Large Language Models for Security Operations Centers: A Comprehensive Survey

0Citations
Citations of this article
66Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

Security operations centers (SOCs) face escalating challenges from alert fatigue and a critical skills gap, leading to delayed incident response times. Addressing these persistent issues calls for innovative automation and decision-support approaches. Large language models (LLMs) present a transformative opportunity to automate complex workflows and augment the capabilities of human analysts. This survey provides the first comprehensive and structured analysis of LLM integration into SOC operations. We systematically map LLM applications to the functions of the NIST Cybersecurity Framework (CSF) and use the MITRE ATT&CK framework as an analytical lens to evaluate their granular threat detection capabilities. By synthesizing findings from 216 studies, we provide a structured overview of current methodologies, identify key trade-offs between LLM architectures, and highlight significant gaps in research, particularly in the NIST “Recover” function. This survey offers researchers and SOC managers a clear research roadmap and actionable insights for leveraging LLMs to build more resilient and intelligent security operations.

Cite

CITATION STYLE

APA

Habibzadeh, A., Feyzi, F., & Atani, R. E. (2026). Large Language Models for Security Operations Centers: A Comprehensive Survey. Journal of Electrical and Computer Engineering. John Wiley and Sons Ltd. https://doi.org/10.1155/jece/3383674

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free