Skip to main navigation Skip to search Skip to main content

SecKQL-Agent: A Real-World APT29 Events Benchmark and Framework for Reliable Text-to-KQL in Security Analytics

  • Huan Zhang
  • , Haiyan Wang
  • , Shaofang Long
  • , Hao Tan
  • , Ziyu Wang
  • , Yan Jia
  • , Zhaoquan Gu*
  • *Corresponding author for this work
  • Harbin Institute of Technology
  • Pengcheng Laboratory

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Text-to-query language (Text-to-QL) techniques allow analysts to express complex threat-hunting and investigation intents in natural language, lowering the barrier to large-scale security telemetry and facilitating practical security analytics. Yet, despite this potential, public resources for this domain remain scarce due to the technical complexities involved in handling wide-column, semi-structured, and high-volume security datasets. To fill this gap, we construct SecKQL-APT29, a Kusto Query Language (KQL) benchmark derived from real APT29 attack traces. It offers an executable, structured schema and expert-annotated Text-to-KQL pairs. We also propose SecKQL-Agent, a Text-to-KQL framework tailored for security analytics that addresses limitations of directly applying Text-to-SQL methods: (i) redundant and oversized schemas, (ii) limited domain adaptation to security query languages, and (iii) semantic mismatch between generated queries and user intent. SecKQL-Agent comprises three components: a Hybrid-attention Schema Refiner for relevant and compact schema selection; an Adaptive Few-shot Generator for robust query generation; and a Chain-of-Thought (CoT)-driven Semantic Consistency Reflector for result-aware semantic validation. Experiments on two benchmarks against three representative baselines show that SecKQL-Agent achieves an optimal balance between execution accuracy and computational efficiency, demonstrating its effectiveness and generalizability.

Original languageEnglish
Title of host publicationDatabase Systems for Advanced Applications - 31st International Conference, DASFAA 2026, Proceedings
EditorsHyungsoo Jung, Tianzheng Wang, Masashi Toyoda, Hyuk-Yoon Kwon, Jae-woong Lee
PublisherSpringer Science and Business Media Deutschland GmbH
Pages272-288
Number of pages17
ISBN (Print)9789819203772
DOIs
StatePublished - 2026
Externally publishedYes
Event31st International Conference on Database Systems for Advanced Applications, DASFAA 2026 - Jeju, Korea, Republic of
Duration: 27 Apr 202630 Apr 2026

Publication series

NameLecture Notes in Computer Science
Volume16540 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference31st International Conference on Database Systems for Advanced Applications, DASFAA 2026
Country/TerritoryKorea, Republic of
CityJeju
Period27/04/2630/04/26

Keywords

  • Cybersecurity Analytics
  • Kusto Query Language (KQL)
  • LLM-based Agent
  • Text-to-Query Generation

Fingerprint

Dive into the research topics of 'SecKQL-Agent: A Real-World APT29 Events Benchmark and Framework for Reliable Text-to-KQL in Security Analytics'. Together they form a unique fingerprint.

Cite this