Autonomous Cyber Incident Response Using Reasoning and Action
Sudipto Baral, Sajal Saha, Anwar ul Haque · 2025
The increasing complexity and frequency of cyber threats necessitate autonomous security solutions capable of real-time detection, reasoning, and response. This paper introduces an autonomous cyber incident response framework that integrates Reasoning and Acting (ReAct) agents with Large Language Models (LLMs) to enhance cybersecurity decision-making. The proposed system features a cloud-based testbed, real-time monitoring tools (Wazuh, Suricata), and a NATS messaging system for seamless threat detection and mitigation. The ReAct agent, powered by a fine-tuned LLM, iteratively analyzes security alerts, generates context-aware mitigation strategies, and autonomously executes response actions via integrated cybersecurity tools such as firewalls. The framework demonstrates its effectiveness in real-time cyberattack mitigation, including port scanning, botnet intrusions, and SSH brute-force attacks. By leveraging LangGraph-guided decision loops and Chain-of-Thought (CoT) reasoning, the system dynamically adapts to evolving threats while reducing reliance on human intervention. Evaluations in a simulated environment highlight the scalability of the architecture and its ability to achieve low-latency, autonomous threat mitigation. The findings highlight the potential of LLM-driven security automation in modern cyber defense strategies, paving the way for future advancements in mitigating phishing, malware, and insider threats.