Update README.md
Browse files
README.md
CHANGED
|
@@ -10,4 +10,46 @@ tags:
|
|
| 10 |
- STIX standard
|
| 11 |
- threat intelligence
|
| 12 |
- MITRE ATT&CK
|
| 13 |
-
---
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 10 |
- STIX standard
|
| 11 |
- threat intelligence
|
| 12 |
- MITRE ATT&CK
|
| 13 |
+
---
|
| 14 |
+
|
| 15 |
+
# QCRI/AZERG-MixTask-Mistral
|
| 16 |
+
|
| 17 |
+
This model is a fine-tuned version of mistralai/Mistral-7B-Instruct-v0.3 specialized for Cyber Threat Intelligence (CTI) tasks. It was trained on the AZERG Dataset covering a mixture of all four tasks required for STIX data generation:
|
| 18 |
+
- T1: Entity Detection
|
| 19 |
+
- T2: Entity Type Identification
|
| 20 |
+
- T3: Related Pair Detection
|
| 21 |
+
- T4: Relationship Type Identification
|
| 22 |
+
|
| 23 |
+
This is the most versatile model in the AZERG collection, capable of handling all STIX extraction sub-tasks.
|
| 24 |
+
|
| 25 |
+
## Intended Use
|
| 26 |
+
|
| 27 |
+
This model is intended to be used within the [AZERG framework](https://github.com/QCRI/azerg/) to extract STIX entities and relationships from security reports. Please check the exact prompts in the framework.
|
| 28 |
+
|
| 29 |
+
Example Prompt (Task 1: Entity Detection):
|
| 30 |
+
```
|
| 31 |
+
Instruction:
|
| 32 |
+
You are a helpful threat intelligence analyst. Your task is to extract all STIX entities mentioned in the input. To help you, here is a list of the possible STIX entity types.
|
| 33 |
+
STIX entity types:
|
| 34 |
+
- ATTACK_PATTERN: A type of TTP that describes ways that adversaries attempt to compromise targets. (e.g., T1051, T1548.001, etc.)
|
| 35 |
+
[...]
|
| 36 |
+
|
| 37 |
+
Answer in the following format: <entities>LIST OF IDENTIFIED ENTITIES SEPARATED BY PIPE |</entities>
|
| 38 |
+
|
| 39 |
+
Input:
|
| 40 |
+
- Text Passage: [INPUT TEXT]
|
| 41 |
+
|
| 42 |
+
Response:
|
| 43 |
+
```
|
| 44 |
+
|
| 45 |
+
## Citation
|
| 46 |
+
If you use this model, please cite our paper:
|
| 47 |
+
|
| 48 |
+
```
|
| 49 |
+
@article{lekssays2025azerg,
|
| 50 |
+
title={From Text to Actionable Intelligence: Automating STIX Entity and Relationship Extraction},
|
| 51 |
+
author={Lekssays, Ahmed and Sencar, Husrev Taha and Yu, Ting},
|
| 52 |
+
journal={arXiv preprint arXiv:2507.16576},
|
| 53 |
+
year={2025}
|
| 54 |
+
}
|
| 55 |
+
```
|