-
14:30
THE PLAN
Live demonstrations of AI agents speed-running blue team challenges, including the failure modes that break investigations. We'll show both what happens when we try the trivial approaches like “just have claude do it”, “AI workflows”, and what ultimately worked, like managed self-planning, semantic SIEM layers, and log agents. Most can be done with free and open tools and techniques on the cheap, so we will walk through that as well.
THE DEEP DIVE
- Why normal prompts and static AI workflows fail
- Self-planning investigation agents that evolve task lists dynamically
- What we mean by semantic layers for calling databases and APIs
- How to handle millions of log events without bankrupting yourself
- Why "no AI" rules are misguided technically and conceptually
GOING BEYOND CTFS
The same patterns that trivialize training exercises work on real SOC investigations. We're watching blue team work fundamentally transform - from humans investigating to humans managing AI investigators. Training programs teaching skills AI already automates. Hiring practices that can't verify who's doing the work. Certifications losing meaning. More fundamentally, when we talk about who watches the watchers, a lot is about to shift again.