Sakeador/ThreatSage-12B
114
ThreatSage-12B ๐
ThreatSage-12B is an open-source cybersecurity-specialized language model fine-tuned from Google Gemma 4 12B. Built for the security community, it excels at threat intelligence analysis, MITRE ATT&CK classification, penetration testing report interpretation, and incident response reasoning.
Key Features
- ๐ฏ Threat intelligence analysis โ APT campaigns, IOCs, TTPs
- ๐ก๏ธ MITRE ATT&CK v16 tactic and technique classification
- ๐ Penetration testing report analysis and remediation advice
- ๐ Incident response guidance and threat hunting support
- ๐๏ธ Multimodal: analyze SIEM screenshots, network diagrams, security dashboards
- ๐ Multilingual: English and Spanish
Model Details
Training Data
Usage
from transformers import AutoModelForCausalLM, AutoTokenizer
from peft import PeftModel
import torch
base_model = "google/gemma-4-12b-it"
adapter = "Sakeador/ThreatSage-12B"
tokenizer = AutoTokenizer.from_pretrained(base_model)
model = AutoModelForCausalLM.from_pretrained(
base_model,
torch_dtype=torch.bfloat16,
device_map="auto"
)
model = PeftModel.from_pretrained(model, adapter)
messages = [
{"role": "user", "content": "Analyze this Wazuh alert and identify the MITRE ATT&CK technique."}
]
text = tokenizer.apply_chat_template(messages, tokenize=False, add_generation_prompt=True)
inputs = tokenizer([text], return_tensors="pt").to(model.device)
outputs = model.generate(**inputs, max_new_tokens=512)
print(tokenizer.decode(outputs[0][inputs.input_ids.shape[1]:], skip_special_tokens=True))Hardware Requirements
Training Infrastructure
- Hardware: NVIDIA GeForce RTX 5060 Ti (16 GB, sm_120 Blackwell)
- Framework: Unsloth + SFTTrainer
- Epochs: 3
- Sequence length: 2048
License
Apache 2.0 โ same as the base model Gemma 4 12B.
Acknowledgements
Thanks to the open-source community, Google DeepMind for Gemma 4, and all the dataset creators who made this possible.
