Cover Image for The Human in the Detection Loop: Building and Breaking AI Detection Pipelines
Cover Image for The Human in the Detection Loop: Building and Breaking AI Detection Pipelines
Avatar for TryHackMe
Presented by
TryHackMe

The Human in the Detection Loop: Building and Breaking AI Detection Pipelines

Zoom
Get Tickets
Welcome! Please choose your desired ticket type:
About Event

​Live Class | The Human in the Detection Loop: Building and Breaking AI Detection Pipelines

​
Who this workshop is for:

  • ​Detection engineers and SOC analysts using AI to write or accelerate detection rules

  • ​Security practitioners who want to understand where AI-generated detections quietly fail

  • ​Anyone building or evaluating agentic AI pipelines for security use cases

​What's included:

  • ​Live, hands-on session, build and break a real detection pipeline, not just watch a demo

  • ​Certificate of participation with CPE credits

​Your AI just wrote a flawless detection in a few seconds. Clean syntax, textbook logic, mapped straight to the ATT&CK technique.

​Ship it, right?

​In this live, instructor-led workshop, you'll find out why that beautiful rule might be easily bypassed, or bury your analysts under a thousand false positives by lunchtime.

​What makes this workshop different:

  • ​It's built around a real bypass and a real pipeline, not a slide deck on AI best practices

  • ​You'll see exactly where AI-generated detections break, before you build the fix

  • ​You leave with a working agentic pipeline architecture you can apply to real detections

​What you'll learn:

​Part 1: The Risks of AI-Generated Detections

  • ​False confidence: why a rule that reads as authoritative and complete isn't necessarily airtight

  • ​Watching an attacker slip straight past a "perfect" AI-generated rule

  • ​Why AI can't see your company context, your estate, your noise, your legitimate admin tooling

  • ​How that context gap turns a perfect-looking rule into a poor detection

​Part 2: Building an Agentic Detection Pipeline

  • ​Designing a pipeline where one agent handles the research

  • ​Adding an agent that hunts specifically for false-positive risk

  • ​Checking detections against your environment's known-good behavior

  • ​A final validation agent that checks syntax before anything reaches production

  • ​Stress-testing the full pipeline with adversary emulation

​Instructor:

​Gabriel Novaes, Senior Content Engineer at TryHackMe

​Career highlights

  • ​Security Researcher at Radiant Security

  • ​SOC Tech Lead at iT.eam (Belo Horizonte, Brazil) — the first SOC in the world certified at SOC-CMM

​

​Recording notice: This event will be recorded. We may share the recording with registered attendees and may also use selected portions publicly, including on our website or social channels. By registering for and attending this event, you agree to this recording and use.

Avatar for TryHackMe
Presented by
TryHackMe