Detect, triage and respond to AI-specific incidents. Build the telemetry, alerts and playbooks your SOC is missing.
Classes are custom built from the following learning modules. Instructors select ~16 hours for a 2-day delivery. Custom formats from 1 to 3 days available. (Times are approximate.)
AI incidents do not look like traditional security incidents. There is no malware binary, no exploit kit, no lateral movement in the usual sense. A prompt injection looks like a normal user message. An agent compromise looks like normal API calls. This module shows SOC teams what AI attacks actually look like in logs, traffic and telemetry so they know what to look for.
A structured walkthrough of every AI attack vector a SOC needs to detect: prompt injection (direct and indirect), jailbreaks, data extraction through model responses, RAG poisoning, tool poisoning, agent privilege escalation, MCP replay attacks, model denial of service and data exfiltration through agent tool calls. For each one we show what it looks like in your existing telemetry and what new telemetry you need.
Where to get threat intelligence on AI attacks. CVE feeds for AI and MCP components, OWASP resources (AISVS, LLM Top 10, MCP Top 10), vendor advisories and the research community. Building an AI threat intel feed into your existing TI programme.
The telemetry your AI systems must produce for the SOC to do its job. LLM call logs (prompts, completions, token counts, latency, model version), tool execution records (tool name, parameters, caller, result), agent action logs (action type, trust level, approval status), MCP request logs (tool, signature status, nonce) and vector store access logs. What format, what retention, and how to get it into your SIEM.
Hands on: write detection rules that fire on prompt injection indicators. Pattern-based detection (known injection prefixes, encoding tricks, role-override attempts), statistical detection (anomalous prompt length, unusual token patterns) and behavioural detection (output that contradicts the system prompt). We write real rules in your SIEM query language.
Hands on: write detection rules for agent compromise. Unusual tool call sequences, trust level escalation attempts, actions outside the agent's normal scope, velocity spikes and data access pattern changes. We focus on the behavioural baselines that make these detections work.
Hands on: write detection rules for data exfiltration through model responses, tool calls and agent actions. The attacker uses the AI system as the exfiltration channel. Detection is about spotting when the AI returns or sends data it should not have access to.
Hands on: write detection rules for MCP-specific attacks. Replay attempts (same nonce reused), unsigned requests, tool description changes between enumeration and invocation, and unbounded request bodies (the CVE-2026-39313 pattern).
Signature rules only catch what you already named. AEBA takes the other half: build a baseline of how each agent normally behaves, which tools it calls, what data it reaches for, how often and when, then alert on the drift. An agent suddenly calling a tool it has never used, looping, pulling data outside its remit or acting at 3am is behaviour you flag even when no single event matches a known bad pattern.
AI detections produce false positives because normal AI usage looks strange to traditional rules. How to tune AI detections without blinding yourself. Baseline windows, whitelisting patterns and the feedback loop between the SOC and the AI engineering team.
A structured triage framework for AI incidents. Classification (prompt injection, model abuse, agent compromise, data leak, tool poisoning, DoS), severity assessment (what data was exposed, what actions were taken, what blast radius), and escalation criteria (when to page engineering, when to revoke agent credentials, when to kill the model endpoint).
How to contain each class of AI incident. Revoking agent credentials, killing model endpoints, isolating vector stores, blocking tool access and halting agent swarms. The order of operations matters because some containment actions destroy evidence.
What evidence to preserve and in what order before containment actions destroy it. LLM interaction logs, agent memory state, vector store snapshots, MCP request logs and infrastructure telemetry. Chain of custody for AI evidence.
Who needs to know, when, and what to tell them. Internal escalation (engineering, legal, executive), external notification (regulators, customers, data subjects under GDPR) and the difference between "the AI was hacked" and what actually happened.
A step-by-step response playbook for a confirmed prompt injection. Detection, triage, containment, investigation, remediation and post-incident. Worked example with log extracts.
A step-by-step response playbook for a compromised agent. Detection of anomalous behaviour, credential revocation, blast radius assessment, evidence collection, root cause analysis and remediation.
A step-by-step response playbook for data exfiltration through model responses or agent tool calls. Identifying what data was exposed, to whom, and through which path.
A step-by-step response playbook for a compromised or malicious MCP server. Tool integrity verification, client-side impact assessment and server isolation.
Rules, roles, tooling access and scoring criteria.
A timed, multi-incident SOC simulation. Multiple AI-specific incidents are injected into the lab environment over three hours. Delegates work as a SOC team: detect, triage, contain, investigate and report. Incidents include prompt injection, agent compromise, data exfiltration and MCP attacks running concurrently. Scored on detection time, containment speed, evidence preservation and report quality.
Walkthrough of every injected incident, what was missed, what was handled well, and how to improve. Lessons learned mapped back to the detection rules and playbooks.
Write and test AI detection rules against a lab SIEM populated with AI attack data. Tune for false positives. Verify each rule fires on the correct attack pattern.
Receive an AI incident alert. Triage it, contain it, preserve evidence and write up the finding. Peer review with another team.
Hands-on with the CyberSecAI tooling, not slideware.
Builds a baseline of how each agent normally behaves, then flags the drift: an agent calling a tool it never touches, looping, reaching for data outside its remit, or acting at the wrong time. Behavioural detection for agents, not just log matching.
AI-specific telemetry and a detection ruleset: Sigma-style rules for LLM and agent logs.
Tamper-evident, hash-chained incident evidence.
The target for the live SOC simulation.
Graduated L0 to L4 human-in-the-loop containment gate.
Work AI alerts with the same rigour you bring to the rest of the estate.
Write detections that fire on real AI attacks, not on noise.
Take an AI incident from first alert to contained and reviewed.
Add AI systems to the surface you defend and monitor.
Stand up the telemetry, playbooks and cover your SOC is missing.
This course counts toward the CyberSecAI AISVS assurance track. Assessment is practical: you instrument a running AI system, write the detections and triage playbooks, work a live SOC simulation, contain a compromised agent, and produce the evidence. On a passing result, the credit is recorded against your assurance track.
Two days, hands-on, from telemetry to response, taught by the former OWASP-AISVS Co-Leader (v1.0) and the author of the MCPS, ATTP and agent-payment-trust Internet-Drafts. Places are limited.
Corporate & sovereign cohorts, and bespoke on-site delivery, on request.