Large Language Models for Security Operations Centers: A Comprehensive Survey

Security operations centers (SOCs) face escalating challenges from alert fatigue and a critical skills gap, leading to delayed incident response times. Addressing these persistent issues calls for innovative automation and decision‐support approaches. Large language models (LLMs) present a transformative opportunity to automate complex workflows and augment the capabilities of human analysts. This survey provides the first comprehensive and structured analysis of LLM integration into SOC operations. We systematically map LLM applications to the functions of the NIST Cybersecurity Framework (CSF) and use the MITRE ATT&CK framework as an analytical lens to evaluate their granular threat detection capabilities. By synthesizing findings from 216 studies, we provide a structured overview of current methodologies, identify key trade‐offs between LLM architectures, and highlight significant gaps in research, particularly in the NIST “Recover” function. This survey offers researchers and SOC managers a clear research roadmap and actionable insights for leveraging LLMs to build more resilient and intelligent security operations.

Paper

Similar papers

© 2026 NYSGPT2525 LLC