Reducing Mean Time To Respond Using Large Language Model-Driven Incident Response with the Aid of Reactively Retrieved Threat Intelligence
Ayad Zewail, Youssef Abdulghany, Moataz Samy · 2025
Rapid response time is of paramount importance in cybersecurity incident response, yet it is currently inadequate for the growing threat landscape. Manual mitigation efforts alone are no longer sufficient to preserve network security and neutralize emerging threats, which calls for a more automated approach to incident response. This paper proposes, implements, and evaluates a new pipeline that combines web scraping for reactive threat-mitigation instruction retrieval with a custom fine-tuned Large Language Model, specifically the Llama-3.1-8B-Lexi-Uncensored-V2 model, trained to take actions based on the retrieved instructions, which are automatically implemented by the Security Orchestration, Automation, and Response Tool. This technique promises a reduction in the Mean Time To Respond for some attacks from an average of tens of minutes to approximately 25 seconds. The study expounds upon the exact methodologies used for web scraping and Large Language Model fine-tuning and exhibits the effectiveness and efficiency of their synergy.