#Twiti: Social Listening for Threat Intelligence
Hyejin Shin, WooChul Shim, Saebom Kim, Sol Lee, Yong Goo Kang, Yong Ho Hwang
Abstract
Twitter is a popular public source for threat hunting. Many security vendors and security professionals use Twitter in practice for collecting Indicators of Compromise (IOCs). However, little is known about IOCs on Twitter. Their important characteristics such as earliness, uniqueness, and accuracy have never been investigated. Moreover, how to extract IOCs from Twitter with high accuracy is not obvious. In this paper, we present Twiti, a system that automatically extracts various forms of malware IOCs from Twitter. Based on the collected IOCs, we conduct the first empirical assessment and thorough analysis of malware IOCs on Twitter. Twiti extracts IOCs from tweets identified as having malware IOC information by leveraging natural language processing and machine learning techniques. With extensive evaluation, we demonstrate that not only can Twiti extract malware IOCs accurately, but also the extracted IOCs are unique and early. By analyzing IOCs in Twiti from various aspects, we find that Twitter captures ongoing malware threats such as Emotet variants and malware distribution sites better than other public threat intelligence (TI) feeds. We also find that only a tiny fraction of IOCs on Twitter come from commercial vendor accounts and individual Twitter users are the main contributors of the early detected or exclusive IOCs, which indicates that Twitter can provide many valuable IOCs uncovered in commercial domain
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 7a8bd9ab-3785-4970-81a1-01fc7e7c9229Cited by top-tier papers2
- Jettisoning Junk Messaging in the Era of End-to-End Encryption: A Case Study of WhatsAppPushkal Agarwal, Aravindh Raman, Damilola Ibosiola, Nishanth Sastry et al.WWW 2022 · 3 citations
- Tweezers: A Framework for Security Event Detection via Event Attribution-centric Tweet EmbeddingJian Cui, Hanna Kim, Eugene Jang, Dayeon Yim et al.NDSS 2025
Related papers
- Acing the IOC Game: Toward Automatic Discovery and Analysis of Open-Source Cyber Threat IntelligenceXiaojing Liao, Kan Yuan, XiaoFeng Wang, Zhou Li et al.CCS 2016 · 308 citations
- BIC: Twitter Bot Detection with Text-Graph Interaction and Semantic ConsistencyZhenyu Lei, Herun Wan, Wenqian Zhang, Shangbin Feng et al.ACL 2023 · 28 citations
- LLMCloudHunter: Harnessing LLMs for Automated Extraction of Detection Rules from Cloud-Based CTIYuval Schwartz, Lavi Ben-Shimol, Dudu Mimran, Yuval Elovici et al.WWW 2025 · 38 citations
- SoK: Automated TTP Extraction from CTI Reports - Are We There Yet?Marvin Büchel, Tommaso Paladini, Stefano Longari, Michele Carminati et al.USENIX Security 2025
- Enabling Efficient Cyber Threat Hunting With Cyber Threat IntelligencePeng Gao, Fei Shao, Xiaoyuan Liu, Xusheng Xiao et al.ICDE 2021 · 124 citations
