) and the STIX 2.1 exchange format, recording for every entry which feed reported it and when. These records let the graph be read as a time series. Read this way, it shows that half of the vulnerabilities known to have been exploited were listed as exploited within five days of their publication (352 cases), and that a large ingestion spike in early 2026 came from a single feed rather than a real attack wave. Benchmarked against 10,000 threat-related social-media posts, the graph already held 96% of the actionable vulnerabilities the posts discussed and reported them at least as quickly, while most posts carried no actionable signal and social media led only in early warning of active exploitation. A crowd-sourced community layer additionally supplies the only intelligence tagged by industry sector. The deployed graph is thus a clean, timely, and comprehensive base, and live social ingestion a small, targeted enhancement.

Read PDF

Similar papers

Preprint Aug 2026

STINER: Automated Extraction of Strategic Cyber Threat Intelligence from X

STINER, a taxonomy and expert-annotated corpus for extracting strategic intelligence from social media streams is introduced, and how social-media-driven extraction can surface early signals of the SafePay ransomware campaign prior to its retrospective characterization in vendor threat landscape reports is illustrated.

Yasir Ech-Chammakhy, Oussama Azrara, J. Chbili et al. · 0 citations
#natural language process... Preprint Aug 2026

BEACON: Behavior-Anchored Cross-Source Knowledge Graph Construction for Cyber Threat Intelligence

BEACON is an LLM-driven framework for cross-source CTI knowledge graph construction that constructs and releases two human-annotated datasets from 34 sources and outperforms all baselines by at least 23% and 9%, respectively.

Changze Li, Yutong Cheng, Tsania Camila Finnisa et al. · 0 citations
#graph neural networks Open access Sep 2026

Insider Threat Prediction Using Graph Analysis

The insider threat is still among the most difficult cybersecurity risks because of the access and capabilities of insiders to hide malicious or careless actions in the ordinary operations. The rules-based system, statistical anomaly detection and traditional machine learning tools are not always efficient in identifying the relational and contextual dependence in an enterprise setting which limits predictive capability as well as high false-positive. This paper presents a graph-baseds model of active preemptive insider threat detection. The Insider Threat Dataset of Multi-source behavioral logs of Classified Environments are converted to a heterogeneous interaction graph, where the nodes represent users, devices, and resources, and the edges indicate the frequency of interaction, sensitivity, and time patterns. Normative measures such as degree, between, eigenvector centrality, community membership, motif patterns and PageRank are derived to display aberrant relational activity. Empirical analysis has shown that a higher number of off-hours of printing/burning, larger volumes of data being exfiltrated, longer occupancy duration, and high-risk travel occur in malicious insiders occupying more influential network positions (much higher PageRank). The full prediction accuracy (FNNs classify every sample correctly) of Graph Neural Networks (GNNs) is high (F1 = 1.0, AUC = 1.0), which is significantly higher than that of the traditional baselines (Random Forest: F1 = 0.7576; XGBoost: F1 = 0.6753). The findings demonstrate the effectiveness of the graph-based methods in providing high-quality behavioral dependencies, with better accuracy and fewer false alarms and greater explainability in real-life insider risk monitoring.

Muhammad Irshad, M. Shafiq, M. Sajjad · 0 citations
Open access Aug 2026

Breaking and Defending LLM-Powered Social Media Bot Detection Systems †

The rise of social media bots poses a persistent threat, enabling misinformation, public opinion manipulation, and erosion of trust in online platforms. To combat this, machine learning systems have been developed to detect and limit bot activity. However, attackers continuously adapt through adversarial optimization, behavior imitation, and semantic manipulation strategies, creating an escalating arms race with detection tools. Recent advances in LLMs have significantly improved bot detection by enabling deeper semantic and contextual analysis. However, this shift also introduces new attack surfaces, allowing adversaries to craft exploits that directly target LLM reasoning and generation mechanisms. Industry tools like Anthropic’s Claude Code Security similarly leverage LLMs for security, motivating our study of their attack surfaces. In this work, we explore both offensive and defensive aspects of LLM-powered, threat-specific cybersecurity applications. While centered on the challenge of social media bot detection, our methodology and insights generalize to a broad class of LLM-powered cybersecurity systems, including phishing detection, email classification, fraud analysis, and more. We introduce two novel adversarial attack strategies that systematically exploit semantic and contextual weaknesses of LLM-based classifiers, degrading LLM performance in bot detection by up to 48%, and propose a robust multi-LLM defense architecture designed to preserve detection reliability under adaptive adversarial conditions. Our solution, LSABRE, is a multi-LLM framework that improves robustness across various attacks, maintaining 86% detection accuracy even under strong adaptive adversarial attacks.

Nof Orenstein, Yoni Birman · 0 citations
Open access Aug 2026

A Web-Based Threat Intelligence Platform for URL Risk Analysis

The rapid growth of cybercrime activities on the darkweb has brought organizations, researchers and cyber security professionals into real troubles.These hidden market places, credential leak repositories, money fraud hubs and anonymous communication channels often run through technologies like The Onion Router (TOR) so pinning down threats and keeping continuous monitoring becomes hard. What comes out of these covert networks is often missed by standard security monitoring tools, largely due to limited access and the chaotic nature of threat intelligence collection in real-world situations. This paper introduces a DarkWeb Monitoring Simulation platform, a web based threat intelligence concept that can analyze suspicious URLs and then create risk assessments. The proposed system combines active web scanning with passive heuristic analysis techniques to discover indicators of phishing, financial fraud, credential theft, darknet marketplaces and other malicious activities. This application is built on Python Flask and SQLite and it has user authentication, OTP verification, scan history management, and an interactive dashboard for threat visualization.In experiments, the system can sort URLs into separate tiers of risk using a weighted scoring method, and the results show this. Essentially, the platform developed is a less expensive educational alternative to commercial threat intelligence solutions and still enables practical experience with cybersecurity monitoring concepts.

A. K. A Keerthana, Palle Chandana, Karbuje Sruthika · 0 citations
Preprint Aug 2026

Operationalizing Cyber Threat Intelligence with GraphRAG

This project asks whether feeding a report into a knowledge-graph retrieval system, Microsoft GraphRAG, rather than a standard vector-similarity retrieval system (Naive RAG), produces detection plans that rely more on these durable, top-of-pyramid clues.

A. Kabra, Prakhar Paliwal, M. Hanawal · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.