AI is revolutionizing Security Operations Centers (SOC) by automating alert triage, threat hunting, and incident response, with AI agents capable of performing tasks traditionally done by human analysts while requiring human oversight for accountability. The evolution progresses from traditional manual SOC to automated SOC using SOAR platforms, then to AI-assisted SOC with co-pilot systems, and finally to agentic AI SOC where autonomous agents handle entire investigation workflows. Key AI technologies include machine learning for pattern recognition, deep learning for complex analysis, and Large Language Models (LLMs) for natural language interaction, with practical implementations using tools like N8N for no-code integration and MCP for standardized tool communication.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
AI SOC Analyst Detailed | Day-5 | 30 Days SOC Challenge | Link below
Added:All right. So AI is changing how security operations team detect, investigate and respond to threats. In this video, you will learn the fundamentals of AI, LLM, AI agents, MCP and AI sock technology stack. We will also explore practical AI use cases for modern sock team. These skills will help you prepare for the future of cyber security career which is now. and I'll take you through the actual AI workflows which you can use yourself in the lab.
Join us for 30 days sock challenge on hex cam. Launch your free labs and subscribe to the channel for more practical sock content. All right. So AI powered sock or AI sock. Let me make one thing very very clearly. There's a lot of rumor that AI will replace their job.
AI will replace the cyber security sock analyst job. DFIR job, malware analysis job and even a lot of other industries was also having the same fear but I can confidently talk about cyber security.
Cyber security job market is only growing after AI it's even more strong.
So AI is not going to replace the sock itself or neither the sock analysis. It it actually changes what sock can keep up with. It actually help the sock analyst to and empower them and also gives more opportunity more variety of threats to look into. Okay. Now let's understand what are we going to cover in this video. First we are going to learn the AI in get the introduction of AI in cyber security. We will learn about the evolution of sock from traditional to the current and next generation sock and we'll talk about we'll go through some AI fundamentals first. It's not going to be security related but it's really important for you to understand then we will learn about the LLMs which is not in detail but important to get the idea how AI can help the cyber security.
We'll learn about the AI agents and multi- aent system as well. Then we'll learn about the AI sock tech system and then we will learn about the uh how we can use some no code tools for AI integration with the sock. Okay, we will also go through some AI use cases as well in the sock. We'll learn about the future of AI powered sock you know which is very important to understand and finally we will conclude. Let's understand few things. What's the definition of AI? AI is a software. I mean there are many definition but let's take some of the simplest one. It's a software. It can be considered as a software that perform the task normally require human intelligence. So the the task that only require human intelligence can be done by the software. Okay. Requiring patterns, understanding languages or making judgment call. Let's go a bit little you know further and um artificial intelligence is a technology it's another definition that enables the computer and machine to simulate the human learning okay simulate the human learning comprehension and problem solving decision making creativity autonomy that's massive that's what the AI delivers and that's what you can feel with charge claude Gemini and everything Okay, let's understand why AI is changing cyber security. Why? So alert volume in in in even a very small or midsize sock you can expect probably thousands of alerts every day on an average. Kim that's huge even after using security automation tool like sore the numbers are reduced probably by 20 25% but that's still you know significant number right another reason is the analysis shortage uh you might have seen lot of news and we also talked about it uh millions of unfilled cyber security job that's happening primarily because of skill shortage there's a demand and supply mismatch match with from the professional analyst right and that's that's the reason why millions of unfilled roles are there in worldwide and um AI is currently the you know good reason for any sock team to adapt right [snorts] because they can't really you know hire professional uh professionals so quickly that's why AI is their preferred options next is the attack speed as well now if you See attackers are always ahead of the defender. So they are using the AI very fast and there you know now the sock team the defenders the organization has a very very good reason to adapt it fast enough. Right now let's talk about the major benefit of using AI. First is definitely the speed. Now if they because the attackers are using AI to build the fishing email to build um you know to build the system for pentesting to automate the entire pentesting to look at different scenarios if their persistence fails or something. So they are using AI to build the exploit malware and everything. Uh we have no choice but to use it right. So speed matters a lot. scale to handle a large large volume of alerts to investigate uh any you know incidents or maybe to perform the threat hunting AI is definitely valuable and helpful and also the consistency because you know there could be a situation workflows has been created in the past by human but it doesn't handle a specific situation and may fails right uh that's why consistency matter and that's possible with the AI let's talk about the some limitation as well like uh confidentiality is the problem because if you if you are using any paid tool you might end up sharing some sensitive data I mean I'm talking about the LLMs right like chat GPT or claude or any other um AI tools as well you might end up sharing some confidential data so that's a risk need we need a lot of data to train our AI especially about the security as well so that's another limitation that we we go through um we can't own the business context and accountability as well that's another you know limitation with it let's talk about the AI and traditional automation this is the traditional automation like with the sore it follows a fixed uh approach where we create workflows and they have multiple condition if this happen if it is malicious it will go to this if it is not malicious clean traffic then it will go to this and This workflow may just send an email. This workflow may create an incident and assign to the level two team. Right? So this is all if and else kind of a situation. There's no real time intelligence happening. That's possible with AI. Right? Uh it's kind of very predictable with because with the automation we follow workflows.
