Section 1: AI in the SOC: Where It Helps and Where It Hurts
- SOC tasks where AI helps most: summarising alerts, adding context, writing queries and drafting reports
- Decisions that must stay with people, and why AI should never trigger active response on its own
- Answers that sound right but are wrong, and how to make AI cite evidence from the logs
- Logs contain personal data: choosing a local LLM or an external service by data classification and PDPA
Section 2: Lab: Connecting Wazuh to a Local LLM
- Bring back the Wazuh 4.14 Docker lab, loaded with a simulated alert set
- Install Ollama and choose a small model suited to log analysis
- Pull alerts through the Wazuh server API and query the Wazuh indexer from Python
- Lab: have the LLM summarise the latest high-level alerts in clear Thai for the team
Section 3: Lab: Prompts for Alert Triage
- Design prompts that return JSON: severity, ATT&CK technique and reasoning
- Have AI flag false positives with evidence that can be traced back
- Measure accuracy against a labelled alert set and tune the prompt from the results
- Lab: build a 30-alert test set and compare two prompt designs
Section 4: Lab: Enrichment with Threat Intelligence
- Check IPs, domains and hashes from alerts against free threat intelligence services
- Combine asset data, host owners and alert history with the analysis
- Have AI turn results from several sources into one recommendation, citing every source
- Lab: enrich an alert for an outbound connection to a suspicious IP and summarise the risk
Section 5: Lab: An Automated Triage Pipeline with n8n
- Send alerts from Wazuh to n8n through a custom webhook integration
- Chain enrichment, LLM analysis and urgency rating
- Add human approval before any step that changes a system
- Lab: a workflow that triages SSH brute force alerts and asks for approval before blocking an IP
Section 6: Lab: AI-Assisted Log Analysis and Rule Writing
- Draft custom Wazuh decoders and rules from sample logs
- Test every AI-drafted rule with wazuh-logtest before using it
- Translate the logic of a Sigma rule into a Wazuh rule and check the result yourself
- Lab: build a rule that detects abnormal API use in a sample application log