Running a Local LLM for Threat Hunting: Setup, Models, and Real Workflows
A complete guide to setting up a local large language model for security work across three hardware tiers: Apple Silicon, consumer GPU, and CPU-only. Covers Ollama, Open WebUI, model selection, and practical threat hunting workflows including log analysis, Sigma rule generation, and VQL assistance.