Best Local LLMs for Cybersecurity
Written by Jakub Rusinowski · Last updated July 15, 2026
Log and alert triage, code review for vulnerabilities, and analysis that cannot be sent to a third party.
Top pick: Qwen 3.7 35B-A3B
Scores 99.5/100 for security analysis and defensive research. 35B parameters, needing about 21.9 GB at Q4_K_M, 256K context, Apache-2.0.
Ranked for security analysis and defensive research
| Model | Score | Params | Context | Licence | Quality index |
|---|---|---|---|---|---|
| 1. Qwen 3.7 35B-A3B | 99.5 | 35B | 256K | Apache-2.0 | — (estimated) |
| 2. Qwen 3.6 35B-A3B | 98.8 | 35B | 256K | Apache-2.0 | — (estimated) |
| 3. Gemma 4 31B | 98.4 | 31B | 250K | Apache-2.0 | — (estimated) |
| 4. DeepSeek V4.1 Flash | 95.2 | 284B | 977K | MIT | — (estimated) |
| 5. DeepSeek V4-Flash | 94.9 | 284B | 977K | MIT | — (estimated) |
| 6. Ternary Bonsai 27B | 94.3 | 27B | 256K | Apache 2.0 | — (estimated) |
Best pick for your memory budget
The strongest model overall is rarely the right answer — what matters is the strongest model that fits the memory you have. These picks are re-ranked per tier, so each one uses its budget rather than simply being small.
| Memory | Typical hardware | Recommended models |
|---|---|---|
| 8 GB | RTX 4060, RTX 3070, base MacBook Air | Qwen3-Coder 8B (86.8) Qwen 3 8B (86) IBM Granite 4.1 Granite 4.1 8B (85) |
| 12 GB | RTX 3060 12 GB, RTX 5070 | Qwen 3 14B (88.9) DeepSeek R1 Distill Qwen 14B (88.3) Qwen3-Coder 8B (85.7) |
| 16 GB | RTX 5080, RTX 4080, RX 9070 XT | Devstral Small 2 24B (89.7) Qwen 3 14B (88.9) DeepSeek R1 Distill Qwen 14B (88.1) |
| 24 GB | RTX 4090, RTX 3090, RX 7900 XTX | Gemma 4 31B (100) Qwen 3.6 35B-A3B (100) Qwen 3.7 35B-A3B (100) |
| 48 GB | RTX 6000 Ada, MacBook Pro M4 Max 48 GB | Qwen 3.7 35B-A3B (100) Qwen 3.6 35B-A3B (99.6) Gemma 4 31B (98.7) |
| 128 GB+ | Mac Studio, DGX Spark, multi-GPU | Qwen 3.7 35B-A3B (97.7) Qwen 3.6 35B-A3B (97) Gemma 4 31B (96.4) |
How this ranking works
Weighted like a coding workload with the licence sensitivity of an enterprise one, and a long-context floor for log and diff analysis. The reason this workload runs locally at all is usually that the material cannot leave the network, which is why licence weight is high (0.7).
Worked example — Qwen 3.7 35B-A3B: capability 93.3 × 0.421, quality 92.7 × 0.248, context 100 × 0.161, license 100 × 0.078, accessibility 80 × 0.093 + 6 tag bonus (reasoning, coding).
Requirements applied: context floor 32,768 tokens (ideal 262,144), quality floor 60, licence weight 0.7, latency weight 0.4.
Running security analysis and defensive research locally
- Local inference is the point here: the artefacts being analysed are often exactly what must not be uploaded.
- Treat model output as a lead, not a finding — false positives in vulnerability review are expensive to chase.
FAQ
What is the best local LLM for security analysis and defensive research?
Qwen 3.7 35B-A3B, scoring 99.5/100 against this workload's published requirements. 159 models qualified.
What hardware do I need for security analysis and defensive research?
A credible answer starts at 8 GB of memory. Larger budgets unlock materially stronger models — the table above lists the best pick at each tier.
How were these models ranked?
Weighted like a coding workload with the licence sensitivity of an enterprise one, and a long-context floor for log and diff analysis. The reason this workload runs locally at all is usually that the material cannot leave the network, which is why licence weight is high (0.7).
Hardware for This Workload
- Best GPU for cybersecurity
- Best models for the NVIDIA GeForce RTX 4060 Ti 8GB
- Best models for the NVIDIA GeForce RTX 3080 Ti
- Best models for the NVIDIA GeForce RTX 4090 Laptop GPU
Related Workloads
- Best local LLMs for agents
- Best local LLMs for document analysis
- Best local LLMs for fine-tuning
- Best local LLMs for ocr