Open Access iconOpen Access

ARTICLE

Large Language Model-Assisted Threat-Driven Testing System for Enhanced Cybersecurity Readiness

Praise Emeka Nze*, Adeniran Kolade Ademuwagun, Muktar Bello, Fortune Daberechi Ifeanyi, Samaila Musa Abdullahi, John Tighil

Department of Cyber Security, Air Force Institute of Technology, Kaduna, Nigeria

* Corresponding Author: Praise Emeka Nze. Email: email

Journal of Cyber Security 2026, 8, 469-486. https://doi.org/10.32604/jcs.2026.083943

Abstract

The rapid evolution of adversarial cyber threats demands proactive, scalable security testing methodologies capable of producing realistic, organization-specific attack scenarios. Conventional approaches, including manual red-teaming, scripted Breach and Attack Simulation (BAS) platforms, and tabletop exercises, are constrained by high expert dependency, limited scenario variability, and an inability to dynamically adapt to an organization’s unique threat profile. This paper proposes and evaluates a Large Language Model (LLM)-Assisted Threat-Driven Testing System that integrates the MITRE Adversarial Tactics, Techniques, and Common Knowledge (MITRE ATT&CK) framework v14, a structured knowledge base of adversarial tactics, techniques, and procedures (TTPs), with GPT-based language models accessed through the OpenAI API, to automate the generation of contextually tailored cyber-attack narratives. The system employs a service-oriented architecture implemented in Python, utilizing Streamlit for the interactive web interface, Pandas for ATT&CK data management, and LangChain as the prompt-orchestration middleware. Evaluation encompassed structured feedback surveys from 30 cybersecurity professionals representing security operations, red-teaming, and incident response roles, together with quantitative analysis using three performance metrics: ATT&CK Technique Coverage (ATC = 85%), False Positive Rate (FPR = 3.2%), and False Negative Rate (FNR = 11%). These results confirm that the system achieves high scenario fidelity, strong ATT&CK alignment, and a generation latency of 2–8 s per scenario. Practically, the framework enables security teams, particularly resource-constrained organizations lacking dedicated red-team capabilities, to conduct high-fidelity threat simulation exercises aligned with current adversarial TTPs, without specialized AI expertise, thereby strengthening organizational cyber-readiness at significantly lower cost than traditional security testing approaches.

Keywords

Large language models; MITRE ATT&CK framework; cyber threat simulation; cybersecurity readiness; attack scenario generation; adversarial TTPs; LangChain

Supplementary Material

Supplementary Material File

Cite This Article

APA Style
Nze, P.E., Ademuwagun, A.K., Bello, M., Ifeanyi, F.D., Abdullahi, S.M. et al. (2026). Large Language Model-Assisted Threat-Driven Testing System for Enhanced Cybersecurity Readiness. Journal of Cyber Security, 8(1), 469–486. https://doi.org/10.32604/jcs.2026.083943
Vancouver Style
Nze PE, Ademuwagun AK, Bello M, Ifeanyi FD, Abdullahi SM, Tighil J. Large Language Model-Assisted Threat-Driven Testing System for Enhanced Cybersecurity Readiness. J Cyber Secur. 2026;8(1):469–486. https://doi.org/10.32604/jcs.2026.083943
IEEE Style
P. E. Nze, A. K. Ademuwagun, M. Bello, F. D. Ifeanyi, S. M. Abdullahi, and J. Tighil, “Large Language Model-Assisted Threat-Driven Testing System for Enhanced Cybersecurity Readiness,” J. Cyber Secur., vol. 8, no. 1, pp. 469–486, 2026. https://doi.org/10.32604/jcs.2026.083943



cc Copyright © 2026 The Author(s). Published by Tech Science Press.
This work is licensed under a Creative Commons Attribution 4.0 International License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
  • 36

    View

  • 15

    Download

  • 0

    Like

Share Link