Section 01
[Introduction] Analisa: Core Introduction to the Intelligent Assistant for SOC Threat Hunting
This article introduces the Analisa project, an LLM-integrated system developed by the Threat Hunting Division of CyberSecurity Malaysia (MyCERT), designed specifically for Security Operations Centers (SOCs). Using natural language processing technology, it helps threat hunting teams quickly analyze Elasticsearch telemetry data, classify security alerts, and generate investigation playbooks. This addresses the conflict between massive alerts and limited human resources, improving the efficiency of security analysis.