Unveiling the Frontiers of Cyber Threat Hunting: A Comprehensive Review of LLM-Based Approaches

Authors

  • Dilkhaz Mohammed University of Mohaghegh Ardabili, Iran
  • Shahram Jamali University of Mohaghegh Ardabili, Iran

DOI:

https://doi.org/10.4114/intartif.vol29iss78pp59-83

Keywords:

Cybersecurity Automation, Cyber Threat Hunting, Artificial Intelligence, Large Language Models (LLMs), Incident Response

Abstract

The dynamic and ever-evolving cyber threat landscape necessitates proactive and sophisticated defensive strategies. Cyber threat hunting, a critical practice, moves beyond reactive security measures. It actively searches for undetected malicious activities. Traditionally reliant on human expertise and structured data analysis, threat hunting is increasingly augmented and transformed by the capabilities of artificial intelligence (AI) and machine learning (ML). Among the latest advancements, large language models (LLMs) have emerged as powerful tools with significant potential to revolutionize how cybersecurity professionals detect, analyze, and respond to threats. This paper presents a comprehensive and systematic review of the state-of-the-art LLM-based approaches for cyber threat hunting, focusing significantly on research published in 2025 and grounding these advances in foundational work published before 2023. We explore the diverse applications of LLMs throughout the threat-hunting lifecycle, including advanced cyber threat intelligence (CTI) analysis, real-time anomaly detection, incident response enhancement, and vulnerability prediction. Furthermore, we examine the foundational AI and LLM concepts driving these innovations. We delve into emergent datasets and evaluation methodologies crucial for progress and critically assess the substantial challenges, limitations, and ethical considerations such as robustness, explainability, data privacy, and adversarial vulnerabilities that are inherent in their deployment. Our review provides a novel synthesis of recent Large Language Model (LLM) applications in threat hunting and identifies critical research gaps. Additionally, it presents a refined perspective on the practical implementation and future trajectory of these technologies.

Downloads

Download data is not yet available.

Metrics

Metrics Loading ...

Author Biography

Shahram Jamali, University of Mohaghegh Ardabili, Iran

Shahram Jamali is an associate professor leading the Autonomic Networking Group at the Department of Engineering, University of Mohaghegh Ardabili. He teaches on computer networks, network security, computer architecture and computer syetems performance evaluation. Dr. Jamali received his M.Sc. and Ph.D. degree from the Dept. of Computer Engineering, Iran University of Science and Technology in 2001 and 2007, respectively. Since 2008, he is with Department of Computer Engineering, University of Mohaghegh Ardabil and has published more than 100 conference and journal papers.

Downloads

Published

2026-07-22

How to Cite

Mohammed, D., & Jamali, S. (2026). Unveiling the Frontiers of Cyber Threat Hunting: A Comprehensive Review of LLM-Based Approaches. Inteligencia Artificial, 29(78), 59–83. https://doi.org/10.4114/intartif.vol29iss78pp59-83