Applied AI for Security Operations — Practitioner Program

Train the workflow, not the technology.

A practitioner-first program for blue and red teams: AI embedded in triage, detection engineering, incident response, hunting and offensive operations — and every module measured by an operational metric, not an essay. Flagship deep-dive: SEC5xx — Detecting and Responding to AI-Generated Adversary Content, a 5-day SANS-format course.

2 tracks — blue + red 10 modules + capstone 60–70% lab time Skills-based assessment only Optional M.Sc. bridge
01 — The gap

The tools arrived. The operator skill didn't.

SOCs are not short of AI. They are short of people who can run AI inside their own workflow — and prove it moved a number.

73%

of organisations rank false positives as their #1 threat-detection challenge — and it is getting worse year over year.

SANS Detection & Response Survey 2025
64%

of analysts spend over half their time on tedious manual work. The single biggest time sink: reporting.

Tines, Voice of the SOC
46%

of teams spend more time maintaining their security tools than actually defending the organisation.

Splunk State of Security 2025

That is a training gap, not an engineering gap. SANS SOC Survey 2025: 42% of SOCs deploy AI/ML out of the box with zero customisation, and GenAI tools score the lowest satisfaction of any SOC technology. Meanwhile SANS and GIAC have named the destination — four AI-focused certifications by end of 2026, and an AI Career Framework defining roles such as AI SOC Orchestrator. What is missing is the structured, role-based path that takes working analysts and operators there. This program is that path.

02 — What the data says

The curriculum is derived from what analysts and SOC engineers actually fight.

Every module exists because a measured, sourced practitioner problem demands it — cross-referenced from the SANS SOC and Detection & Response surveys, Tines Voice of the SOC, Splunk State of Security, CrowdStrike GTR 2026, Mandiant M-Trends 2026, Verizon DBIR 2026 and ISC2 Workforce Study 2025. Read the full evidence annex →

Real challengeThe numberTrained in
Alert overload & false positives73% rank FPs as the #1 detection challenge; over 60% see them frequently (SANS D&R 2025)B1 · SEC5xx Day 1
Manual toil & reportingReporting is the top time sink (50.4%); 69% of SOCs compile metrics manually (Tines · SANS SOC 2025)B5
Identity-first, malware-free intrusions82% of detections are malware-free; credential abuse appears in 39% of breaches (CrowdStrike GTR 2026 · DBIR 2026)SEC5xx Day 2 · B2
Machine-speed attacks vs human-speed triageAverage breakout 29 minutes, fastest 27 seconds; access hand-off down to 22 seconds (CrowdStrike · M-Trends 2026)B3 · SEC5xx Day 5
Voice social engineering of help desksVishing is now the #2 initial infection vector (11% of intrusions) (M-Trends 2026)SEC5xx Day 2
Tool sprawl & data gaps78% run disconnected tools; 57% lose investigation time to data-management gaps (Splunk 2025)B6
Vulnerability exploitation & exposure overload#1 breach vector at 31%; zero-days increasingly exploited before patch release (DBIR 2026 · M-Trends 2026)B2 · B4
Shadow AI in the businessOf the 45% of employees using AI at work, 67% do it through personal accounts (DBIR 2026)S1
AI skills gapAI security skills are the #1 rising skill demand (41%), two years running (ISC2 2025)C1 · whole program
03 — Design principle

Start from the workflow, not the technology.

Every module is anchored in a task security personnel already perform, and its exit test is a measurable improvement on that task. One rule governs scope: if a module cannot name the workflow it improves and the metric it moves, it is cut.

What stays out

Model training, data engineering, MLOps, knowledge graphs — builder skills. Analysts don't train vision transformers, and no curriculum hour here pretends they will.

What stays in (the 30%)

Prompting on real cases, retrieval from the user side, model failure modes, evaluating output, and safe handling of sensitive telemetry — including local models where cloud is off-limits. Just enough AI mechanics to run it well; 70% of the time lives in security workflows.

04 — Program map

Two tracks over a common core. Closed by a capstone in your own environment.

Blue and red tracks can be taken independently; S1 and the capstone are shared.

ModuleBuilt aroundMetric it moves
C1 · AI Literacy for Security Work COREDaily casework with an LLM assistant — with and without AI, plus error analysisBaseline: knowing when to trust output
B1 · AI-Assisted Triage & Investigation BLUEThe alert queue and the phishing inbox — enrichment, summarisation, query drafting (SPL/KQL)Time-to-verdict · triage error rate
B2 · AI for Detection Engineering BLUERule backlog and coverage gaps — Sigma authoring and tuning, validated against attack replaysATT&CK coverage · false-positive rate
B3 · AI in Incident Response & Forensics BLUETimelines, artifacts, reporting — with evidence-integrity rules when AI touches evidenceMTTR · report turnaround
B4 · Threat Hunting & CTI with AI BLUEHunt hypotheses and intel feeds — IOC extraction, campaign clustering, poisoned-intel handlingHunt cycle time · intel throughput
B5 · SOC Automation with AI Agents BLUESOAR playbooks, reporting and ticket toil — guarded agent workflows with human approval gatesCase cycle time · reporting hours · escalation quality
B6 · Engineering the SOC Data Layer BLUETool sprawl, pipelines and log economics — normalisation, coverage and retention strategy, AI-assisted parsing and schema mappingMaintenance hours · coverage per € ingested
R1 · AI-Augmented Offensive Operations REDRecon, phishing, payload iteration — every technique paired with its detection (purple format)Engagement prep time · detection of AI-enabled TTPs
R2 · Red Teaming AI Systems REDPrompt injection, jailbreaks, RAG exfiltration and tool abuse against an instrumented assistantFindings reproducibility · time-to-report
S1 · Defending Enterprise AI SHAREDYour own copilots, RAG and agents — shadow-AI discovery, LLM app monitoring, AI incident playbooksCoverage of the AI attack surface
Capstone SHAREDDeploy one AI-augmented workflow in your own environment; measure before/after; defend the resultThe metric you chose

