RACONTEUR: A Knowledgeable, Insightful, and Portable LLM-Powered Shell Command Explainer
Jiangyi Deng, Xinfeng Li, Yanjiao Chen, Yijie Bai, Haiqin Weng, Yan Liu, Tao Wei, Wenyuan Xu
摘要
Malicious shell commands are linchpins to many cyber-attacks, but may not be easy to understand by security analysts due to complicated and often disguised code structures. Advances in large language models (LLMs) have unlocked the possibility of generating understandable explanations for shell commands. However, existing general-purpose LLMs suffer from a lack of expert knowledge and a tendency to hallucinate in the task of shell command explanation. In this paper, we present RACONTEUR, a knowledgeable, expressive and portable shell command explainer powered by LLM. RACONTEUR is infused with professional knowledge to provide comprehensive explanations on shell commands, including not only what the command does (i.e., behavior) but also why the command does it (i.e., purpose). To shed light on the high-level intent of the command, we also translate the natural-language-based explanation into standard technique & tactic defined by MITRE ATT&CK, the worldwide knowledge base of cybersecurity. To enable RACONTEUR to explain unseen private commands, we further develop a documentation retriever to obtain relevant information from complementary documentations to assist the explanation process. We have created a largescale dataset for training and conducted extensive experiments to evaluate the capability of RACONTEUR in shell command explanation. The experiments verify that RACONTEUR is able to provide high-quality explanations and in-depth insight of the intent of the command.
• We propose RACONTEUR, an LLM-powered shell command explainer that can provide knowledgeable and insightful descriptions on shell commands, especially malicious ones, to assist security analysts in identifying potential cyber-attacks.
• We equip RACONTEUR with a holistic toolkit including behavior explainer, intent identifier, and documentation retriever, allowing RACONTEUR to provide comprehensive and faithful explanations on public and private shell commands.
• We have conducted extensive experiments to verify that RACONTEUR is able to provide high-quality explanations and in-depth insight of the intent of the command. The dataset we curated is open-source to boost further research in LLM-aided code explanation 1 .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Perception-Guided Jailbreak Against Text-to-Image ModelsYihao Huang, Le Liang, Tianlin Li, Xiaojun Jia 等AAAI 2025 · 被引用 34 次
- Incident Response Planning Using a Lightweight Large Language Model with Reduced HallucinationKim Hammar, Tansu Alpcan, Emil C. LupuNDSS 2026 · 被引用 16 次
- DeclarUI: Bridging Design and Development with Automated Declarative UI Code GenerationTing Zhou, Yanjie Zhao, Xinyi Hou, Xiaoyu Sun 等FSE 2025 · 被引用 13 次
- A Multi-Agent Framework for High-Interaction Terminal SimulationKai Wei, Yuwen Cui, Kehan Shen, Hua Wei 等ACL 2026
- DynamicNER: A Dynamic, Multilingual, and Fine-Grained Dataset for LLM-based Named Entity RecognitionHanjun Luo, Yingbin Jin, Yiran Wang, Xinfeng Li 等EMNLP 2025
它引用的顶会 Paper12
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah 等NeurIPS 2020 · 被引用 64,255 次
- Training language models to follow instructions with human feedbackLong Ouyang, Jeffrey Wu, Xu Jiang, Diogo Almeida 等NeurIPS 2022 · 被引用 24,707 次
- Chain-of-Thought Prompting Elicits Reasoning in Large Language ModelsJason Wei, Xuezhi Wang, Dale Schuurmans, Maarten Bosma 等NeurIPS 2022 · 被引用 22,562 次
- LoRA: Low-Rank Adaptation of Large Language ModelsEdward J. Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu 等ICLR 2022 · 被引用 18,833 次
- GraphCodeBERT: Pre-training Code Representations with Data FlowDaya Guo, Shuo Ren, Shuai Lu, Zhangyin Feng 等ICLR 2021 · 被引用 1,644 次
相关 Paper
- CyberPal.AI: Empowering LLMs with Expert-Driven Cybersecurity InstructionsMatan Levi, Yair Allouche, Daniel Ohayon, Anton PuzanovAAAI 2025 · 被引用 17 次
- Malla: Demystifying Real-world Large Language Model Integrated Malicious ServicesZilong Lin, Jian Cui, Xiaojing Liao, XiaoFeng WangUSENIX Security 2024 · 被引用 49 次
- BashCoder-R1: Towards Robust and Explainable Bash Script Generation with Robustness-Aware Group Relative Policy OptimizationLei Yu, Peng Wang, Jia Xu, Jingyuan Zhang 等ISSTA 2026
- Mimicking the Familiar: Dynamic Command Generation for Information Theft Attacks in LLM Tool-Learning SystemZiyou Jiang, Mingyang Li, Guowei Yang, Junjie Wang 等ACL 2025
- AutoMalDesc: Large-Scale Script Analysis for Cyber Threat ResearchAlexandru-Mihai Apostu, Andrei Preda, Alexandra Daniela Damir, Diana Bolocan 等AAAI 2026
