[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83712-en":3,"doc-seo-83712-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83712,4398048949847,"Eliana","https://ap-avatar.wpscdn.com/avatar/400002536579ef2da7f?_k=1778318612642679267",8,"Research & Report","Agentic and Generative AI for Open-Source Intelligence and Cyber Investigations Taxonomy Evaluation Challenges and Future Directions","Rapid growth of publicly available digital information makes manual open-source intelligence (OSINT) analysis inadequate for contemporary intelligence, cybersecurity, and cyber investigation needs. The survey reviews 74 studies on agentic AI, generative AI, and LLMs for OSINT, cyber threat intelligence, and cyber investigation, proposing an 11-category taxonomy, identifying a corpus-level hallucination–validation gap, mapping coverage across the OSINT workflow, and extracting a 10-point research agenda spanning evaluation, robustness, and governance.","Agentic and Generative AI for Open-Source Intelligence and Cyber Investigations: Taxonomy, Evaluation, Challenges, and Future Directions  \nEduardo Almeida Palmieri, Mohamed Chahine Ghanem *, Dipo Dunsin, Zubair Baig, Ed de Quincey,  \nand Kim-Kwang Raymond Choo  \narXiv :2607 .03233v 1 [ cs .CR] 3 Jul 2026  \nAbstract—The rapid growth of publicly available digital information has rendered manual open-source intelligence (OSINT) analysis insufficient for contemporary intelligence, cybersecurity, and Cyber Investigation requirements. Large language models (LLMs) and agentic AI systems, which select tools, perform multistep reasoning, and iteratively produce intelligence, have emerged as promising responses, yet published capability demonstrations have substantially outpaced the evaluation infrastructure required to validate operational deployment. This survey systematically reviews 74 unique studies on the application of agentic AI, generative AI, and LLMs to OSINT, cyber threat intelligence (CTI), and Cyber Investigation. Its contribution is fourfold. First, it treats agentic AI as a distinct analytical category rather thana variant of LLM prompting, organising the literature through an 11-category taxonomy spanning LLM foundations, agentic architectures, retrieval-augmented generation (RAG), knowledge graphs, prompt engineering, domain adaptation, evaluation benchmarks, and risk. Second, it establishes the hallucination– validation gap as a corpus-level finding: although hallucination is named a reliability concern in more than twenty studies, end-to-end hallucination is empirically measured in only one OSINT-specific system, a RAG-augmented architecture reporting a 4% rate under favourable, non-reproducible conditions; the reasoning-error and factual-correction results reported elsewhere are measured in general-domain question answering, not on OSINT hallucination, and do not close this gap. Third, it maps the corpus onto the OSINT workflow lifecycle, showing that collection and analysis are well served while verification, reporting, dissemination, and decision support remain systematically underexplored. Fourth, it derives a ten-point research agenda, covering evaluation, benchmarking, hallucination measurement, adversarial robustness, dark-web coverage, multimodal processing, and governance, directly from the gaps the corpus exposes. The review further finds that no standardised, open, communityadopted benchmark exists for cross-study comparison of OSINTAI systems, and that agentic systems are evaluated exclusively under benign conditions despite documented adversarial threats.  \nE. A. Palmieri and E. de Quincey are with the School of Computer Science and Mathematics, Keele University, Newcastle-under-Lyme ST5 5AA, U.K.(e-mail: [e.a.palmieri@keele.ac.uk](e.a.palmieri@keele.ac.uk); [e.de.quincey@keele.ac.uk](e.de.quincey@keele.ac.uk)).  \nM. C. Ghanem is with the School of Computer Science and Mathematics, Keele University, Newcastle-under-Lyme ST5 5AA, U.K., and also with the Cybersecurity Institute, University of Liverpool, Liverpool L69 3BX, U.K.(corresponding author, [e-mail: mohamed.chahine.ghanem@liverpool.ac.uk](e-mail: mohamed.chahine.ghanem@liverpool.ac.uk)).  \nD. Dunsin is with the Department of Applied Computing IICL, University of Wales Trinity Saint David, London E14 4HA, U.K. (e-mail: [d.dunsin@uwtsd.ac.uk](d.dunsin@uwtsd.ac.uk)) .  \nZ. Baig is with the Deakin Cyber Research and Innovation Hub, Deakin University, Waurn Ponds, VIC 3216, Australia (e-mail: [zubair.baig@deakin.edu.au](zubair.baig@deakin.edu.au)).  \nK.-K. R. Choo is with the Department of Information Systems and Cyber Security, The University of Texas at San Antonio, San Antonio, TX 78249, USA (e-mail: [raymond.choo@utsa.edu](raymond.choo@utsa.edu)).  \nManuscript received 02 July 2026 .  \nIt concludes that a structured human–AI co-pilot model, in which LLMs support collection and triage while analysts retain responsibility for verification, reporting, ","cbCaivVNXIRu2DEm","https://ap.wps.com/l/cbCaivVNXIRu2DEm","pdf",16337053,3,1,36,"English","en",105,"# Introduction\n## Agentic and generative AI for OSINT\n# Taxonomy and evidence base\n## 11-category taxonomy of approaches\n## Hallucination–validation gap\n## OSINT workflow lifecycle mapping\n# Challenges and evaluation shortcomings\n## Lack of standardized open benchmarks\n## Benign-only evaluation despite adversarial threats\n# Future directions\n## Ten-point research agenda","[{\"question\":\"Why is manual OSINT analysis no longer sufficient?\",\"answer\":\"Public digital information has expanded so quickly that operational-scale processing, verification, and synthesis cannot be handled effectively with traditional manual workflows.\"},{\"question\":\"How does the survey treat agentic AI in relation to LLM prompting?\",\"answer\":\"Agentic AI is handled as a distinct analytical category, organized via an 11-category taxonomy rather than treated as just a variant of LLM prompting.\"},{\"question\":\"What is the hallucination–validation gap reported in the survey?\",\"answer\":\"More than twenty studies name hallucination as a reliability concern, but end-to-end OSINT-specific hallucination is empirically measured in only one system, leaving the gap largely unclosed under non-reproducible conditions.\"}]",1784189912,91,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"agentic-and-generative-ai-for-open-source-intelligence-and-cyber-investigations-taxonomy-evaluation-challenges-and-future-directions","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/agentic-and-generative-ai-for-open-source-intelligence-and-cyber-investigations-taxonomy-evaluation-challenges-and-future-directions/83712/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why is manual OSINT analysis no longer sufficient?","Question",{"text":75,"@type":76},"Public digital information has expanded so quickly that operational-scale processing, verification, and synthesis cannot be handled effectively with traditional manual workflows.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the survey treat agentic AI in relation to LLM prompting?",{"text":80,"@type":76},"Agentic AI is handled as a distinct analytical category, organized via an 11-category taxonomy rather than treated as just a variant of LLM prompting.",{"name":82,"@type":73,"acceptedAnswer":83},"What is the hallucination–validation gap reported in the survey?",{"text":84,"@type":76},"More than twenty studies name hallucination as a reliability concern, but end-to-end OSINT-specific hallucination is empirically measured in only one system, leaving the gap largely unclosed under non-reproducible conditions.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]