Where the flagship fits: SEC5xx instantiates the detection side of this map — B1/B2 applied to AI-generated adversary content, S1's enterprise-copilot defense, and R2's tradecraft inside its labs — packaged as a 5-day SANS-format course on the SEC450 graduate pathway.

05 — Flagship course

SEC5xx — Detecting and Responding to AI-Generated Adversary Content

SEC5xx — Cyber Defense Curriculum

For eight hours, you defend Verdancy Health against an AI adversary that has studied your AI SOC.

Five days, threat-driven by day, the detector's stack woven in — closing with an 8-hour immersive capstone against an adversary built to make your own agents lie to you.

Three courses cover AI. None cover this.

CourseWhat it covers
SEC450Analyst uses AI in the SOC
SEC598Team automates with AI
SEC535Red team attacks with AI
This courseDetection + response for adversary content generated by AI

Six threat classes — ranked by how often SOCs actually see them.

Daily

AI-authored phishing

44% of AI-assisted initial access (DBIR 2026)

Fluent, locale-correct phishing at scale; fake-CAPTCHA lures up 563% in one year.

Surging

Voice phishing & synthetic identity

#2 initial vector, 11% of intrusions (M-Trends 2026)

Help-desk impersonation and MFA-reset fraud — increasingly with cloned voices. Arup's $25.6M case is the ceiling, the help desk is the daily floor.

Growing

Prompt-injection campaigns

EchoLeak CVE-2025-32711, June 2025

Zero-click M365 Copilot data exfil; GenAI tools exploited at 90+ organisations.

Emerging

Agentic intrusions

GTG-1002, Nov 2025 · NCSC/CISA guidance

End-to-end agent operations; AI-enabled attack volume up 89% year over year.

Rare, high-impact

Polymorphic AI malware

ESET PromptLock, Aug 2025

Ransomware calling an LLM at runtime to generate payloads per victim.

Rare, high-impact

AI supply chain

LiteLLM/Mercor breach, Mar 2026

Compromised PyPI packages exfiltrating cloud credentials and ML pipeline secrets — scaled to ~4TB.

Course hours follow this ranking: the daily and surging classes get the deepest treatment; rare classes get detection patterns, not full days.

Threat-driven by day. Detector's stack woven in.

01

Detector's AI stack + AI-generated phishing

Deployment decision, embeddings, RAG for detection engineering, plus the first threat class.

  1. 01.1What changed when adversaries got LLMs
  2. 01.2The detector's AI deployment decision (open-weight vs cloud)
  3. 01.3Embeddings as the detector's highest-ROI primitive
  4. 01.4RAG for detection engineering
  5. 01.5Detecting AI-generated phishing
  6. 01.6Anti-patterns to avoid
Read full Day 1 content →
02 · REBUILT FROM THE DATA

Identity attacks + voice social engineering

Where 2026 intrusions actually start: credentials, sessions, help desks. Synthetic voice is one module — sized to the evidence, not the headlines.

  1. 02.1The identity-first kill chain: infostealer → broker → ransomware
  2. 02.2Vishing & help-desk impersonation (incl. cloned voices)
  3. 02.3MFA bypass, session hijack and token-theft detection
  4. 02.4Valid-account abuse in cloud (35% of cloud incidents)
  5. 02.5Precursor hunting: the credential-to-ransomware window
  6. 02.6IR playbook: identity compromise + out-of-band verification
Read full Day 2 content →
03

LLM-authored malware + enterprise-copilot injection

LLM-authorship signals, polymorphic malware, the EchoLeak class, guardrail stack as detection telemetry.

  1. 03.1LLM-authorship signals in dropped code
  2. 03.2Polymorphic and runtime-generated malware
  3. 03.3OWASP LLM Top 10 (2025) as a detection checklist
  4. 03.4Prompt injection against enterprise copilots
  5. 03.5The guardrails stack as detection telemetry
  6. 03.6The lethal trifecta
Read full Day 3 content →
04

Agentic adversaries + AI supply-chain compromise

Detect adversary agent telemetry, harden your own agents, audit ML artifact provenance.

