A practitioner-first program for blue and red teams: AI embedded in triage, detection engineering, incident response, hunting and offensive operations — and every module measured by an operational metric, not an essay. Flagship deep-dive: SEC5xx — Detecting and Responding to AI-Generated Adversary Content, a 5-day SANS-format course.
SOCs are not short of AI. They are short of people who can run AI inside their own workflow — and prove it moved a number.
of organisations rank false positives as their #1 threat-detection challenge — and it is getting worse year over year.
of analysts spend over half their time on tedious manual work. The single biggest time sink: reporting.
of teams spend more time maintaining their security tools than actually defending the organisation.
That is a training gap, not an engineering gap. SANS SOC Survey 2025: 42% of SOCs deploy AI/ML out of the box with zero customisation, and GenAI tools score the lowest satisfaction of any SOC technology. Meanwhile SANS and GIAC have named the destination — four AI-focused certifications by end of 2026, and an AI Career Framework defining roles such as AI SOC Orchestrator. What is missing is the structured, role-based path that takes working analysts and operators there. This program is that path.
Every module exists because a measured, sourced practitioner problem demands it — cross-referenced from the SANS SOC and Detection & Response surveys, Tines Voice of the SOC, Splunk State of Security, CrowdStrike GTR 2026, Mandiant M-Trends 2026, Verizon DBIR 2026 and ISC2 Workforce Study 2025. Read the full evidence annex →
| Real challenge | The number | Trained in |
|---|---|---|
| Alert overload & false positives | 73% rank FPs as the #1 detection challenge; over 60% see them frequently (SANS D&R 2025) | B1 · SEC5xx Day 1 |
| Manual toil & reporting | Reporting is the top time sink (50.4%); 69% of SOCs compile metrics manually (Tines · SANS SOC 2025) | B5 |
| Identity-first, malware-free intrusions | 82% of detections are malware-free; credential abuse appears in 39% of breaches (CrowdStrike GTR 2026 · DBIR 2026) | SEC5xx Day 2 · B2 |
| Machine-speed attacks vs human-speed triage | Average breakout 29 minutes, fastest 27 seconds; access hand-off down to 22 seconds (CrowdStrike · M-Trends 2026) | B3 · SEC5xx Day 5 |
| Voice social engineering of help desks | Vishing is now the #2 initial infection vector (11% of intrusions) (M-Trends 2026) | SEC5xx Day 2 |
| Tool sprawl & data gaps | 78% run disconnected tools; 57% lose investigation time to data-management gaps (Splunk 2025) | B6 |
| Vulnerability exploitation & exposure overload | #1 breach vector at 31%; zero-days increasingly exploited before patch release (DBIR 2026 · M-Trends 2026) | B2 · B4 |
| Shadow AI in the business | Of the 45% of employees using AI at work, 67% do it through personal accounts (DBIR 2026) | S1 |
| AI skills gap | AI security skills are the #1 rising skill demand (41%), two years running (ISC2 2025) | C1 · whole program |
Every module is anchored in a task security personnel already perform, and its exit test is a measurable improvement on that task. One rule governs scope: if a module cannot name the workflow it improves and the metric it moves, it is cut.
Model training, data engineering, MLOps, knowledge graphs — builder skills. Analysts don't train vision transformers, and no curriculum hour here pretends they will.
Prompting on real cases, retrieval from the user side, model failure modes, evaluating output, and safe handling of sensitive telemetry — including local models where cloud is off-limits. Just enough AI mechanics to run it well; 70% of the time lives in security workflows.
Blue and red tracks can be taken independently; S1 and the capstone are shared.
| Module | Built around | Metric it moves |
|---|---|---|
| C1 · AI Literacy for Security Work CORE | Daily casework with an LLM assistant — with and without AI, plus error analysis | Baseline: knowing when to trust output |
| B1 · AI-Assisted Triage & Investigation BLUE | The alert queue and the phishing inbox — enrichment, summarisation, query drafting (SPL/KQL) | Time-to-verdict · triage error rate |
| B2 · AI for Detection Engineering BLUE | Rule backlog and coverage gaps — Sigma authoring and tuning, validated against attack replays | ATT&CK coverage · false-positive rate |
| B3 · AI in Incident Response & Forensics BLUE | Timelines, artifacts, reporting — with evidence-integrity rules when AI touches evidence | MTTR · report turnaround |
| B4 · Threat Hunting & CTI with AI BLUE | Hunt hypotheses and intel feeds — IOC extraction, campaign clustering, poisoned-intel handling | Hunt cycle time · intel throughput |
| B5 · SOC Automation with AI Agents BLUE | SOAR playbooks, reporting and ticket toil — guarded agent workflows with human approval gates | Case cycle time · reporting hours · escalation quality |
| B6 · Engineering the SOC Data Layer BLUE | Tool sprawl, pipelines and log economics — normalisation, coverage and retention strategy, AI-assisted parsing and schema mapping | Maintenance hours · coverage per € ingested |
| R1 · AI-Augmented Offensive Operations RED | Recon, phishing, payload iteration — every technique paired with its detection (purple format) | Engagement prep time · detection of AI-enabled TTPs |
| R2 · Red Teaming AI Systems RED | Prompt injection, jailbreaks, RAG exfiltration and tool abuse against an instrumented assistant | Findings reproducibility · time-to-report |
| S1 · Defending Enterprise AI SHARED | Your own copilots, RAG and agents — shadow-AI discovery, LLM app monitoring, AI incident playbooks | Coverage of the AI attack surface |
| Capstone SHARED | Deploy one AI-augmented workflow in your own environment; measure before/after; defend the result | The metric you chose |
Where the flagship fits: SEC5xx instantiates the detection side of this map — B1/B2 applied to AI-generated adversary content, S1's enterprise-copilot defense, and R2's tradecraft inside its labs — packaged as a 5-day SANS-format course on the SEC450 graduate pathway.
