Evolving Cyber Threat Intelligence: A Systematic Review and Comparative Analysis
Authors
Faculty of Artificial Intelligence, Universiti Teknologi Malaysia, Kuala Lumpur, Malaysia (Saudi Arabia)
Faculty of Artificial Intelligence, Universiti Teknologi Malaysia, Kuala Lumpur, Malaysia (Malaysia)
Faculty of Artificial Intelligence, Universiti Teknologi Malaysia, Kuala Lumpur, Malaysia (Malaysia)
Center of Cybersecurity, Faculty of science information and Technology, National University of Malaysia (Malaysia)
Article Information
DOI: 10.51244/IJRSI.2026.1307000326
Subject Category: Computer Science
Volume/Issue: 13/7 | Page No: 4445-4478
Publication Timeline
Submitted: 2026-08-05
Accepted: 2026-08-10
Published: 2026-08-18
Abstract
To improve cybersecurity across industries, Cyber Threat Intelligence (CTI) is becoming increasingly crucial. This systematic review explores how CTI practices are evolving in response to advancements in Artificial Intelligence (AI), particularly in the context of Large Language Models (LLMs). We examined 61 peer-reviewed studies using the PRISMA methodology, which demonstrates a strict selection procedure founded on specified inclusion, exclusion, and quality standards. This approach aligns with the scope of similar systematic reviews in the field of cyber threat intelligence. The review provides a comparative synthesis of CTI research capabilities across threat detection and prediction, attribution, forecasting, and automated reporting. We classify these approaches into three categories: conventional methods, those enhanced by AI and Machine Learning, and those based on LLMs. Our findings indicate that LLMs offer significant advantages in contextual reasoning, processing unstructured threat intelligence, and generating actionable mitigation plans. However, challenges such as model explainability, data privacy, system interoperability, and standardization impede their integration into operational environments. In addition to highlighting the potential and practical limitations of LLMs in CTI, this study identifies research gaps and proposes methods to create scalable, secure, and flexible CTI systems that support real-time cyber defense.
Keywords
cyber threat intelligence; artificial intelligence; cybersecurity; threat detection; threat prediction; large language models
Downloads
References
1. Tounsi, W., & Rais, H. (2018). A survey on technical threat intelligence in the age of sophisticated cyber attacks. Computers & security, 72, 212-233. [Google Scholar] [Crossref]
2. Sharif, M. H. U., & Mohammed, M. A. (2022). A literature review of financial losses statistics for cyber security and future trend. World Journal of Advanced Research and Reviews, 15(1), 138-156. [Google Scholar] [Crossref]
3. Ainslie, S., Thompson, D., Maynard, S., & Ahmad, A. (2023). Cyber-Threat Intelligence for Security Decision-Making: A Review and Research Agenda for Practice. Computers & Security, 103352. [Google Scholar] [Crossref]
4. Kotsias, J., Ahmad, A., & Scheepers, R. (2023). Adopting and integrating cyber-threat intelligence in a commercial organisation. European Journal of Information Systems, 32(1), 35-51. [Google Scholar] [Crossref]
5. PwC. (2024). PwC's 24th Annual Global CEO Survey: CEOs on their tech concerns., Report by PwC annual survey of CEO on IT or technology concerns. . https://www.pwc.com/gx/en/issues/c-suite-insights/ceo-survey.html [Google Scholar] [Crossref]
