CURRICULUM: Cyber Defense SEC450: AI-Enabled Security Operations: Hands-on Detection, Investigation, and Automation™ MAJOR UPDATE 5 Day Program 30 CPEs 19 Labs You Will Be Able To ▐ Define SOC mission and scope so analysts focus on what matters most ▐ Use threat intel to prioritize threats and sharpen triage decisions ▐ Analyze network, endpoint, email, and file evidence across the SOC toolset ▐ Separate observed facts from assumptions and AI- generated inferences ▐ Apply structured methods like ACH to reduce bias in investigations ▐ Write, test, and document detections using Sigma and YARA concepts ▐ Evaluate agentic AI workflows for prompt-injection risk and approval gates Who Should Attend This course is designed for security professionals who work in or support security operations: ▐ SOC analysts and intrusion detection analysts ▐ Cyber defense analysts moving beyond basic alert handling ▐ Incident handlers building stronger triage, evidence, and documentation skills ▐ Detection engineers who want more operational context for rule development and tuning ▐ Security engineers supporting SIEM, EDR/XDR, SOAR, case management, and AI-enabled SOC tooling ▐ Threat intelligence analysts connecting CTI more directly to SOC prioritization ▐ SOC leads or managers who need to understand how AI, automation, and analyst process fit together ▐ NICE Framework Work Roles ▐ Cyber Defense Analyst (OPM 511) ▐ Cyber Defense Infrastructure Support Specialist (OPM 521) GSOC Security Operations giac.org/gsoc Security Operations Centers are under pressure from growing telemetry volume, more complex attacks, constant alert noise, and increasing expectations for speed. At the same time, AI- assisted tools and agentic workflows are becoming part of the SOC toolset. Analysts need to understand what these systems can do, where they fit, where they fail, and how to keep human judgment at the right decision points. This course teaches SOC analysis as an end-to-end operational discipline. Students start with the mission and scope of the SOC, then learn how to use security tools, threat intelligence, network evidence, endpoint logs, email artifacts, file and malware indicators, structured investigation methods, and detection engineering to reach defensible conclusions. Along the way, they learn how to use AI effectively for summarization, triage, enrichment, drafting, detection support, and automation without confusing generated output for evidence. Business Takeaways ▐ ▐ Sharper triage and evidence review mean analysts spend more time on real threats Get more value from SIEM, EDR/XDR, threat intel, andç automation working together ▐ Speed up investigations with AI while preserving evidence and human decisions ▐ Turn investigation findings into tested, documented detections with Sigma/YARA ▐ Adopt AI with real controls: approval gates, audit trails, and least privilege ▐ Reduce analyst toil and burnout with better handoffs and documentation Build a team ready to oversee agentic AI and make defensible SOC decisions Syllabus Summary SECTION 1: Building the AI-Enabled SOC: Mission, Intelligence, Tools, and Workflow SECTION 2: Network Evidence and Agentic Enrichment: Protocols, OPSEC, and Tool Use SECTION 3: From Telemetry to Investigation: Triage, Structured Analysis, and Agentic Automation SECTION 4: From Phishing to Detection: Email, Malware Analysis, YARA-X, and Sigma SECTION 5: Operating the AI-Enabled SOC: Risk, Judgment, and Sustainable Performance For detailed course description, visit SANS.ORG/SEC450 John Hubbard Course Author In-Person WAYS TO TAKE SEC450 Live Online OnDemand