Five days, threat-driven by day, the detector's stack woven in — closing with an 8-hour immersive capstone against an adversary built to make your own agents lie to you.
| Course | What it covers |
|---|---|
| SEC450 | Analyst uses AI in the SOC |
| SEC598 | Team automates with AI |
| SEC535 | Red team attacks with AI |
| This course | Detection + response for adversary content generated by AI |
Fluent, locale-correct phishing at scale; fake-CAPTCHA lures up 563% in one year.
Help-desk impersonation and MFA-reset fraud — increasingly with cloned voices. Arup's $25.6M case is the ceiling, the help desk is the daily floor.
Zero-click M365 Copilot data exfil; GenAI tools exploited at 90+ organisations.
End-to-end agent operations; AI-enabled attack volume up 89% year over year.
Ransomware calling an LLM at runtime to generate payloads per victim.
Compromised PyPI packages exfiltrating cloud credentials and ML pipeline secrets — scaled to ~4TB.
Course hours follow this ranking: the daily and surging classes get the deepest treatment; rare classes get detection patterns, not full days.
Deployment decision, embeddings, RAG for detection engineering, plus the first threat class.
Where 2026 intrusions actually start: credentials, sessions, help desks. Synthetic voice is one module — sized to the evidence, not the headlines.
LLM-authorship signals, polymorphic malware, the EchoLeak class, guardrail stack as detection telemetry.
Detect adversary agent telemetry, harden your own agents, audit ML artifact provenance.
8-hour immersive IR against PROMETHEUS-7 attacking Verdancy Health.
This course assumes SEC450 as prerequisite. It does not re-teach the RAG, agent, or Ollama labs that SEC450's 2025 refresh already covers — Day 1 begins where SEC450 ends. The positioning is intentionally aligned with the SEC450 graduate pathway.
EchoLeak — zero-click M365 Copilot exfil
ESET PromptLock — first LLM-runtime ransomware
CrowdStrike GTR: 82% of detections malware-free, breakout down to 29 minutes
M-Trends: initial-access hand-off down to 22 seconds; vishing now the #2 vector
"For eight hours, you defend Verdancy Health against PROMETHEUS-7 — an AI-orchestrated adversary that has studied your AI SOC, knows how it reasons, and built an attack designed to make your own agents lie to you."
Verdancy Health Cooperative — a 14,000-employee regional healthcare insurer whose CISO publicly bragged about its 'agentic AI SOC'. PROMETHEUS-7 — a financially motivated crew — scraped the talk and built the campaign around defeating that specific stack.
Pass bar 700/1000 for GIAC capstone credit.
GAIDA — GIAC AI Detection Analyst (proposed)
Browser-based on pre-provisioned EC2
3 pre-built scenario variants
5 days / ~36 CPE hours
Each module runs as a 3–4 day intensive or six half-days live online, with 60–70% of the time in labs on replayed telemetry and range infrastructure. Bring your own sanitised telemetry — encouraged.
Skills-based only: perform the triage, ship the detection, execute the red team engagement, present the capstone measurement. No written exams, no essays.
A single module stands alone; a completed track earns a Blue or Red practitioner certificate; both tracks plus capstone complete the program. Completed tracks credit into the Steinbeis M.Sc. as recognised prior learning — the degree is an optional bridge, not the entry barrier.
Because AI tooling has a short half-life, labs are refreshed quarterly — and taught by working practitioners.
Master's degree in IT Security
15 years as Network + Security Architect
Master class at Universitatea Politehnică București (UPB) — Romania's top engineering university · upb.vexpertai.com
4-hour hands-on workshop at AutoCon 5, Munich, June 2026 — premier European network-automation industry conference
Active relationship with Packt Publishing
vExpertAI recognition; 3+ years developing AI curriculum for network and infrastructure engineers
The intersection of AI tooling and network/security infrastructure is the exact technical territory this program covers — and the territory Ed has been building, teaching, and publishing in for the past three years. Past delivery: graduate-level instruction at UPB (Bucharest) and conference-format workshops at industry events including AutoCon 5 (Munich, June 2026). Continuous practitioner work via vExpertAI consulting.
Co-author with John Hubbard from blueprint forward.
Position SEC5xx as the SEC450 follow-on in the curriculum map — and pressure-test the program map above against the field.
Pilot one program module — B1, AI-assisted triage — as a single instrumented workshop. Time-to-verdict and error-rate data decide the rest.
Munich, Germany (CET/CEST)