6. Lin, P. C., Hsu, W. H., Lin, Y. D., Hwang, R. H., Wu, H. K., Lai, Y. C., & Chen, C. K. (2023). Correlation of cyber threat intelligence with sightings for intelligence assessment and augmentation. Computer Networks, 228, 109736. [Google Scholar] [Crossref]
7. Saeed, S., Suayyid, S. A., Al-Ghamdi, M. S., Al-Muhaisen, H., & Almuhaideb, A. M. (2023). A systematic literature review on cyber threat intelligence for organizational cybersecurity resilience. Sensors, 23(16), 7273. [Google Scholar] [Crossref]
8. Page, M. J., McKenzie, J. E., Bossuyt, P. M., Boutron, I., Hoffmann, T. C., Mulrow, C. D., ... & Moher, D. (2021). The PRISMA 2020 statement: an updated guideline for reporting systematic reviews. International journal of surgery, 88, 105906. [Google Scholar] [Crossref]
9. Zhang, S., Chen, P., Bai, G., Wang, S., Zhang, M., Li, S., & Zhao, C. (2022). An automatic assessment method of cyber threat intelligence combined with ATT&CK matrix. Wireless Communications and Mobile Computing, 2022. [Google Scholar] [Crossref]
10. Serketzis, N., Katos, V., Ilioudis, C., Baltatzis, D., & Pangalos, G. (2019). Improving forensic triage efficiency through cyber threat intelligence. Future Internet, 11(7), 162. [Google Scholar] [Crossref]
11. Chatziamanetoglou, D., & Rantos, K. (2023). Blockchain-Based Cyber Threat Intelligence Sharing Using Proof-of-Quality Consensus. Security and Communication Networks, 2023. [Google Scholar] [Crossref]
12. Kia, A. N., Murphy, F., Sheehan, B., & Shannon, D. (2024). A cyber risk prediction model using common vulnerabilities and exposures. Expert Systems with Applications, 237, 121599. [Google Scholar] [Crossref]
13. Borges Amaro, L. J., Percilio Azevedo, B. W., Lopes de Mendonca, F. L., Giozza, W. F., Albuquerque, R. D. O., & García Villalba, L. J. (2022). Methodological framework to collect, process, analyze and visualize cyber threat intelligence data. Applied Sciences, 12(3), 1205. [Google Scholar] [Crossref]
14. Li, Z., Zeng, J., Chen, Y., & Liang, Z. (2022, September). AttacKG: Constructing technique knowledge graph from cyber threat intelligence reports. In European Symposium on Research in Computer Security (pp. 589-609). Cham: Springer International Publishing. [Google Scholar] [Crossref]
15. Sakellariou, G., Fouliras, P., & Mavridis, I. (2023). SECDFAN: A Cyber Threat Intelligence System for Discussion Forums Utilization. Eng, 4(1), 615-634. [Google Scholar] [Crossref]
16. Sacher-Boldewin, D., & Leverett, E. (2022). The Intelligent Process Lifecycle of Active Cyber Defenders. Digital Threats: Research and Practice (DTRAP), 3(3), 1-17. [Google Scholar] [Crossref]
17. Mendez Mena, D., & Yang, B. (2021). Decentralized actionable cyber threat intelligence for networks and the internet of things. IoT, 2(1), 1-16. https://doi.org/10.3390/iot2010001 [Google Scholar] [Crossref]
18. Gong, S., & Lee, C. (2020). Blocis: blockchain-based cyber threat intelligence sharing framework for sybil-resistance. Electronics, 9(3), 521. [Google Scholar] [Crossref]
19. Chen, T., Zeng, H., Lv, M., & Zhu, T. (2024). CTIMD: Cyber threat intelligence enhanced malware detection using API call sequences with parameters. Computers & Security, 136, 103518. [Google Scholar] [Crossref]
20. Irshad, E., & Siddiqui, A. B. (2023). Cyber threat attribution using unstructured reports in cyber threat intelligence. Egyptian Informatics Journal, 24(1), 43-59. [Google Scholar] [Crossref]
21. Sufi, F. (2023). A New Social Media-Driven Cyber Threat Intelligence. Electronics, 12(5), 1242. [Google Scholar] [Crossref]
