Triple
T28509965
| Position | Surface form | Disambiguated ID | Type / Status |
|---|---|---|---|
| Subject | Raphael Mudge |
E721453
|
entity |
| Predicate | toolCobaltStrikeType |
P86841
|
FINISHED |
| Object | commercial adversary simulation platform |
—
|
LITERAL FINISHED |
How this triple was built (2 steps)
Every LLM step that produced this triple, in pipeline order — named-entity classification, the disambiguation choices (the exact options shown, with the pick highlighted), and the generated description. The batch + timestamp of each is in the Provenance table below.
NER
Named-entity recognition
gpt-5-mini
Instruction
Given a phrase, classify it is english named entity (e.g., persons, organizations, works of art) in Latin script, or not (e.g., literals, dates, URLs, verbose phrases). For disambiguation, the statement where the phrase occurs as object is also given. Please return a JSON object with `phrase` (string, the phrase being analyzed) and `is_ne` (boolean, indicating whether the phrase is a Named Entity).
Input
Phrase: commercial adversary simulation platform | Statement: [Raphael Mudge, toolCobaltStrikeType, commercial adversary simulation platform]
PD
Predicate disambiguation
gpt-5-mini-2025-08-07
Target predicate: toolCobaltStrikeType Context triple: [Raphael Mudge, toolCobaltStrikeType, commercial adversary simulation platform]
-
A.
attackToolExample
Indicates that a specific tool or method is used as an example of how an attack is or can be carried out.
-
B.
toolDeveloperFor
Indicates that one entity is the creator or developer of a tool that is used by or associated with another entity.
-
C.
toolType
chosen
Indicates the specific kind or category of tool associated with an entity.
-
D.
toolUsed
Indicates that an action or task is performed using a particular tool as the means or instrument.
-
E.
toolIn
Indicates that one entity is a tool or instrument used in or associated with another entity or context.
- F. None of above.
Provenance (3 batches)
The batch behind each pipeline step, in order, with when it ran. Timestamps are batch-level — stages were processed in waves, so the object chain (NER → NED1 → NEDg → NED2) reads in order, but predicate / elicitation batches can sit in a different wave.
| Step | Stage | Batch ID | Status | When |
|---|---|---|---|---|
| creating | Elicitation | batch_69f01a5c072081908c7b04bcf6478da9 |
completed | April 28, 2026, 2:24 a.m. |
| NER | Named-entity recognition | batch_69f65876c52c8190bc889c7a67bd07f3 |
completed | May 2, 2026, 8:03 p.m. |
| PD | Predicate disambiguation | batch_69f6575d89788190aca478e4aea05a65 |
completed | May 2, 2026, 7:58 p.m. |
Created at: April 28, 2026, 3:11 a.m.