Workflows are all created by human at the end right. So it it is meant to be predictable and at most of the instances there are human in the loop. So uh we need human to verify on on very important stages. Right? If you look at the AI, it learns the pattern instead of following the fixed rule. In future we will learn about different agents which can understand different situation, different scenarios and take the actions accordingly. Right? I mean it also adapts to different variation in the rules and it might be able to create the rule itself right and we needs the oversight instead of rule maintenance but honestly I would say AI also needs human in the loop right we also require human attention or intervention as well with even with the AI but it it is getting developed in a way that there's a need of less human intervention right so that's a benefit of using AI Okay. So now let's talk about the evolution of sock. Okay. It started with the traditional sock as we all know automated sock, AI assisted sock and agentic AI sock. Let's learn about each of them one by one. Okay. Traditional sock as you can imagine in the traditional sock we have you know we have the sock premise where there are multiple department right? Uh you can have level one sock analyst maybe three sock analyst in this two sock analyst two in this department and then there can be threat hunter uh detection engineering team all in this team right now in the manual uh in the manual sock or traditional sock all of all the things are done manually by the analysis itself from the initial triage which takes most of the time that's where you know I I I I don't think currently any organization is doing all manual you know triage themselves. Uh I'm not saying they are using AI all of a sudden. Nobody is using AI uh completely. Probably I could say maximum 20 20 to 25% organization might be using it. um I'm not 100% sure about it but most of the organization are currently using the automation with that right but in this case we are only talking about the traditional sock so in the traditional sock the entire triage is done by the sock analyst level one engineer where they look at the alert they perform the initial triage to understand if it is a false positive or if it's a real threat and then they might assign that incident to the level two team Right? And then they will perform the incident response process from containment to eradication to recovery to reporting and everything.
Right? So and when we talk about the level three again that is also all manual they it's all role based detection. So level three team creates the rules themsel it goes to the SIM solution or maybe on the EDR itself and based on that the uh alert will be triggered. Right? So it's a fully analystriven sock. That's traditional sock. In the automated sock, the analyst the sock system, the entire sock including their SIM software, their EDR software, ITSM and everything even thread intelligence, CTI system as well.
All of them are connected to a fabric called sore. All right. This saves the time. This this saves the analyst from the alert fatigue as well because the secur products like phantom um you know from splunk or polo alto cortex sim solution or it can be times which is now getting very popular or swim lane. These are all security orchestration and um automation response tool. This basically create a workflow of for every alert and then perform the initial triage. All the all the initial triage which in the traditional sock was taken care by the sock analyst level one probably 40% of those works are offloaded to the security operation I mean sore platform right so sar platform orchestrate the response process it might perform the basic incident response as well it's all driven based on the playbook for every workflow there will be a playbook and it has a basic automation it's still created by the human itself self it's still created by the sock analysis or detection engineering at the end but it's all it's all predictable it's all created uh based on a certain alert right let's talk about the AI assisted sock in this case you know we have sock analyst all the analyst working currently but analyst the let's say L1 analyst they will be using the AI as an assistant Right? It's like a co-pilot system. You might have heard about this co-pilot product suite from uh Microsoft a lot. So Microsoft provides the Microsoft security co-pilot as well. So they they own all the tools from Microsoft. If you talk about Microsoft Sentinel, which is the SIM product, you know, their Microsoft Sentinel product, their Microsoft Defender for EDR product, they all works with the Microsoft Copilot. Okay. So this is kind of a they this is kind of a helping them right the the analyst with the additional context uh saving their time from thread intelligence lookup saving the their time with the initial triage activity. Um if let's say an analyst need to you know let's take an alert where the analyst got an IP address right and he need to verify all the machine where there