Transformation of Cybersecurity Playbooks into CACAO Format -
arxiv.org/pdf/2508.03342
Existing cybersecurity playbooks are often written in heterogeneous, non-machine-readable formats, which limits their automation and interoperability across Security Orchestration, Automation, and Response platforms. This paper explores the suitability of Large Language Models, combined with Prompt Engineering, to automatically translate legacy incident response playbooks into the standardized, machine readable CACAO format.
Authors:
@stefanjdecker,
@matzutt Mehdi Akbari Gurabi, Lasse Nitz, Radu-Mihai Castravet, Roman Matzutt, Avikarsha Mandal, Stefan Decker /
@Fraunhofer_FIT @knowpipelines @RWTH
#Cybersecurity #Automation #IncidentResponse #CACAO #PromptEngineering #LLMIntegration #WorkflowAutomation #SecurityStandards #MachineLearning #SemanticAccuracy #SyntacticValidation #KnowledgeInjection #TaskDecomposition #SOARPlatforms #PlaybookAutomation #AIinSecurity #GraphSimilarity #DataStandardization #ThreatResponse #LegacyMigration #JSONValidation #AISecurity @OASISopen