Biography: Kevin is a Director at Ghostscale, responsible for overseeing penetration testing, risk assessments, compliance audits, incident response, and cybersecurity advisory services. Kevin has 25+ years working in a variety of cybersecurity leadership roles, including application... Read More →
We are currently at an inflection point. The traditional SOC model—relying on manually correlated alerts and fragmented SIEM, EDR, and SOAR tools is failing. Why? Because the adversary has industrialized the attack chain using Generative AI.
Threat actors no longer operate at human speed. They can generate complex phishing campaigns, discover vulnerabilities, and execute sophisticated attacks in hours, not months. This isn’t a future risk; it’s happening today, with AI-powered worms accelerating the speed and scale of breaches.
Our challenge is simple: We cannot fight machine speed with human effort.
The core architectural flaw in legacy environments is the "human correlation engine." You pay massive fees to ingest data into a SIEM, then you pay highly skilled analysts to manually pivot through disjointed consoles to stitch together a single attack story. This results in overwhelming alert fatigue, long Mean Time to Resolution (MTTR), and high analyst burnout.
To survive and compete in the AI era, you must adopt an Autonomous SOC model.
This means replacing fragmented tools with a single, unified platform—one that fuses XDR, SIEM, and SOAR onto a single data lake. The goal is to move the human out of the repetitive decision-making process. The AI should automatically ingest all telemetry, synthesize it into a single, comprehensive Incident (the full story), and orchestrate the response before your team even sees the alert.
This shift isn't about incremental improvement; it's about architectural transformation. It’s the only way to solve the most common problems that we face in the SOC today
DFIR today involves millions of artifacts, hundreds of thousands of logs with a hundred different sources. An analyst would spend more time collecting, normalizing and then searching for data rather than reasoning about what happened. An average incident resulting in large timelines as APTs and ransomware gangs today, equipped with AI to help them on their quest for world encryption.
So why not look at the problem? The analysts spending hours analyzing and looking at logs, a hundred different tools and then normalizing the mess... phew! This makes DFIR the path with the highest burnout rates withing the cybersecurity domain. The solution to this is relatively simple, or is it? Let's dive into employing the OSDFIR framework to automate investigations and as a plus, leveraging the ability of LLMs to work with opensource tools like OpenRelik and Tmesketch (both would be explained to the audience) to make this workflow applicable in your day to day forensics and incident response scenarios.
I would demonstrate how a practical, end-to-end workflow using the above can be set and show the audience a demo where I prompt an LLM to identify malicious activity within a defined time frame. We will walk through a realistic muti-stage timeline where forensic artifacts are standardized and is used to build an enriched timeline for the the LLM to work with. The process to do the same would be explained followed by a short demo on the final product: a solution where you can ask the LLM using prompts in natural language to identify malicious activity!
Cybersecurity professional with over 5 years in the industry, currently working in incident response and digital forensics. Initially, I specialized in a red team role as a Security Consultant at Synopsys, where I was heavily involved in Offensive Security and Penetration testing... Read More →