would be a connection to this IP address right from all the machine for this say case he might have to create sort of a rule he might have to come up with a a new rule to identify all the machines um you know uh having a connection with this external IP IP address or possible C2 observable or IOC whatever it is. He might have to come up with that rule that might take probably 10 minutes to create or come up with this idea with the co-pilot or AI assisted sock kind of a thing. it you just have to tell him on the natural language right you can just tell the chat on the chat itself on the scope software itself uh give me just like this right give me all the machines talking to this IP and then you can enter the IP address right so it will give you the exact answer that you're looking for right so that's AI assisted sock there's a there's an human human in the loop it's AI generated report cut documentation times and that's a major benefit right now if you look at the agentic AI sock that's where the major value ad comes in and in this case what's really happen is you can actually outsource the entire sock L1 job to this AI assisted sock okay and what exactly happen is for every activity that could be done in the sock analysis level one which could be initial triage okay bas basic security investigation uh basic investigation. Okay. Or let's say you might have to do some sort of a uh threat hunting by the level three uh level three team for level three team as well or maybe basic incident response for isolating the machine from the network. For every activity for every major activity you can actually create an AI agent. Right? So you can create an AI agent for every major activity or maybe minor activity and that AI agent will take care of its job by itself right and then you have multiple agent and all of them can start talking to each other and take a decision take the appropriate decision itself and these are like all autonomous workflow that runs without a constant prompting you don't have to prompt to the agents you can just verify you can look at the alerts on the sim these all agent can take the alerts from the sim from the EDR and perform those basic investigation or initial triage itself right so that's a benefit of agentic AI sock and we will going to look at a bit more in detail in further slides and for sock analyst of course this is not going to take away the job of a sock analyst it's just that um you know sock analyst will be there um looking at most of the alert um it's just that sock analyst will be getting promoted to a different role altogether if you are onboarding solution like this right so that's the major benefit that you will see and the role of analyst is actually evolving from performing the repetitive task monotonous job alert fatigue to supervising the AIdriven investigation it's not that AI will never fail it's just that you have to supervise them if If it is doing anything wrong then you probably have to uh add some more data uh prompt it uh so that it can be fine- tuned. So now let's get the fundamentals right. AI fundamental we learn about the AI definition in the beginning already but just to give you an idea AI is a broad topic uh it's mimicking the human intelligence or intelligence itself right so example could be chess playing software self-driving car these are all you know general way how we define AI so AI is just an umbrella term right so in this the first concept that we should learn about is the machine learning okay this is most practical use case um you know because this is how the AI the evolution of AI started it's a subset of AI as it learns the pattern from the data for example if you have you can give a context saying that if the email okay contain which is very much simple to do has a text inside like win money or when get a faster money okay or get rich in 30 days then mark that email as spam so That's a simple filter. But with machine learning, what you can do is we you can give thousands of spam email and non-spam email which has that kind of a text into it and machine learning will take the action accordingly. Right? So that's possible with the machine learning. So fraud detection, product recommendation in the e-commerce portal, credit scoring, uh productive customer churning, uh this is all possible with the machine learning. Right? Now let's talk about the deep learning. Deep learning is an advanced version of machine learning that's has a layered network approach. It's a neural network uh that it uses just like a human brain.
So instead of manual manually creating different features deep learning actually automatically learn the complex uh pattern complex behavior. So that's why it is widely used for images uh speech videos and understanding different languages and widely used for use cases like face recognition uh speech to text or autonomous driving.
This is where deep learning is widely used. Now let's talk about the generative generative AI. This is where this is what we see currently uh with Chad GPT with claude with Gemini.
