SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsMigrations of mature security information and event management (SIEMs) can be overwhelming due to the sheer volume of detection logic and log sources that must be translated between platforms and query languages. This research explores how Large Language Models (LLMs) and automation scripts can expedite the translation of detection logic between SIEMs, converting detections in minutes instead of hours. Multiple tests can be conducted to optimize translation results, test various LLM parameters, and increase the successful output of the conversion. This translation process can be automated by utilizing scripting and API integrations, significantly reducing the manual effort involved in SIEM migrations.