Lightning Talk: AI-Assisted Threat Hunting That Remembers
Skills:
AI Security85%
Designing AI-Assisted Threat Hunting That Remembers
๐๏ธ Sydney Marrone, Head of Threat Hunting, Nebulock
๐ Presented at SANS AI Cybersecurity Summit 2026
Threat hunting teams struggle to reuse prior investigations, which leads to repeated setup work, inconsistent results, and limited benefit from AI tools that lack durable context. Early attempts to add AI often fail because hunts are unstructured, state lives in scattered notes, and models have nothing reliable to reason over.
This talk presents a CLI-first approach to threat hunting that captures hypotheses, assumptions, and outcomes as structured artifacts and uses that data to support AI-assisted recall and reasoning. Instead of prompting chatbots, teams integrated AI into the hunting workflow itself, allowing it to reference past hunts, surface related investigations, and suggest next steps while analysts remained in control.
After adopting this approach, teams reduced hunt restart time, improved analyst handoffs, and increased reuse of prior investigations. AI moved from a novelty to a practical assistant, with measurable gains in speed and consistency and clear lessons learned around integration pain, workflow changes, and where AI did not help.
Explore upcoming SANS Summits to continue learning from leading voices in cybersecurity: https://go.sans.org/summits
Watch on YouTube โ
(saves to browser)
Sign in to unlock AI tutor explanation ยท โก30
More on: AI Security
View skill โRelated AI Lessons
โก
โก
โก
โก
This Tool is Changing How Chinese Devs Build AI Apps
Dev.to AI
Japanโs Monster Wolf robot is a $4,000 scarecrow with red LED eyes, and it actually works
The Next Web AI
5 Claude AI Prompts That Save Me 10 Hours Every Week (Copy & Paste Ready)
Medium ยท ChatGPT
Desktop vs Web Applications for PDF Accessibility Validation
Medium ยท AI
๐
Tutor Explanation
DeepCamp AI