Generative AI is using the deep learning itself to generate new content because it generate a new content. It don't analyze it, right? So it actually it uses a deep learning to come up with a new kind of a content, new kind of a text or document, images, video, PPT, anything right so you can uh in the traditional machine learning system you can is it is it suspicious or is it malicious? That's kind of a question you can ask after giving a file. But in case of generative AI, you can ask the AI itself, chat, GPT or claude to write a professional email and it will give you you can ask the AI to give you the uh non-spammy uh email or a professional quotation as well. So that's pretty much possible with it. Right? Now let's talk about the fifth concept which is LLM. Right? uh LLM is basically a very specialized form of generative AI that's trained on different languages right so it's uh it's basically it's basically built based on different large amount of a data to understand different context different type of text uh understand the human language and generate the human understandable language as well so that's possible with the large u large language language model. Okay. So types whatever you see currently like GPT model claude Gemini Llama or Lama this is all possible. So LLM can actually answer questions can understand the question precisely. It can write the different codes. You must be knowing about cloud code um you know chat GPT codeex this is all possible. It can it can also translate uh different languages as well. get a bit more deeper. Let's understand the LLM and its con its concepts. Right? So first let's understand about tokens and context window. Token is basically the smallest unit of any text maximum. It's a four character or three fourth of any text.
Right? That's token smallest unit of a text. And what about context window? Now this is also very important. This is like a maximum amount of a token on input output direction that you can transfer at any any time that's a working memory for any LLM right and that's defined as context window. Next is prompt engineering. This is from the user point of view. Usually um you must be knowing about it that whenever we we want to get a very specific and uh appropriate answer we have to make sure the prompt is perfect. For that you there are multiple framework use you have to start with the persona then you define the context and if you have any sort of a reference that's even better right so maybe for example I'm I'm looking for a proper diet chart so assume I can ask JP or any LLM that assume you are a professional dietician and um I'm suffering from this and this this and um give me a chart and that will fit my goal and I can give some sort of a reference to the specific guy and I can share some reports health report as well and based on that it will give me the diet chart right let's talk about the embedding embedding why embedding is used because uh let's understand the purpose of embedding first of all see lms cannot read the words directly it can only understand the numbers so embedding basically converts this converts these uh words, sentences, paragraph, text into long list of numbers, right? And this numbers are called as vectors. Okay? Now, um the these are then become useful for any LLM. So, the model if you talk about the rag at the end, which is basically a retrievable augmented generation that's basically uses the embedding that's the one which actually is the way we give an AI model an open book exam. using the math vector that we have. So that's uh with the help of vector it will get the relevant answer before it can generate the u before it can show the answer to any users. Okay. So let's understand a bit more deeper. So how rag actually uses the rag uses the vector specifically we have three step. First is the vector search. Okay, as you know whenever the user enter a question it will be converted by the embedding into uh different words into different vectors and your question will be turned into vector and the system match it against the database of all the documents that is present right so all my questions will be converted converted into vectors and then it will be con compared against all the database created by the LLM itself now after that's done Then there will be a retrieval phase. In the retrieval, the system grabs the exact text blocks connected to those uh those winning uh vectors I would say and once those words are have been selected then the AI reads those specific text blocks and it will give us those uh words in the real time. That's how the LLM exactly works and in fact in the real time it rag itself tells you if those data for those data do I need to go to the external site and grab those output right so that's that's about rag now let's understand about the AI agent and multi- aent system AI agents if I talk about the single agent system they know everything they can use the LLM by itself and they have a specific goal so if I talk about the single agent they uh They handle a full task itself autonomous um and they are simple to build. You have in different agent on chat GPT on cloud as well. You can just tell him this is the example. This is the task you have to do. Grab this data.
Give me the feeds every day at 10 p.m.
or something. It will handle it because it has a specific goal, right? So it's easy to manage. Uh but it's just that it will be just one agent because you have a specific goal in your mind, right? You can also use multi- aent system where every agent will have one task. Maybe from security point of view it can be triage, it can be enrichment, it can be reporting and the agents will hand off work to each other. All the agents can talk to each other directly without any [clears throat] human intervention. Now it's very powerful more complex for the larger AI sock tech stack. Okay, which is very important. What all components needed to build a AI sock infrastructure. Okay, first is the AI application directly. You can you can get the entire fully plug-and-play kind of AI sock. You don't have to build anything additional yourself. Then AI agent framework. If you want to build something yourself from scratch, then you can possibly go for AI agent framework. [snorts] there basically a standardized format that basically allow all the AI agent or AI models to talk and interact with the different external tools maybe anything maybe service now similarly uh it also allow the security tools to talk to directly to the models as well right just like you can talk to the Splunk or Wazu directly from your cloud agent that's interesting right so you can just type on the cloud agent that how many agent I have how many agents I have or how many healthy agents I have. So it will tell you the answer.
