SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
In the age of LLMs, the volume of new threat reports, CVEs, actor TTPs, and fragmented signals are often arriving faster than analysts can process them. AI is often positioned as the solution, but in practice, most implementations stop at summarization or basic enrichment.
This hands-on technical session focuses on how to build and deploy modern AI-backed agents inside real CTI workflows - systems that continuously ingest, reason, and take action, including automatically opening and enriching tickets tied to real exposure.
We’ll break down how AI can automate key stages of the CTI lifecycle: parsing unstructured intelligence, extracting IOCs and TTPs, correlating activity, mapping threats to your environment, and triggering operational workflows like detection updates and ticket creation.


Rebekah Brown has been instrumental in advancing cyber threat intelligence, serving as a network warfare analyst at the NSA, Operations Chief of a U.S. Marine Corps cyber unit, and training lead at U.S. Cyber Command.
Read more about Rebekah Brown