Security operations center (SOC) analysts must interpret large volumes of alerts under severe time pressure, and this burden grows more demanding when advanced persistent threat (APT) activity is distributed across endpoint telemetry, network indicators, host context, and threat intelligence. This paper presents SecLM, a retrieval-grounded large language model (LLM) copilot, built on Google’s Gemini with a FAISS vector index over Sentence-Transformer (all-MiniLM-L6-v2) embeddings, that supports early-stage alert triage, investigation planning, and remediation recommendations for APT analysis. The proposed workflow embeds curated cyber security knowledge into a vector index, retrieves alert-relevant evidence, and conditions a generation module, guided by few-shot prompting and Pydantic-validated structured generation, on both the retrieved context and a predefined incident response schema. This design preserves the flexibility of natural language synthesis, while constraining the output to auditable fields that include an alert summary, a risk assessment, an investigation plan, remediation actions, and adversary behavior mappings aligned with MITRE ATT&CK. The system is evaluated through a DarkHydrus-inspired case study (ALERT-001) involving a high-severity malware alert on WORKSTATION-075, which communicates with a suspected command and control (C2) endpoint linked to DarkHydrus. The generated output correlates alert telemetry, host metadata, and threat intelligence into a six step investigation plan, a five-action remediation plan, and analyst-facing visual summaries. The study does not claim autonomous response or universal detection performance. Instead, it shows that retrieval-grounded LLM assistance can produce structured, reviewable, and machine-consumable response artifacts that reduce synthesis burden while preserving analyst control.
The results are packaged in the Greenfield Startup Model (GSM), which explains the priority of startups to release the product as quickly as possible, and the need to shorten time-to-market, by speeding up the development through low-precision engineering activities.
Carmine Giardino, Nicolò Paternoster, M. Unterkalmsteiner et al.· IEEE Transactions on Softwar...· 178 citations· ⚡14
Software startup companies develop innovative, software-intensive products within limited timeframes and with few resources, searching for sustainable and scalable business models.
M. Unterkalmsteiner, P. Abrahamsson, Xiaofeng Wang et al.· e-Informatica Software Engin...· 157 citations· ⚡17
This study conducts a case survey study based on the secondary data of the major pivots happened in 49 software startups, and demonstrates that customer need pivot is the most common among all pivot types.
Sohaib Shahid Bajwa, Xiaofeng Wang, Anh Nguyen-Duc et al.· Empirical Software Engineeri...· 127 citations· ⚡15
The comparison of adopter and non-adopter sample reveals three potential adoption inhibitor, security, data privacy, and portability, which underlines the importance of the technical and security perspectives for research investigating the adoption of technology.
Nattakarn Phaphoom, Xiaofeng Wang, S. Samuel et al.· Journal of Systems and Softw...· 111 citations· ⚡8
The ongoing work building a Raspberry Pi cluster consisting of 300 nodes is presented, with potential use cases being an inexpensive and green test bed for cloud computing research and a robust and mobile data center for operating in adverse environments.
P. Abrahamsson, S. Helmer, Nattakarn Phaphoom et al.· IEEE International Conferenc...· 110 citations· ⚡7
The results indicate that software developers are a slightly happy population, but the need for limiting the unhappiness of developers remains, and 219 factors representing causes of unhappiness while developing software are identified.
D. Graziotin, Fabian Fagerholm, Xiaofeng Wang et al.· International Conference on...· 84 citations· ⚡6
Related blog posts
MIT News · Artificial Intelligence· news.mit.eduOct 8, 2026