Even similarly you can ask plunk to uh maybe on the cloud agent cloud agent itself how many uh security alerts I have. Right. Next we have LLM the large language model that provides the reasoning analysis you this is very important because without this our AI would be incomplete whether you use the commercial option or maybe the open-source you know your local model as well that's fine finally the security infrastructure of course that includes your sim edr and all those product let's understand each one of them one by one these are all vendorbuilt AI security platform from so you don't have to do anything into it.
Profet is very popular. Drop zone uh uh this is the product made by uh crowdstrike which is Charlotte uh Microsoft security copilot which is like a AI it is is basically a kind of a co-pilot system assisted sock but again this has also been invol evolved in past few months. So this is also a very great tool to work with. Okay. If you buy an AI application like this you don't have to think about anything else.
Now if you are thinking about building the AI sock system yourself where you have the security infrastructure but you want to build this all those AI agent who are specialized on a specific task then this is what you should look for you can use crew AI crew AI or you can use the autogen or maybe open AI which is again costly one so I don't recommend initially you can also go for lang chain lang graph as well crew oai is my favorite because with this you can create multiple AI agent and you can ask I mean you can give a specific task to a specific AI agent with connected LLM as well. So you can connect LLM to this agent, you can connect LLM to this agent and you can specify uh you know you can give a specific task maybe this agent will perform the initial triage. This will perform the threat hunting.
Okay, this agent will perform the uh incident response maybe basic incident response, right? And you can also tell them to coordinate with each other if they need any help. MCP and tool interaction. In this you can MCP is model context protocol. This allow any AI models like claw cursor or any custom one to talk to any security tool or any third party tool over a standardized format. Okay, standardize uh bridge itself. So you don't have to create one integration for every security tool, right? So that connects the AI tool to the external one. We have different MCP servers for Wazu uh Splunk MCP, Virus Total MCP, Jira MCP as well, right? So these are basically just a packages. Now how does it work? If you look at the before MCP what used to happen is you have an AI models like chat GPD you're using on your machine right the software you have cloud agent so if MCP wasn't there you have to create a unique you have to create an unique API unique API for slack unique API for drive unique API for GitHub and everything but with the help of LLM it's like a USB drive right uh you have a USB port station right doc station where you MCP works like a dock station and it allow any third party tool to directly interact with it. Right? So this saves time for anybody to build their own MCP or their own interaction with the AI model.
Right? And this is completely open source. Now let's talk about the LLM itself. It's a foundation model as we all know. These are some of the well-known and popular AI models we use for the AI sock system. Deeps very popular Quen quite popular. Mr. AI Olama as well. These both are commercial one.
Companies don't prefer a lot for them.
But for training or learning purpose, that's pretty good. Finally, security infrastructure. This is must to have.
Without this nothing will absolutely absolutely going to work. So you must have Wazu which is open source, elastic and Splunk as well as a SIM infrastructure. And for EDR you can of course go for Microsoft defender for endpoint or crowd strike or maybe sentinel one as well. So these are the must to have security tool then only your sock going to work. So let's talk about the no code AI integration because you see that it's it's not it's not that easy to build something from scratch.
You probably have to learn how to integrate the LLM with your security tool. you have to learn about using the right MCP there can be an error what if there is a solution which is no code right that's what the niten basically solves so so niten basically gives you the sort of a workflow and also an option to use different MCP call the AI agent I mean call the AI models directly call the security tools directly talk on the web hook or rest API as well right so you can create any sort of a workflow and then you can call, Wazu, Crowdstrike, Windows Defender, Elastic all in it. Right? So, let me take an example for it. You can see if you want to just try try it out. There are multiple labs on Hexam as well. You can visit Hex Cam, go to labs and under this click on Hex AI sock analyst. You will find all the labs. Uh I'll open one of them and in fact you can also do it. You can go to any lab, click on launch lab and this will take some time and your lab will be built. It will be dedicated in warm for you. Before we do that, let's understand the niten a little.
Annet is kind of a workflow uh creator.
So you can build your own a AI agent.
You can create your own workflows all in it. You can create different security workflows. That's it's one of the popular use case as well. And this is mainly human-driven. So it's a workflow.
It's not a multi- aent kind of environment uh where you can allow anybody to talk to anybody directly but it solves the purpose of not building you you don't have to build something from scratch. It's all building block right so I'll show you something here.
