AI Security Podcast

How AI is changing Detection Engineering & SOC Operations?

14 snips
Feb 7, 2025
In this engaging discussion, Dylan Williams, a seasoned cybersecurity practitioner with nearly ten years in detection engineering, shares his insights on AI's transformative effects on detection processes. He explores how AI is reshaping threat detection and reducing false positives while enhancing investigation speed. Dylan also delineates the difference between automation and agentic AI, emphasizes the importance of accurate signal identification, and introduces practical AI tools that detection engineers can utilize right now. Tune in for a glimpse into the future of detection engineering!
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

AI vs. Traditional Search

  • Dylan Williams uses Stack Overflow and Google searches to illustrate AI's impact.
  • He highlights how AI can achieve the same results in a fraction of the time.
INSIGHT

Detection Engineering Challenges

  • Threat detection requires diverse knowledge, including threat intelligence and query languages.
  • AI can accelerate specific parts of the detection engineering workflow.
ADVICE

Maturity in Detection Engineering

  • Organizations have different maturity levels in their detection engineering functions.
  • Testing and validating detections is crucial for ensuring their effectiveness.
Get the Snipd Podcast app to discover more snips from this episode
Get the app