✨ Parsing Threat Intel reports with LLM is fun and opens up huge possibilities. I've been doing this for quite a while and I think it's time to give it some better structure.
So far, LlamaIndex is the best package for this, though LangChain is good too. Gemini 1.5 Pro is the most comprehensive one, whilst GPT4o Mini is the most efficient in terms of speed and information returned. Ollama3.1 8B and 3.2 3B cannot handle complex JSON structures.
An example parsing an article from the DFIRReport







