0:00
/
0:00
Transcript

D@S Podcast #62 - Training Analysts When AI Does the Investigating

SANS Institute's John Hubbard predicts the future SOC analyst won't investigate alerts, but will instead manage the AI agent army that does.

I sat down with John Hubbard, a leading instructor at the SANS Institute, and we explored some counterintuitive ideas, such as his argument that if you already trust a cloud vendor with all your production data, the concern over sharing investigation context with that same vendor's LLM might be misplaced.

We discussed a future where the SOC analyst's role evolves from a hands-on investigator to a supervisor, responsible for validating the output of an "agent army." Here are some of the key pragmatic takeaways from our conversation:

๐“๐ž๐š๐œ๐ก ๐ญ๐ก๐ž "๐‡๐š๐ซ๐ ๐–๐š๐ฒ," ๐ญ๐ก๐ž๐ง ๐ญ๐ก๐ž "๐…๐š๐ฌ๐ญ ๐–๐š๐ฒ": John's approach to education in the AI era is to first build a strong foundation by teaching manual processes. Only then does he introduce AI to accelerate those tasks. This ensures analysts develop core concepts while leveraging AI for the speed necessary to keep up with attackers.

๐‚๐จ๐ง๐ญ๐ž๐ฑ๐ญ ๐ข๐ฌ ๐Š๐ข๐ง๐ : One of AI's most powerful applications in the SOC is enriching alerts with business context. By dynamically pulling in data on critical systems or VIPs, AI helps analysts more accurately triage and prioritize the most significant threats.

๐€๐ˆ ๐Ÿ๐จ๐ซ ๐ƒ๐ž๐ž๐ฉ๐ž๐ซ ๐๐ž๐ซ๐Ÿ๐จ๐ซ๐ฆ๐š๐ง๐œ๐ž ๐ˆ๐ง๐ฌ๐ข๐ ๐ก๐ญ๐ฌ: SOC leaders can leverage AI to analyze team performance at scale. AI can process huge volumes of text from investigation notes to spot trends, identify areas for improvement, and facilitate knowledge sharing between analysts.

๐“๐ก๐ž ๐…๐ฎ๐ญ๐ฎ๐ซ๐ž ๐ข๐ฌ ๐€๐›๐ฌ๐ญ๐ซ๐š๐œ๐ญ๐ž๐: John foresees a future where analysts interact with a suite of interconnected tools primarily through a single chat interface. This shifts the analyst's role from hands-on-keyboard analysis to overseeing and validating the output of AI agents.

๐…๐ฎ๐ญ๐ฎ๐ซ๐ž-๐ฉ๐ซ๐จ๐จ๐Ÿ ๐ฒ๐จ๐ฎ๐ซ ๐œ๐š๐ซ๐ž๐ž๐ซ: Embrace the things that scare you, consistently find ways to apply AI to your daily challenges, and seek mentorship.

The episode is essential for anyone building or operating in a SecOps team. Check it out above!

Related Reading

Discussion about this video

User's avatar