This is the pre-built workflow which we have in on our lab and you these are all workflows. You can see the configuration of them. Uh this is all web hook. So whenever there's a new alert on Wazu, there's a new alert on Wazu, the alert will be triggered here on the workflow itself through web hook and then the alert will be normalized and this will you know this will be a data parameter sent to the AI uh system and then we have an AI model as well which is from grock. So we just have to put the credential into it. The integration is all done by the enterain itself. You can also add a custom code into it to parse those data and you can then create an incident or maybe send an email uh from the enter itself. So it's all done with the drag and drop option. I can also show you when you go to the search option you can click on AI and under this you have multiple AI models from Google to you know from Google uh Gemini option to claw to chat GPD and anything in fact you can search for Splunk you have Splunk tools option and multiple actions associated with that you can also use elastic search as well and in fact you also have service now so you can see service now tool tool service now in here as well. So that's a benefit of using N10.
It mainly has three component. First is the hook. First is the trigger point which is this area. And next is where you actually normalize, you analyze the data, you perform certain action. You can add flows, you can transform the data. And finally you have the actions where you send the data. Maybe you forward the data to the email or maybe send it to any third party tools like service now or incident management tool.
All right. And now let's go through a demo of AI sock analyst. Okay. In this we are going to use AI model on a basic level to help us for the sock investigation. Okay. So you can go to the labs under this you can find sock analyst. We'll start with the easy one.
So AI malware hash investigator. In this lab, the purpose of this lab is basically to you know use the uh data coming in from virus total or hash output malware hash output and create a report and send it over the email or maybe ITSM2 like service now. Okay. So we'll launch the lab. This is the entire data and everything just to get a detail about it. So I will launch the lab.
Okay. And in meanwhile I'll just get the hash value of any malware. So I'll go to malware bazar. And let's get a hash value of maybe this. This is the hash value. I just copied SH 256. I'll open the N. We are using N security automation and orchestrator orchestration tool. It's quite impressive. You can see the multiple nodes in it as well.
So this is uh we have automated uh this entire process. So whenever a wazu alert comes in the the entire workflow can be triggered. So this is done using the web hook. You can see this is the web hook wazu um tool that is talking to and this goes to the virus total uh through the HTTP request and then we have a custom code. You can see the custom code which will parse the data coming in from virus total because virus total submit the data to multiple antivirus. And then we have different rules and condition and uh based on that this will give us the repetition alert. This is like uh we have a we have our own custom portal where it will notify just like a slack chat or Microsoft teams. So it's just that with this tool you can just go online and see the data as well just to simplify your life and um with this this will also generate the report with using the groth model. You can see grock model and our AI report generator. It will take certain data. You can see this is like an input data which will take a data with the hash value risk level. All the data comes in from the virus total and then it will parse the data creates the HTML data and send the create an incident on Trello. In this in in this case in the workflow we have used Trello. In the real world we'll be using service now. Okay. And then we have a malware report which will comes properly uh you know in HTML format which can be sent over the email. Okay. So let's execute this workflow. And this will immediately ask you to submit the SHA value hash value. Why it should be automated right? Because what's really happening is in case when we have an alert then it will execute automatically. You don't have to do anything. But I want you to experience this. That's why we have another option on here where you can add your own custom malware hash as well. So this is what it is right. So let's submit the data and this will get executed immediately after this. Perfect. Can you see this? The workflow has been executed and the incident has been created into the Trello as well. From here you can see this and uh you can also see the entire report in here. If you want to see the incident on Trello, you can click on it at the bottom and you can see the incident has been recently created with the entire detail which can be sent over the email or maybe on to the service now. Okay. And um or this is basically used to trigger and this will be sent on your you know slack chat or maybe on Microsoft teams as well. So you see this this is like a you know notification option just like Slack works. Okay. So this is how you can automate everything. Whenever a new alert comes in, it will take the hash value of the file maybe file integrated check or any modification of the file and then it will submit to virus total and um then just to create the uh report it we it can use the LM model which might not take a lot of tokens as well and send the report uh to the email or slack chat. it it might not necessarily require to create the incident but in case it's malicious it can create an incident and open the ticket on the service now all right now let's talk about different AI use cases practical use cases okay first one is the AI alert triage I talked about it lot so it's very important you can score different alerts you can perform the initial triage by doing the threat intelligence lookup on virus total or alien vault and prioritize the incoming alerts as well.
You can also perform the log analysis using the AI sock different AI agents.
