[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-llms-still-struggle-to-extract-threat-clues-from-malicious-scripts":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},6222,"llms-still-struggle-to-extract-threat-clues-from-malicious-scripts","LLMs Still Struggle to Extract Threat Clues From Malicious Scripts","A new benchmark shows even top language models top out around 65 F1 when pulling IOCs from real malware scripts without running them.","A fresh benchmark finds that large language models still can't reliably pull threat indicators out of malicious scripts without running them.\n\nResearchers built SCRIPTIOC-BENCH, a set of 634 manually verified JavaScript, PowerShell, and VBScript malware samples, to test how well LLMs can statically extract indicators of compromise - URLs, domains, IP addresses, and filesystem artifacts - without executing the code. They graded models on whether IOCs were directly exposed in the script or buried behind encoding and obfuscation that required reconstruction. Across a range of proprietary and open-weight models, the best performer topped out at 65.4 F1, a measure that balances precision and recall. The team also built a taxonomy of false positives and tested two fixes on a small open-weight model - deterministic string utilities and task-specific fine-tuning - which improved precision and shifted remaining errors toward ones grounded in the actual sample.\n\nSecurity teams increasingly lean on LLMs to triage script-based malware, one of the most common delivery methods for phishing payloads and living-off-the-land attacks. A 65.4 F1 ceiling means even the best model still misses or mislabels roughly a third of the actionable intelligence analysts need to block a domain or flag a malicious IP - not a rounding error when minutes matter during an incident. The findings also suggest static analysis alone isn't enough; the paper's own mitigations point toward pairing LLMs with deterministic tooling and targeted fine-tuning rather than expecting a general-purpose model to catch everything.\n\nTreat any vendor pitch promising fully automated IOC extraction with the same skepticism you'd apply to a script claiming to be a PDF.","[\"llm-security\",\"malware-analysis\",\"benchmark\",\"threat-intelligence\"]","2026-09-10T04:00:00.000Z","2026-09-10T07:15:21.480Z","2026-09-10T07:15:33.402Z","published",null,[],"security",[26,27,28,29],"llm-security","malware-analysis","benchmark","threat-intelligence",[31],{"name":32,"url":33},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2609.06149",0,{"sections":36},[37,42,45,50,55,60,65,69,74,79,84,89,94,99],{"name":38,"slug":39,"count":40,"latest_published_at":41},"AI","ai",3480,"2026-09-11T04:00:00.000Z",{"name":43,"slug":24,"count":44,"latest_published_at":41},"Security",628,{"name":46,"slug":47,"count":48,"latest_published_at":49},"Policy","policy",336,"2026-09-11T00:56:21.000Z",{"name":51,"slug":52,"count":53,"latest_published_at":54},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":56,"slug":57,"count":58,"latest_published_at":59},"Hardware","hardware",153,"2026-09-09T15:12:32.000Z",{"name":61,"slug":62,"count":63,"latest_published_at":64},"Consumer Tech","consumer-tech",99,"2026-09-09T17:27:33.000Z",{"name":66,"slug":67,"count":68,"latest_published_at":41},"Science","science",98,{"name":70,"slug":71,"count":72,"latest_published_at":73},"Software","software",75,"2026-09-10T20:41:21.000Z",{"name":75,"slug":76,"count":77,"latest_published_at":78},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":80,"slug":81,"count":82,"latest_published_at":83},"Startups","startups",55,"2026-09-09T23:14:29.000Z",{"name":85,"slug":86,"count":87,"latest_published_at":88},"Gaming","gaming",43,"2026-09-10T12:18:06.000Z",{"name":90,"slug":91,"count":92,"latest_published_at":93},"General","general",41,"2026-09-08T01:57:23.000Z",{"name":95,"slug":96,"count":97,"latest_published_at":98},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":100,"slug":101,"count":102,"latest_published_at":103},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]