  1. 04.1The agentic adversary
  2. 04.2Detection signatures for adversary agents
  3. 04.3Hardening your own agents
  4. 04.4Supply-chain compromise of ML artifacts
  5. 04.5Backdoored fine-tunes and sleeper-agent models
  6. 04.6Poisoned RAG corpora
Read full Day 4 content →
05

Capstone — Operation Hollow Mirror

8-hour immersive IR against PROMETHEUS-7 attacking Verdancy Health.

  1. 05.1Briefing & env check
  2. 05.2Phase 1 — Recon detection
  3. 05.3Phase 2 — Deepfake BEC + triage
  4. 05.4Phase 3 — Prompt-injection IR on NoraBot
  5. 05.5Phase 4 — The Mirror twist (manipulated SIEM)
  6. 05.6Reporting + hot wash + GIAC prep
Read full Day 5 content →
CAPSTONE SCENARIO

The 4-stage kill chain

  1. AI-driven recon — LLM-generated dossiers on 40 finance staff identify the AP Director.
  2. Deepfake voice BEC — CFO voice clone plants a malicious vendor-onboarding PDF.
  3. Indirect prompt injection — poisoned support ticket makes the chatbot leak session tokens.
  4. Agentic exfil with AI SOC manipulation — injected logs make the triage agent blame a legitimate vendor sync. This is the twist.

Built where SEC450 ends.

Prerequisite
SEC450
Blue Team Fundamentals & SOC
This course
SEC5xx
AI-Generated Adversary Content

This course assumes SEC450 as prerequisite. It does not re-teach the RAG, agent, or Ollama labs that SEC450's 2025 refresh already covers — Day 1 begins where SEC450 ends. The positioning is intentionally aligned with the SEC450 graduate pathway.

Adversary AI is operational. The curriculum hasn't caught up.

2025.06

EchoLeak — zero-click M365 Copilot exfil

2025.08

ESET PromptLock — first LLM-runtime ransomware

2026.02

CrowdStrike GTR: 82% of detections malware-free, breakout down to 29 minutes

2026.03

M-Trends: initial-access hand-off down to 22 seconds; vishing now the #2 vector

"For eight hours, you defend Verdancy Health against PROMETHEUS-7 — an AI-orchestrated adversary that has studied your AI SOC, knows how it reasons, and built an attack designed to make your own agents lie to you."

Verdancy Health Cooperative — a 14,000-employee regional healthcare insurer whose CISO publicly bragged about its 'agentic AI SOC'. PROMETHEUS-7 — a financially motivated crew — scraped the talk and built the campaign around defeating that specific stack.

Hollow Mirror: FintechHalgrove Capital Partners · STYX-4
Hollow Mirror: OTBrackenwell Industrial Systems · CINDERHOOK
Hollow Mirror: Public SectorState of Lincoln DMV · PALEHORSE-9

Pass bar 700/1000 for GIAC capstone credit.

Course package and downloadable artifacts.

GIAC

GAIDA — GIAC AI Detection Analyst (proposed)

Labs

Browser-based on pre-provisioned EC2

Capstone

3 pre-built scenario variants

Duration

5 days / ~36 CPE hours

06 — Delivery & assessment

Lab-heavy, skills-validated, stackable.

Format

Each module runs as a 3–4 day intensive or six half-days live online, with 60–70% of the time in labs on replayed telemetry and range infrastructure. Bring your own sanitised telemetry — encouraged.

Assessment

Skills-based only: perform the triage, ship the detection, execute the red team engagement, present the capstone measurement. No written exams, no essays.

Stackable

A single module stands alone; a completed track earns a Blue or Red practitioner certificate; both tracks plus capstone complete the program. Completed tracks credit into the Steinbeis M.Sc. as recognised prior learning — the degree is an optional bridge, not the entry barrier.

Because AI tooling has a short half-life, labs are refreshed quarterly — and taught by working practitioners.

07 — Meet the instructor

15 years in network + security architecture. University and industry conference delivery.

Education

Master's degree in IT Security

Experience

15 years as Network + Security Architect

University teaching

Master class at Universitatea Politehnică București (UPB) — Romania's top engineering university · upb.vexpertai.com

Industry workshop

4-hour hands-on workshop at AutoCon 5, Munich, June 2026 — premier European network-automation industry conference

Publishing

Active relationship with Packt Publishing

Recognition

vExpertAI recognition; 3+ years developing AI curriculum for network and infrastructure engineers

The intersection of AI tooling and network/security infrastructure is the exact technical territory this program covers — and the territory Ed has been building, teaching, and publishing in for the past three years. Past delivery: graduate-level instruction at UPB (Bucharest) and conference-format workshops at industry events including AutoCon 5 (Munich, June 2026). Continuous practitioner work via vExpertAI consulting.

Full instructor profile →

08 — What I'm asking for

Three concrete asks.

01

Co-author with John Hubbard from blueprint forward.

02

Position SEC5xx as the SEC450 follow-on in the curriculum map — and pressure-test the program map above against the field.

03

Pilot one program module — B1, AI-assisted triage — as a single instrumented workshop. Time-to-verdict and error-rate data decide the rest.

Ed Dulharu

Munich, Germany (CET/CEST)

ed@vexpertai.com →