DFIR ATT&CK Technique Classification (3-Shot): leaderboard
Metric: Micro-F1 (%; multi-label ATT&CK technique prediction for 2,076 sentences from 83 The DFIR Report incident reports, 211-technique label space; three in-context examples, no chain of thought, temperature 0; models run at Q4_K_M 4-bit quantization). Source: arxiv.org. Saturation forecast: Rough model projection: around 2026. 6 models tracked.
Top models
| # | Model | Score |
|---|---|---|
| 1 | DeepSeek-V2.5 [Q4_K_M] | 20 |
| 2 | gpt-oss-120b [Q4_K_M] | 19 |
| 3 | gemma-3-27b-it [Q4_K_M] | 17 |
| 4 | gemma-3-12b-it [Q4_K_M] | 13 |
| 5 | Llama-3.1-8B-Instruct [Q4_K_M] | 11 |
| 6 | gpt-oss-20b [Q4_K_M] | 3 |
Interactive version: theaggregate.ai/benchmark?slug=dfir-att-ck-technique-classification-3-shot · How It Works · Data refreshed daily, snapshot 2026-09-26.