Best Local LLMs for Cybersecurity

Written by Jakub Rusinowski · Last updated July 15, 2026

Log and alert triage, code review for vulnerabilities, and analysis that cannot be sent to a third party.

Top pick: Qwen 3.7 35B-A3B

Scores 99.5/100 for security analysis and defensive research. 35B parameters, needing about 21.9 GB at Q4_K_M, 256K context, Apache-2.0.

Ranked for security analysis and defensive research

ModelScoreParamsContextLicenceQuality index
1. Qwen 3.7 35B-A3B99.535B256KApache-2.0— (estimated)
2. Qwen 3.6 35B-A3B98.835B256KApache-2.0— (estimated)
3. Gemma 4 31B98.431B250KApache-2.0— (estimated)
4. DeepSeek V4.1 Flash95.2284B977KMIT— (estimated)
5. DeepSeek V4-Flash94.9284B977KMIT— (estimated)
6. Ternary Bonsai 27B94.327B256KApache 2.0— (estimated)

Best pick for your memory budget

The strongest model overall is rarely the right answer — what matters is the strongest model that fits the memory you have. These picks are re-ranked per tier, so each one uses its budget rather than simply being small.

MemoryTypical hardwareRecommended models
8 GBRTX 4060, RTX 3070, base MacBook AirQwen3-Coder 8B (86.8)
Qwen 3 8B (86)
IBM Granite 4.1 Granite 4.1 8B (85)
12 GBRTX 3060 12 GB, RTX 5070Qwen 3 14B (88.9)
DeepSeek R1 Distill Qwen 14B (88.3)
Qwen3-Coder 8B (85.7)
16 GBRTX 5080, RTX 4080, RX 9070 XTQwen 3 14B (88.9)
DeepSeek R1 Distill Qwen 14B (88.1)
Qwen3-Coder 8B (84.8)
24 GBRTX 4090, RTX 3090, RX 7900 XTXGemma 4 31B (100)
Qwen 3.6 35B-A3B (100)
Qwen 3.7 35B-A3B (100)
48 GBRTX 6000 Ada, MacBook Pro M4 Max 48 GBQwen 3.7 35B-A3B (100)
Qwen 3.6 35B-A3B (99.6)
Gemma 4 31B (98.7)
128 GB+Mac Studio, DGX Spark, multi-GPUQwen 3.7 35B-A3B (97.7)
Qwen 3.6 35B-A3B (97)
Gemma 4 31B (96.4)

How this ranking works

Weighted like a coding workload with the licence sensitivity of an enterprise one, and a long-context floor for log and diff analysis. The reason this workload runs locally at all is usually that the material cannot leave the network, which is why licence weight is high (0.7).

Worked example — Qwen 3.7 35B-A3B: capability 93.3 × 0.421, quality 92.7 × 0.248, context 100 × 0.161, license 100 × 0.078, accessibility 80 × 0.093 + 6 tag bonus (reasoning, coding).

Requirements applied: context floor 32,768 tokens (ideal 262,144), quality floor 60, licence weight 0.7, latency weight 0.4.

Running security analysis and defensive research locally

FAQ

What is the best local LLM for security analysis and defensive research?

Qwen 3.7 35B-A3B, scoring 99.5/100 against this workload's published requirements. 109 models qualified.

What hardware do I need for security analysis and defensive research?

A credible answer starts at 8 GB of memory. Larger budgets unlock materially stronger models — the table above lists the best pick at each tier.

How were these models ranked?

Weighted like a coding workload with the licence sensitivity of an enterprise one, and a long-context floor for log and diff analysis. The reason this workload runs locally at all is usually that the material cannot leave the network, which is why licence weight is high (0.7).

Hardware for This Workload

Related Workloads

Top Pick

Tools

← All workloads | Check your hardware