22. Sarhan, M., Layeghy, S., Moustafa, N., & Portmann, M. (2023). Cyber threat intelligence sharing scheme based on federated learning for network intrusion detection. Journal of Network and Systems Management, 31(1), 3. [Google Scholar] [Crossref]
23. Bayer, M., Frey, T., & Reuter, C. (2023). Multi-level fine-tuning, data augmentation, and few-shot learning for specialized cyber threat intelligence. Computers & Security, 134, 103430. [Google Scholar] [Crossref]
24. Keim, Y., & Mohapatra, A. K. (2022). Cyber threat intelligence framework using advanced malware forensics. International Journal of Information Technology, 14(1), 521-530. [Google Scholar] [Crossref]
25. Gao, P., Liu, X., Choi, E., Ma, S., Yang, X., Ji, Z., ... & Song, D. (2022). ThreatKG: A Threat Knowledge Graph for Automated Open-Source Cyber Threat Intelligence Gathering and Management. arXiv preprint arXiv:2212.10388. [Google Scholar] [Crossref]
26. Koloveas, P., Chantzios, T., Alevizopoulou, S., Skiadopoulos, S., & Tryfonopoulos, C. (2021). intime: A machine learning-based framework for gathering and leveraging web data to cyber-threat intelligence. Electronics, 10(7), 818. [Google Scholar] [Crossref]
27. Zhao, J., Yan, Q., Li, J., Shao, M., He, Z., & Li, B. (2020). TIMiner: Automatically extracting and analyzing categorized cyber threat intelligence from social data. Computers & Security, 95, 101867. [Google Scholar] [Crossref]
28. Kristiansen, L. M., Agarwal, V., Franke, K., & Shah, R. S. (2020, December). CTI-Twitter: gathering cyber threat intelligence from twitter using integrated supervised and unsupervised learning. In 2020 IEEE International Conference on Big Data (Big Data) (pp. 2299-2308). IEEE. [Google Scholar] [Crossref]
29. Liu, J., Yan, J., Jiang, J., He, Y., Wang, X., Jiang, Z., ... & Li, N. (2022). TriCTI: an actionable cyber threat intelligence discovery system via trigger-enhanced neural network. Cybersecurity, 5(1), 8. [Google Scholar] [Crossref]
30. Gao, Y., Li, X., Peng, H., Fang, B., & Philip, S. Y. (2020). Hincti: A cyber threat intelligence modeling and identification system based on heterogeneous information network. IEEE Transactions on Knowledge and Data Engineering, 34(2), 708-722. [Google Scholar] [Crossref]
31. Suryotrisongko, H., Musashi, Y., Tsuneda, A., & Sugitani, K. (2022). Robust botnet DGA detection: Blending XAI and OSINT for cyber threat intelligence sharing. IEEE Access, 10, 34613-34624. [Google Scholar] [Crossref]
32. Jiang, T., Shen, G., Guo, C., Cui, Y., & Xie, B. (2023). BFLS: Blockchain and Federated Learning for sharing threat detection models as Cyber Threat Intelligence. Computer Networks, 224, 109604. [Google Scholar] [Crossref]
33. Zhou, Y., Tang, Y., Yi, M., Xi, C., & Lu, H. (2022). CTI view: APT threat intelligence analysis system. Security and Communication Networks, 2022, 1-15. [Google Scholar] [Crossref]
34. Perrina, F., Marchiori, F., Conti, M., & Verde, N. V. (2023, December). AGIR: Automating Cyber Threat Intelligence Reporting with Natural Language Generation. In 2023 IEEE International Conference on Big Data (BigData) (pp. 3053-3062). IEEE. [Google Scholar] [Crossref]
35. Ferrag, M. A., Ndhlovu, M., Tihanyi, N., Cordeiro, L. C., Debbah, M., & Lestable, T. (2023). Revolutionizing Cyber Threat Detection with Large Language Models. arXiv preprint arXiv:2306.14263. [Google Scholar] [Crossref]