So you can create the explainer summarize the log log data raw data log as well. You can also do some sort of a primary thread hunting or coming up with different hypothesis based on different logs and the your organization context as well. But remember this is this is like giving a lot of information and context to any LLM. So make sure you kind of use your internal LLM models as well like Olama which is good and then detection engineering you can draft and tune the detection rules faster as well with this right. Next is thread intelligence you can enrich the IOC which is like a enrichment process itself for every alerts and correlate the context as well. Next is the incident response. I don't recommend building the entire incident response using the AI agent because um you know sometime there there are some incident response process which are not so business impacting but imagine like incident response steps like isolating the window machine right or maybe creating a fire rule this might disrupt the business right so make sure you partially create that incident response or there's always a human in the loop so that you know you approve improve them and it will be in effect immediately and report generation it's also very important you know simple use case I would say start building your AI sock now I'll just give you few simple workflow that you can think about and start building you can do some research and start building yourself most simplest one is the wazu MCP and cloud cloud AI integration for this you can also use the nitn for building it up or there are multiple open-source libraries available on GitHub repository. You can definitely use it.
And once it is connected, let's say this is my wazu in here and I'll be having my claw agent, right? My clawude agent and with this I have an MCP server connected, right? And then start asking few question once it is connected. Start asking like how many uh alerts I have, how many priority one or high priority alerts I have, how many agents are healthy currently, how many agents are connected and this will give you the result in table in proper format. Right?
Then you can start building the AI sock alert riage workflows on N. This is this is going to be very interesting. We have a lot of workflows created on our platform. There are many workflows I have created in the past on my YouTube channel as well. Go check it out. Okay.
Uh let's talk about the future of AI powered sock infrastructure. The future is definitely for agentic sock where we have multiple agent configured and talking to each other taking the uh actions uh doing the handoff as well.
Autonomous sock infrastructure where detection response and tuning is all done with minimum input. I'm laughing because this is a little tricky but this may take some time and might I personally feel this is definitely the future but uh it's not going to be easy it will take a lot of human effort and I personally feel even if we have autonomous soccer ready we still need human uh in the loop and we still need human working along with this because uh even if the small thing happen it might lead to a major issue in the entire sock right uh because remember one thing human needs accountability from human not the tool okay you can't make a a tool or LLM accountable for any business disruption right AI detection engineering this is definitely a future where you can have the AI to build new detection rules right AI threat hunter definitely yes AI sock manager will be a future where they will monitor all the sock analysis their performance how many incident they have closed they look at their uh learning path and everything and new analyst skills so by prompting by validation by AI oversight right let's now conclude everything that we have learned foundation we learn about AI ML deep learning LLM that aren't the same thing evolution we talked about the evolution of sock from traditional to autonom automated sock infrastructure, assisted sock infrastructure and agentic sock as well. Different tools from open source to MCP oriented commercial tool.
We talked about different use cases from triage through hunting detection and finally judgment because without supervising you can't have a proper sock running right finally thank you so much for h for watching this video. If you have any question do let me know in the comment section. I would love to answer them.
Related Videos

Expanding Stikbot thumbnails
leopoldshorts
2K views•2023-09-24

Digital Discrimination: Cognitive Bias in Machine Learning
redmonktechevents2974
4K views•2019-12-18

Evolutionary Approach to Clustering by Ujjwal Maulik
ICTStalks
279 views•2019-06-26

Rose Yu "Learning from Large-Scale Spatiotemporal Data"
networkscienceinstitute
2K views•2019-03-04

Stanford Seminar - Generalization through Task Representations with Foundation Models
stanfordonline
4K views•2025-07-14

Satellite-Based Wheat Yield Forecasting using GEE & Transformer Neural Network
gisrsinstitute
634 views•2025-06-15

Paradigm Shifts in Data Processing for the Generative AI Era: Robert Nishihara of Anyscale & Ray.io
GradientFlow
2K views•2025-01-02

How to Build Your Own GenAI-Based Knowledge Management System
2150GmbH
360 views•2025-06-03
Trending

2.4 BILLION Records Got Leaked...
DeepHumor
15K views•2026-07-22

Playstation NO DISC/NO BUY Fight Is Over...
DavidJaffeGames
4K views•2026-07-23

Should I buy a Sawmill?
essentialcraftsman
29K views•2026-07-22

Americans Confused in Australia for 17 Minutes Straight
IWrocker
17K views•2026-07-23