SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Evidence of USB device connection is littered all over a Windows system. Many tools try to parse this information and some even get it right…sometimes!
Hey, it depends!
I’ll talk about some of these artifacts and some of the available tools, including a script I wrote to try and pull a lot of this data together in a useful way, which has recently been updated, so this is also a chance to provide feedback.
Artificial intelligence (AI) is making its way into security operations quickly, but many practitioners are still struggling to turn early experimentation into consistent operational value. This is because SOCs are adopting AI without an intentional approach to operational integration. Some teams treat it as a shortcut for broken processes. Others attempt to apply machine learning to problems that are not well defined. Findings from our 2025 SANS SOC Survey reinforce that disconnect.