LogPrecis / SecureShellBert
A pair of models from an Italian university: they read a recorded command session and mark which parts belong to reconnaissance, persistence and other attacker steps. A human makes the decision on a disputed operation; automatic blocking without review is not acceptable.
The last open version came out in Mar 2024. The family has not been updated for a long time: the model still works, but do not expect fixes or new sizes.
- Developer
- SmartData@PoliTO, Politecnico di Torino, Italy
- First release
- Jul 2023
- Latest release
- Mar 2024
- Sizes
- about 125M (based on CodeBERT)
- License
- Commercial use with conditionsno license is stated on the model card — check with the developer
- Running
- On your own serverAlso runs without a GPU
- Industries
- Security, Software development
What it does
- Labelling command logs by stage of activity
- Grouping similar sessions for incident review
- Preparing features for server monitoring
Where it is used
Hardware requirements
Versions
- SecureShellBert и LogPrecis на Hugging Face
- Код LogPrecis на GitHub
How to run it
I can set this up end to end: pick the model size, deploy it on your server and connect it to your systems.
Frequently asked questions
Can LogPrecis / SecureShellBert be used in a commercial project?
With conditions. License: no license is stated on the model card — check with the developer. Restrictions vary — region, company revenue, attribution requirements. Have a lawyer check the terms before a commercial launch.
What hardware does LogPrecis / SecureShellBert need?
At minimum: Laptop or regular PC, up to 8 GB of VRAM — smaller versions. Some versions also run on an ordinary CPU, without a GPU. You can calculate the exact VRAM for your model size and context in the hardware calculator.
Does LogPrecis / SecureShellBert support Russian?
Language does not matter for this model: it does not work with text.
Where can I download LogPrecis / SecureShellBert and what does it cost?
The LogPrecis / SecureShellBert weights are open and free to download. You only pay for the hardware it runs on and for the setup. Source links are at the bottom of this page.
How I deploy it for clients
- SelectionI pick the model size for your task and hardware and test it on your examples.
- DeploymentI deploy it on your server or in a closed network and provide an API.
- Fine-tuningI fine-tune it on your data (LoRA) or connect a knowledge base — whichever is cheaper for the task.
- IntegrationI connect it to your CRM, ERP, bot, website or team chat and set up monitoring.
Similar models
A model pretrained on a large volume of logs from different systems: it turns a log line into a vector on top of which failure and outlier detection is fine-tuned. A human makes the decision on a disputed operation; automatic blocking without review is not acceptable.
DetailsCybersecuritySecureBERTEhsan Aghaei and co-authors · USACommercial use with conditionsA compact language encoder trained on cybersecurity texts: tagging threat reports, finding entities and classification.
DetailsCybersecurityNVIDIA Morpheus (набор моделей)NVIDIA · USACommercial use allowedAn open NVIDIA bundle: a card-transaction graph plus a classifier, a profile of normal user behaviour, log parsing and root-cause search. A human makes the decision on a disputed operation; automatic blocking without review is not acceptable.
DetailsSource: huggingface.co/SmartDataPolito/logprecis. Data checked against the model card on 22 Sep 2026. Have a lawyer review the license before commercial launch.


