Keynote: SIFT: Find Evil! Defensive AI Orchestration

SANS Institute ยท Intermediate ยท๐Ÿค– AI Agents & Automation ยท1w ago
Skills: Defensive AI90%
Keynote: SIFT: Find Evil! Meeting AI Threat Speed with Defensive AI Orchestration ๐ŸŽ™๏ธ Rob T. Lee, Fellow; Chief AI Officer and Chief of Research at SANS Institute ๐Ÿ“ Presented at SANS AI Cybersecurity Summit 2026 AI attack workflows run 47 times faster than human operators. Your adversary already has agentic AI. The question is whether defenders do too. Rob T. Lee wired Claude Code into the SIFT Workstation via Model Context Protocol. Two words typed. Fourteen minutes later: a complete C drive forensic analysis, timeline generation, memory analysis, malware sweeps, all via natural language. What normally takes defenders three days to do. This session covers what 40+ hours of testing actually produced: โ€ข How Claude Code integrates with SIFT via MCP for timeline generation, memory analysis, and malware sweeps โ€ข What โ€œFind Evil!โ€ produces end to end โ€” and where it still needs a human analyst โ€ข Why matching AI speed with AI speed is no longer optional The velocity gap between AI offense and human defense is already operational, and closing it requires defenders to build with the same architecture that the adversary has already demonstrated works: an orchestration layer, tool integration, and autonomous execution. Explore upcoming SANS Summits to continue learning from leading voices in cybersecurity: https://go.sans.org/summits
Watch on YouTube โ†— (saves to browser)
Sign in to unlock AI tutor explanation ยท โšก30

Related AI Lessons

โšก
Getting Started With Agent-to-Agent aka A2A Protocol
Learn how the Agent-to-Agent (A2A) protocol enables coordinated work among isolated AI agents and its importance for AI engineers
Medium ยท AI
โšก
Getting Started With Agent-to-Agent aka A2A Protocol
Learn how Agent-to-Agent (A2A) protocol enables coordinated AI workforces and its importance for AI engineers
Medium ยท Python
โšก
Getting Started With Agent-to-Agent aka A2A Protocol
Learn about the Agent-to-Agent (A2A) protocol, which enables coordinated workforce among isolated AI agents, and its importance for AI engineers
Medium ยท LLM
โšก
One MCP Server or Ten? The Architecture Decision That Can Make or Break Your AI Agent
Learn how to architect your AI agent's infrastructure to ensure scalability and reliability, a crucial decision for e-commerce applications
Medium ยท Python
Up next
Build & Automate ANYTHING With Hermes Agent
Julian Goldie SEO
Watch โ†’