Visão Geral
Este curso apresenta o uso de IA Generativa para apoiar atividades de SOC, incluindo análise de alertas, investigação de logs, criação de consultas, documentação e resposta a incidentes.
Conteúdo Programatico
Module 1: Generative AI for SOC Operations
- Generative AI fundamentals
- Large Language Models
- SOC use cases
- AI-assisted analysis
- Security workflow integration
- Human-in-the-loop
- AI limitations
- Responsible AI
- Security considerations
- Generative AI adoption
Module 2: AI-Assisted Alert Analysis
- Alert summarization
- Alert classification
- Alert prioritization
- Context enrichment
- IOC analysis
- Event correlation
- False positive analysis
- Investigation assistance
- Analyst validation
- AI-assisted triage
Module 3: AI-Assisted Log Analysis
- Log interpretation
- Event correlation
- Authentication analysis
- Windows Event Logs
- Network logs
- Endpoint logs
- SIEM queries
- Query optimization
- Timeline generation
- Log investigation
Module 4: AI-Assisted Threat Hunting
- Hunt hypothesis generation
- IOC analysis
- TTP identification
- MITRE ATT&CK mapping
- Query generation
- Behavioral analysis
- Threat intelligence enrichment
- Hunt prioritization
- Detection development
- AI-assisted hunting
Module 5: AI-Assisted Incident Response
- Incident summarization
- Timeline construction
- Evidence organization
- Attack chain analysis
- Response planning
- Containment recommendations
- Investigation documentation
- Executive summaries
- Human validation
- AI-assisted response
Module 6: Secure Use of Generative AI
- Sensitive data protection
- Prompt security
- Data leakage
- Hallucination management
- Output validation
- Access controls
- AI governance
- Security policies
- Auditability
- Secure SOC AI practices