36. Moskal, S., Laney, S., Hemberg, E., & O'Reilly, U. M. (2023). LLMs Killed the Script Kiddie: How Agents Supported by Large Language Models Change the Landscape of Network Threat Testing. arXiv preprint arXiv:2310.06936. [Google Scholar] [Crossref]
37. Hu, Y., Zou, F., Han, J., Sun, X., & Wang, Y. (2024). Llm-Tikg: Threat Intelligence Knowledge Graph Construction Utilizing Large Language Model. Computers & Security, 145, 103999. https://doi.org/10.1016/j.cose.2024.103999. [Google Scholar] [Crossref]
38. Siracusano, G., Sanvito, D., Gonzalez, R., Srinivasan, M., Kamatchi, S., Takahashi, W., ... & Bifulco, R. (2023). Time for aCTIon: Automated Analysis of Cyber Threat Intelligence in the Wild. arXiv preprint arXiv:2307.10214. [Google Scholar] [Crossref]
39. Sewak, M., Emani, V., & Naresh, A. (2023). CRUSH: Cybersecurity Research using Universal LLMs and Semantic Hypernetworks. [Google Scholar] [Crossref]
40. Rahman, M. R., Wroblewski, B., Matthews, Q., Morgan, B., Menzies, T., & Williams, L. (2024). Mining Temporal Attack Patterns from Cyberthreat Intelligence Reports. arXiv preprint arXiv:2401.01883. [Google Scholar] [Crossref]
41. Ferrag, M. A., Ndhlovu, M., Tihanyi, N., Cordeiro, L. C., Debbah, M., Lestable, T., & Thandi, N. S. (2024). Revolutionizing Cyber Threat Detection with Large Language Models: A privacy-preserving BERT-based Lightweight Model for IoT/IIoT Devices. IEEE Access. [Google Scholar] [Crossref]
42. Mitra, S., Neupane, S., Chakraborty, T., Mittal, S., Piplai, A., Gaur, M., & Rahimi, S. (2024). LOCALINTEL: Generating Organizational Threat Intelligence from Global and Local Cyber Knowledge. arXiv preprint arXiv:2401.10036. [Google Scholar] [Crossref]
43. Shafee, S., Bessani, A., & Ferreira, P. M. (2024). Evaluation of LLM Chatbots for OSINT-based Cyberthreat Awareness. arXiv preprint arXiv:2401.15127. [Google Scholar] [Crossref]
44. Garza, E., Hemberg, E., Moskal, S., & O’Reilly, U. M. (2023). Assessing Large Language Model’s knowledge of threat behavior in MITRE ATT&CK. [Google Scholar] [Crossref]
45. Chan, C. F., Yip, D. W., & Esmradi, A. (2024). Detection and Defense Against Prominent Attacks on Preconditioned LLM-Integrated Virtual Assistants. arXiv preprint arXiv:2401.00994. [Google Scholar] [Crossref]
46. Iqbal, Z., & Anwar, Z. (2020). SCERM—A novel framework for automated management of cyber threat response activities. Future Generation Computer Systems, 108, 687-708. [Google Scholar] [Crossref]
47. Mohan, J. S., Thirunavukkarasu, M., Kumaran, N., & Thamaraiselvi, D. (2024). Deep Learning with Blockchain Based Cyber Security Threat Intelligence and Situational Awareness System for Intrusion Alert Prediction. Sustainable Computing: Informatics and Systems, 100955. [Google Scholar] [Crossref]
48. Ahmed, K., Khurshid, S. K., & Hina, S. (2024). CyberEntRel: Joint extraction of cyber entities and relations using deep learning. Computers & Security, 136, 103579. [Google Scholar] [Crossref]
49. Jo, H., Lee, Y., & Shin, S. (2022). Vulcan: Automatic extraction and analysis of cyber threat intelligence from unstructured text. Computers & Security, 120, 102763. [Google Scholar] [Crossref]
50. Zacharis, A., Katos, V., & Patsakis, C. (2024). Integrating AI-driven threat intelligence and forecasting in the cybersecurity exercise content generation lifecycle. International Journal of Information Security, 23, 2691–2710. https://doi.org/10.1007/s10207-024-00860-w [Google Scholar] [Crossref]
51. B. D. Le, G. Wang, M. Nasim, and M. A. Babar, “Gathering Cyber Threat Intelligence from Twitter Using Novelty Classification,” in Proc. 2019 Int. Conf. Cyberworlds (CW), 2019, pp. 316–323. [Online]. Available: https://doi.org/10.1109/CW.2019.00058 [Google Scholar] [Crossref]
