In conjunction with the 2026 IEEE International Conference on Big Data (IEEE BigData 2026)
December 14-17, 2026 | Sheraton Phoenix Downtown | Phoenix, Arizona, USA
An outstanding paper will be selected for the CyberHunt 2026 Best Paper Award, to be announced during the workshop
Due date for paper submission
October 19, 23:59 (ET) 2026
Notification of paper acceptance to authors
Nov 2, 2026
Camera-ready of accepted papers
Nov 14, 2026 (firm deadline)
Workshop & main conference
Dec 14-17, 2026
Paper Submission Information
The workshop invites full-length paper submissions reporting original research. Papers should be up to 10 pages, including references, in IEEE two-column format.
All submissions will undergo a double-blind peer-review process. Authors should anonymise (names, affiliations, acknowledgements) manuscripts for review. Conflicts of interest will be handled in accordance with IEEE peer-review principles, with conflicted chairs and PC members recused from the review and decision process.
For manuscript templates and formatting instructions, please visit the IEEE conference templates page: https://www.ieee.org/conferences/publishing/templates
Please note: All accepted and presented papers will be included in the IEEE BigData 2026 Workshop Proceedings, published by the IEEE Computer Society Press. At least one author of each accepted paper must register for the conference and present the paper in order to have the paper included in the proceedings.
CyberHunt 2026 explores the future of intelligence-driven cyber defence at the intersection of cyber threat intelligence, threat hunting, AI-enabled Security Operations Centres (SOCs), and agentic cybersecurity systems. The workshop brings together researchers and practitioners to discuss methods, tools, architectures, datasets, standards, and operational experiences that make intelligence more actionable, automate security workflows, support human–AI collaboration, and strengthen proactive cyber defence.
Cyber threats are becoming more complex, faster-moving, and increasingly difficult to detect using reactive security approaches alone. Modern Security Operations Centres are therefore shifting towards intelligence-driven, highly automated operations, in which cyber threat intelligence, threat hunting, detection engineering, and incident response are closely integrated to support proactive defence. At the same time, advances in artificial intelligence (AI), large language models (LLMs), agentic systems, and neuro-symbolic reasoning are reshaping how cyber defenders collect, analyse, interpret, and operationalise intelligence. These technologies create new opportunities to automate parts of the intelligence cycle, augment human analysts, improve decision-making, and enable more adaptive security operations. They also introduce new risks, including adversarial manipulation, insecure AI deployment, and AI-enabled cyber threats.
The 9th Annual Workshop on Cyber Threat Intelligence and Hunting (CyberHunt 2026) brings together researchers and practitioners from academia, industry, government, and the wider cybersecurity community to explore the evolving relationship between cyber threat intelligence, threat hunting, AI-enabled security operations, and operational cyber defence. The workshop welcomes original research, practical experience reports, system designs, datasets, benchmarks, and emerging ideas that advance intelligence-driven cybersecurity. Particular emphasis is placed on methods and systems that make threat intelligence actionable, support human–AI collaboration, improve SOC automation, enable machine-readable intelligence sharing, and advance rigorous evaluation, effective governance, and the trustworthy deployment of AI-enabled cyber defence systems.
Threat Intelligence and Threat Hunting
Intelligence-driven threat hunting methodologies
Intelligence-driven detection engineering and incident response
Adversary modelling, attribution, and behavioural analysis
Adversary and defender tradecraft (TTPs)
Intelligence-driven red teaming and adversary emulation
Visualisation and explainability techniques for intelligence
AI, Agentic Systems, and Automation for Cybersecurity
Agentic AI and autonomous systems for CTI and threat hunting
Multi-agent systems for SOC operations
AI-assisted threat analysis, reasoning, and decision-making
Human–AI collaboration and cognitive augmentation in SOCs
Large Language Models (LLMs) and generative AI for cybersecurity
AI-enabled automation and orchestration of security workflows
Data, Knowledge Representation, and Intelligence Engineering
Data sources, collection, and processing for CTI
Multi-modal data fusion (e.g., text, image, telemetry, malware, OSINT)
Knowledge representation (ontologies, knowledge graphs, symbolic AI)
Neuro-symbolic AI approaches for CTI
Machine-readable intelligence sharing formats and standards
Intelligence lifecycle automation and pipelines
SOC Architectures and Operational Intelligence
AI-enabled and intelligence-driven SOC architectures
Security orchestration, automation, and response
Integration of CTI into detection and response pipelines
Real-time and streaming intelligence systems
Scalability and performance in modern SOC environments
Security of AI and Adversarial Threats
Adversarial attacks on AI/ML models used in cybersecurity
Prompt injection, data poisoning, and model manipulation
Secure deployment and governance of AI in SOCs
AI supply chain security and trustworthiness
Detection of AI-enabled cyber threats
Emerging Threat Landscapes and Applications
AI-enabled cybercrime
Automated attack campaigns using AI
Critical infrastructure and OT/ICS threat intelligence
AI-enabled disinformation, influence operations, and hybrid threats
Cyber geopolitics and strategic intelligence
Evaluation, Benchmarking, and Datasets
Evaluation methodologies for CTI and threat hunting systems
Benchmarking AI models for cybersecurity tasks
Datasets for CTI, threat detection, and intelligence analysis
Metrics for intelligence quality, relevance, and actionability
Governance, Ethics, and Collaboration
Legal, ethical, and privacy considerations in CTI
Intelligence sharing, collaboration, and trust frameworks
Standardisation and interoperability
Open-source tools and platforms for CTI and SOCs
Vasileios Mavroeidis, University of Oslo
Habtamu Abie, Norwegian Computing Center
Nicholas Kolokotronis, University of the Peloponnese
Fabio Martinelli, Consiglio Nazionale delle Ricerche
Eva Papadogiannaki, Technical University of Crete
Mateusz Zych, University of Oslo
Tamas Bisztray, Eötvös Loránd University
Vasileios Mavroeidis, University of Oslo
Alexios Lekidis, University of Thessaly
Audun Jøsang, University of Oslo
Gudmund Grøv, Norwegian Defence Research Establishment
Panagiotis Radoglou-Grammatikis, University of Western Macedonia
Reijo Savola, University of Jyväskylä
Sokratis Katsikas, Norwegian University of Science and Technology
Stavros Shiaeles, University of Portsmouth
TBA