Research objective
This research reviews how large language models may assist analysts during triage, threat hunting, incident explanation and reporting.
Evaluation questions
- Which tasks can be accelerated without lowering investigation quality?
- How should model output be grounded in security evidence?
- What hallucination, privacy and prompt-injection risks must be managed?
- Which actions require explicit analyst approval?
- How should usefulness and trust be evaluated in realistic workflows?
Working position
Language models should be treated as assistance tools rather than authoritative sources. Their output must remain reviewable, bounded and connected to the evidence supplied by the security workflow.