ARTFEED — Contemporary Art Intelligence

TRACE-CTI: A Framework for Auditable TTP Claim Governance

other · 2026-07-29

A new framework called TRACE-CTI addresses the challenge of trusting automated mappings of Cyber Threat Intelligence reports to MITRE ATT&CK. It preserves run-level predictions, aggregates them into configuration-level GraphAssertions, materializes corroboration as ConsensusAssertions, and exposes only policy-compliant GraphAssertions. The framework retains evidence granularity, extraction provenance, versioned trust decisions, and non-destructive revocation history. Evaluated on two public CTI corpora with 65 reports and 5,303 sentences using a controlled 2x3 matrix of retrievers and generator families.

Key facts

  • TRACE-CTI is a post-extraction claim-governance framework for CTI reports mapped to MITRE ATT&CK.
  • It preserves run-level predictions and aggregates them into GraphAssertions.
  • Corroboration is materialized as ConsensusAssertions.
  • Only policy-compliant GraphAssertions are exposed.
  • Framework retains evidence granularity, extraction provenance, versioned trust decisions, and non-destructive revocation history.
  • Evaluated on two public CTI corpora with 65 reports and 5,303 sentences.
  • Used a controlled 2x3 matrix of retrievers and generator families.
  • Addresses the need for auditable governance of TTP claims.

Entities

Institutions

  • MITRE
  • Security Operations Centers

Sources