52. Kaspersky, “What is an Advanced Persistent Threat (APT)?,” Kaspersky, 2023. [Online]. Available: https://www.kaspersky.com/resource-center/threats/advanced-persistent-threats. [Accessed: Jul. 5, 2025]. [Google Scholar] [Crossref]
53. C.Whitman,“Leveraging cyber threat intelligence mining for enhanced proactive cybersecurity: A comprehensive review and future directions,” [Google Scholar] [Crossref]
54. International Journal of Cyber Threat Intelligence and Secure Networking, pp. 14–19, Dec. 15, 2024. [Google Scholar] [Crossref]
55. P. Santos, R. Abreu, M. J. C. S. Reis, C. Serôdio, and F. Branco, [Google Scholar] [Crossref]
56. “A systematic review of cyber threat intelligence: The effectiveness of technologies, strategies, and collaborations in combating modern threats,” [Google Scholar] [Crossref]
57. Sensors, vol. 25, no. 14, Art. no. 4272, Jul. 2025, doi: 10.3390/s25144272. [Google Scholar] [Crossref]
58. G. Cascavilla, S. Gupta, F. Massacci, and J. Camacho, [Google Scholar] [Crossref]
59. “Cybercrime threat intelligence: A systematic multi-vocal literature review,” [Google Scholar] [Crossref]
60. Computers & Security, vol. 105, Art. no. 102442, Jun. 2021, doi: 10.1016/j.cose.2021.102442. [Google Scholar] [Crossref]
61. A. Tolah, "BlockIntelChain: A blockchain-based cyber threat intelligence sharing framework," Scientific Reports, vol. 15, Art. no. 29152, 2025. [Online]. Available: [Google Scholar] [Crossref]
62. H. El Amin, A. E. Samhat, M. Chamoun, and L. Oueidat, "An integrated approach to cyber risk management with cyber threat intelligence framework to secure critical infrastructure," Journal of Cybersecurity and Privacy, vol. 4, no. 2, Art. no. 18, 2024. [Online]. Available: [Google Scholar] [Crossref]
63. A. Mahida and A. Tyagi, "Cyber threat intelligence and information sharing in cloud ecosystems," Proceedings on Engineering, vol. 7, no. 1, pp. 1–12, 2025. [Online]. Available: [Google Scholar] [Crossref]
64. P. Fuxen, M. Hachani, R. Hackenberg, and M. Ross, "MANTRA: Towards a conceptual framework for elevating cybersecurity applications through privacy-preserving cyber threat intelligence sharing," in Proc. 15th Int. Conf. Cloud Computing, GRIDs, and Virtualization (CLOUD COMPUTING 2024 ), 2024, pp. 44–50. [Google Scholar] [Crossref]
65. D. M. Janosek, "Toward a global framework for cyber threat intelligence sharing," Cyber Defense Review, vol. 10, no. 2, 2025. [Online]. Available: [Google Scholar] [Crossref]
66. Y. Zhou et al., "A blockchain based efficient incentive mechanism in cyber threat intelligence sharing," Journal of Information Security and Applications, vol. 82, Art. no. 103769, 2025. [Online]. Available: [Google Scholar] [Crossref]
67. J. Komarthi, "Optimizing threat intelligence sharing across multiple security platforms," Emerging Frontiers Library for The American Journal of Engineering and Technology, vol. 3, no. 1, Art. no. 552, 2025. [Google Scholar] [Crossref]
68. Varbanov, V., et al. (2024). Advancing cyber threat intelligence through machine learning algorithms. ACM International Conference on Computing Frontiers, Art. no. 3660879. https://dl.acm.org/doi/fullHtml/10.1145/3660853.3660879 [Google Scholar] [Crossref]
69. Demirol, D., et al. (2025). A novel approach for cyber threat analysis systems using BERT model from cyber threat intelligence data. Symmetry, 17(4), 587. https://www.mdpi.com/2073-8994/17/4/587 [Google Scholar] [Crossref]
