AIW-304Cybersecurity & Threat
AI in Security Operations: Triage and Detection
What you leave with
An AI-assisted SOC runbook: playbooks with evidence for the alert types that matter, what AI may close and what needs an analyst, automated actions allowed, exception rules tested against past incidents, injection defenses and tool permissions, and quality sampling.
Same obligation, two realities
Early-stage and SMESmall team: five alert types, short playbooks, AI recommending and people closing anything serious.
Enterpriseshifts, orchestration and hundreds of rules, so autonomy by alert type and action, suppression governance, injection defenses and weekly sampling.
How the course runs
- The obligation: where the responsibility comes from, cited by section.
- Two realities: how it is met in a small organisation and in an enterprise.
- The method: step-by-step practice with templates and edge cases.
- Paired labs: complete the one matching your work, read the other.
- Artefact and assessment: submit the artefact; a rubric and a short scenario quiz decide the certificate.