arXiv Artificial Intelligence

Effective and Efficient Threat Hunting with Small Language Models

Effective and Efficient Threat Hunting with Small Language Models

Quick summary

arXiv:2512.06660v3 Announce Type: replace-cross Abstract: Analysts in Security Operations Centers query massive telemetry streams using Kusto Query Language (KQL), but writing correct KQL demands specialized expertise that bottlenecks scaling security teams. We investigate how Small Language Models (SLMs) can enable accurate, cost-effective translation from natural language queries (NLQs) to KQL. We propose a three-knob framework spanning prompting, fine-tuning, and architecture. First, we adapt NL2KQL for SLMs with lightweight retrieval and introduce error-aware prompting that targets common

Key takeaways

  • arXiv:2512.06660v3 Announce Type: replace-cross Abstract: Analysts in Security Operations Centers query massive telemetry streams using Kusto Query Language (KQL), but writing correct KQL demands specialized expertise that bottlenecks scaling security teams.
  • We investigate how Small Language Models (SLMs) can enable accurate, cost-effective translation from natural language queries (NLQs) to KQL.
  • We propose a three-knob framework spanning prompting, fine-tuning, and architecture.

Why it matters

This development is a reminder to test misuse and data-leak scenarios alongside speed and quality. Trust should come from testable controls and clear failure reporting, not protection claims alone.

Kaynak sitede devamını oku: arXiv Artificial Intelligence ↗