Triple
T28509534
| Position | Surface form | Disambiguated ID | Type / Status |
|---|---|---|---|
| Subject | Social-Engineer Toolkit |
E721443
|
entity |
| Predicate | supportsAttackVector |
P202851
|
FINISHED |
| Object | email phishing |
—
|
LITERAL FINISHED |
How this triple was built (2 steps)
Every LLM step that produced this triple, in pipeline order — named-entity classification, the disambiguation choices (the exact options shown, with the pick highlighted), and the generated description. The batch + timestamp of each is in the Provenance table below.
NER
Named-entity recognition
gpt-5-mini
Instruction
Given a phrase, classify it is english named entity (e.g., persons, organizations, works of art) in Latin script, or not (e.g., literals, dates, URLs, verbose phrases). For disambiguation, the statement where the phrase occurs as object is also given. Please return a JSON object with `phrase` (string, the phrase being analyzed) and `is_ne` (boolean, indicating whether the phrase is a Named Entity).
Input
Phrase: email phishing | Statement: [Social-Engineer Toolkit, supportsAttackVector, email phishing]
PD
Predicate disambiguation
gpt-5-mini-2025-08-07
Target predicate: supportsAttackVector Context triple: [Social-Engineer Toolkit, supportsAttackVector, email phishing]
-
A.
hasAttackProfile
Indicates that an entity is associated with a specific pattern, method, or characteristics of attack it can perform or employ.
-
B.
canBeAttackedBy
Indicates that an entity is a possible target of an attack initiated by another entity.
-
C.
supportsAt
Indicates that one entity provides assistance, endorsement, or backing to another entity in a specific context, location, or point in time.
-
D.
relatedAttack
Indicates that one attack is connected or associated with another attack, such as being part of the same incident, campaign, or sequence of actions.
-
E.
knownAttacks
Indicates that one entity is aware of, or has information about, specific attacks associated with another entity.
- F. None of above. chosen
Provenance (4 batches)
The batch behind each pipeline step, in order, with when it ran. Timestamps are batch-level — stages were processed in waves, so the object chain (NER → NED1 → NEDg → NED2) reads in order, but predicate / elicitation batches can sit in a different wave.
| Step | Stage | Batch ID | Status | When |
|---|---|---|---|---|
| creating | Elicitation | batch_69f01a5c072081908c7b04bcf6478da9 |
completed | April 28, 2026, 2:24 a.m. |
| NER | Named-entity recognition | batch_6a00c59b03dc8190870f0dd24603a1ef |
completed | May 10, 2026, 5:51 p.m. |
| PD | Predicate disambiguation | batch_6a00c5178bc88190b2a0e03f38314035 |
completed | May 10, 2026, 5:49 p.m. |
| PDg | Predicate description generation | batch_6a00c59a1af88190848c5b1775af9caa |
completed | May 10, 2026, 5:51 p.m. |
Created at: April 28, 2026, 3:11 a.m.