---
格式版本: 2
标题: "From Threat Intelligence to Detection: Knowledge-driven Enrichment and Template-based Rule Grounding for Automated Sigma Rule Generation"
原文链接: "https://arxiv.org/abs/2608.19011"
发布日期: "2026-08-19"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Wed, 19 Aug 2026 15:11:43 UTC (1,860 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-20T15:50:12+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-20T15:48:16+08:00"
入库时间: "2026-08-20T07:50:12.962Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=model%20fit&searchtype=all"
匹配关键词:
  - "model fit"
  - "AI"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 2
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "论文主题为网络安全威胁情报自动化Sigma规则生成，与超节点/AI Rack/机柜级AI基础设施完全无关，无任何相关技术、商业或部署信息。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-20T15:56:25+08:00"
AI主题相关性: 0
AI来源权威性: 1
AI新颖性: 0
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 1
AI摘要: "AUTOSIGMA 提出一种自动化方案，将非结构化的网络威胁情报报告转换为 Sigma 检测规则，以解决人工编写易错且难以扩展的问题。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:19:40.124Z"
采集批次: "2026年8月20日14点19分32秒"
采集批次ID: "20260820-141932-079"
去重键: "https://arxiv.org/abs/2608.19011"
---

## Computer Science > Cryptography and Security

## Title:From Threat Intelligence to Detection: Knowledge-driven Enrichment and Template-based Rule Grounding for Automated Sigma Rule Generation

[View PDF](https://arxiv.org/pdf/2608.19011) [HTML (experimental)](https://arxiv.org/html/2608.19011v1)

> Abstract:Mechanisms for dynamically converting cyber threat intelligence (CTI) into actionable detection capabilities are necessary due to the rapid evolution of Advanced Persistent Threats (APTs). Sigma rules are an essential part of contemporary threat detection workflows because they offer a platform-independent framework for expressing detection logic that can be converted into particular queries across SIEM systems. Conventional techniques for manually crafting Sigma rules are prone to mistakes, and necessitate extensive knowledge, which restricts their scalability. Although there are open-source and industry-maintained Sigma rule repositories, they often fail to keep pace with emerging threats and require frequent customization to fit diverse operational environments. This emphasizes the necessity of dynamic rule generation that is adapted to evolving attack techniques as well as particular use cases. In this work, we design AUTOSIGMA, an automated solution for transforming unstructured CTI reports into relevant Sigma rules. Rather than relying solely on language models, AUTOSIGMA leverages a structured knowledge base to enrich partial inputs, matches the enriched content against a repository of existing Sigma rules, and then employs an LLM-as-a-Judge mechanism to iteratively validate the rules. By combining knowledge-driven enrichment, template-based rule grounding, and a multi-stage solution, AUTOSIGMA enables accurate, context-aware, and relevant rule generation. Evaluations across multiple real-world APT reports and multiple security blogs demonstrate that AUTOSIGMA outperforms alternative solutions and LLM models in rule validity, rule relevancy, MITRE ATT&CK technique coverage, and robustness to input quality.  
> AUTOSIGMA's Demo: [this https URL](https://youtu.be/iSr6IurQ6BM)

| Comments: |  |
| --- | --- |
| Subjects: | Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI) |
| Cite as: | [arXiv:2608.19011](https://arxiv.org/abs/2608.19011) \[cs.CR\] |
|  | (or [arXiv:2608.19011v1](https://arxiv.org/abs/2608.19011v1) \[cs.CR\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.19011](https://doi.org/10.48550/arXiv.2608.19011) |

## Submission history

From: Boubakr Nour \[[view email](https://arxiv.org/show-email/7d57e384/2608.19011)\]  
**\[v1\]** Wed, 19 Aug 2026 15:11:43 UTC (1,860 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.19011) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
