Cover Image for AI Wrote My Detection: Then My SOC Caught Fire
Cover Image for AI Wrote My Detection: Then My SOC Caught Fire
Avatar for TryHackMe
Presented by
TryHackMe

AI Wrote My Detection: Then My SOC Caught Fire

Register to See Address
Registration
Welcome! To join the event, please register below.
About Event

This is a teaser class for The Human in the Detection Loop: Building and Breaking AI Detection Pipelines, running Thursday, December 17th at 4:30 PM BST.

Who this teaser is for:

What's included:

  • Live, instructor-led teaser session

  • A live demo: watch an AI-generated rule get bypassed in real time

  • A preview of the full workshop, running December 17th

Everyone's showing you how AI writes detections. Almost nobody's showing you how they fail.

In 30 minutes, we'll do both.

Watch an LLM create a beautiful, syntactically flawless detection rule. Then watch an attacker walk straight past it, because "convincing" and "correct" aren't the same thing.

Then we'll drop that same rule into a realistic estate and watch it fall apart. With no grasp of your context, the "perfect" rule buries you in false positives.

What you'll learn:

  • Why a syntactically flawless AI-generated rule can still be trivially bypassed

  • The gap between a rule that "reads" complete and one that actually holds up

  • Why AI can't see your estate, your noise, or your legitimate admin tooling, and what that costs you

  • What to expect from the full "Human in the Detection Loop" workshop on December 17th

Learn directly from:

Gabriel Novaes, Content Engineer at TryHackMe

Recording & livestream notice: This free class will be livestreamed and recorded. The recording may be made available on our YouTube channel and other public channels after the event. By registering for or attending this class, you understand and agree that your participation, including your name, voice, image, and any questions or comments you submit, may appear in the livestream or recording.

Avatar for TryHackMe
Presented by
TryHackMe