70. Ragab, M., et al. (2025). Advanced artificial intelligence with federated learning framework for privacy-preserving cyberthreat detection in IoT-assisted sustainable smart cities. Scientific Reports, 15, Art. no. 88843. https://www.nature.com/articles/s41598-025-88843-2 [Google Scholar] [Crossref]
71. Hamad, N. A., et al. (2025). Systematic analysis of federated learning approaches for cybersecurity. IEEE Access, 13, 1–15. https://ieeexplore.ieee.org/document/11017512/ [Google Scholar] [Crossref]
72. Koball, C., et al. (2024). Machine learning security: Threat model, attacks, and defenses. Computer, 57(10), 42–51. https://www.computer.org/csdl/magazine/co/2024/10/10687326/ [Google Scholar] [Crossref]
73. Robinette, P. K., et al. (2024). Neural network malware detection verification for feature robustness. arXiv preprint, arXiv:2404.05703. https://arxiv.org/abs/2404.05703 [Google Scholar] [Crossref]
74. Mouiche and S. Saad, "Entity and relation extractions for threat intelligence knowledge graphs," Computers & Security, vol. 148, Art. no. 104255, 2025. https://www.sciencedirect.com/science/article/pii/S0167404824004255 [Google Scholar] [Crossref]
75. M. Motlagh, A. Hajizadeh, and M. Raahemi. (2024). Large language models in cybersecurity: State-of-the-art and future directions. https://arxiv.org/abs/2402.00891 [Google Scholar] [Crossref]
76. H. Kheddar, Y. Himeur, S. Al-Maadeed, A. Amira, and F. Bensaali. (2024). Transformers and large language models for efficient intrusion detection systems: A comprehensive survey. arXiv preprint, arXiv:2408.07583. [Google Scholar] [Crossref]
77. G. Liu, K. Lu, and S. Pi, “Graph neural networks embedded with domain knowledge for cyber threat intelligence entity and relationship mining,” PeerJ Computer Science, vol. 11, p. e2769, 2025, doi: 10.7717/peerj-cs.2769. [Google Scholar] [Crossref]
78. Y. Hmimou, M. Tabaa, A. Khiat, and Z. Hidila, “A multi-agent system for cybersecurity threat detection and correlation using large language models,” IEEE Access, vol. 13, pp. 150199-150214, 2025, doi: 10.1109/ACCESS.2025.3602681. [Google Scholar] [Crossref]
79. E. M. Hutchins, M. J. Cloppert, and R. M. Amin, “Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains,” Lockheed Martin Corporation, White Paper, 2011. [Google Scholar] [Crossref]
80. P. Balasubramanian, S. Nazari, D. K. Khlogh, A. Mahmoodi, J. Seby, and P. Kostakos, “A cognitive platform for collecting cyber threat intelligence and real-time detection using cloud computing,” Decision Analytics Journal, vol. 14, p. 100545, 2025, doi: 10.1016/j.dajour.2025.100545. [Google Scholar] [Crossref]
81. P. Xiao, “Malware cyber threat intelligence system for Internet of Things (IoT) using machine learning,” Journal of Cyber Security and Mobility, vol. 13, no. 1, pp. 53–90, Dec. 2023, doi: 10.13052/jcsm2245-1439.1313. [Google Scholar] [Crossref]
Metrics
Views & Downloads
Similar Articles
- What the Desert Fathers Teach Data Scientists: Ancient Ascetic Principles for Ethical Machine-Learning Practice
- Comparative Analysis of Some Machine Learning Algorithms for the Classification of Ransomware
- Comparative Performance Analysis of Some Priority Queue Variants in Dijkstra’s Algorithm
- Transfer Learning in Detecting E-Assessment Malpractice from a Proctored Video Recordings.
- Dual-Modal Detection of Parkinson’s Disease: A Clinical Framework and Deep Learning Approach Using NeuroParkNet