CTIFoundry: Restructuring the Corpus, Not the Model, Adds +0.19 to +0.28 F1 at Half the Tool Calls
CTIFoundry (arXiv 2608.18613, 2026-08-19) argues the bottleneck in agentic threat-intel investigation is the corpus substrate, not model capability, and replaces opaque RAG chunks with a build-time ontology graph over CVE, CWE, CAPEC and ATT&CK whose official cross-references become typed traversable edges, plus a span-grounded provenance-carrying report layer. Exposed as seven typed tools and three procedural skills on a stock open-source harness, swapping only the action surface lifts overall F1 by +0.19 to +0.28 on the CTIConnect benchmark across a four-model, two-provider panel. A small model on CTIFoundry beats a flagship on the flat substrate, and on both Claude models the scaffolded agent is more accurate using roughly half the tool calls.
↳ Follow the thread