Stay Ahead of Ransomware: Building an AI-Powered Ransomware Intelligence Agent
SANS Digital Forensics and Incident Response
0:00 / 0:00
Stay Ahead of Ransomware: Building an AI-Powered Ransomware Intelligence Agent
847 просмотров · 6 месяцев назад
SANS Digital Forensics and Incident Response
79,6 тыс. подписчиков
847 просмотров · 6 месяцев назад
In the last two episodes (Jan & Feb '26), we talked about the AI arms race. Specifically, how attackers and defenders are both leveraging LLMs. This time, we’re getting hands-on. Raymond DePalma returns to walk through building an AI agent that ingests host-based forensic artifacts from a ransomware incident. The agent will cross-reference the provided artifacts against ransomware.live’s real-time intelligence database to attribute threat actors, surface IOCs, pull negotiation transcripts, and generate actionable IR briefs - all in minutes instead of hours.
This isn’t a product demo. It’s open-source and buildable by any DFIR practitioner with basic Python skills and designed to show how AI amplifies expertise rather than replacing it. We’ll walk through a simulated ransomware incident from artifact collection to attributed intelligence report, with the agent doing the heavy lifting. Join us for an informative session that will provide you with a direct toolkit you can implement in your place of business. Who wants to learn to leverage AI, not just talk about?