Skip to content

AI for defenders: detection, triage and response

Using language models and machine learning inside a security team without creating a new incident class.

Free on glitchdata intermediate 4 lessons 1 hr

What you'll learn

  • Judge where AI helps a security team and where it adds risk
  • Design an LLM-assisted triage pipeline that keeps analysts in control
  • Reason about false-positive economics in detection
  • Run an incident involving an AI system, including what evidence to keep

About this course

The other half of AI security: not defending the AI, but using it. Security teams are drowning in alerts and short of people, which makes automation attractive — and makes the failure modes expensive.

This course covers where AI genuinely helps a security team, where it does not, how to evaluate detection honestly, and how to respond when the AI system itself is the thing that went wrong.

Before you start

  • Working knowledge of security operations
  • Basic familiarity with language models

Course content

4 lessons · 1 hr

  1. 1
    Where AI helps a security team

    Summarising, enriching and drafting, versus deciding — and which is which.

    Free preview 14 min
  2. 2
    Triage and enrichment that keeps analysts in control

    Designing the pipeline so a confident wrong answer costs a minute, not an incident.

    15 min
  3. 3
    Detection engineering and false-positive economics

    Why a 99%-accurate detector can still be useless, and what to build instead.

    16 min
  4. 4
    When the AI system is the incident

    Responding to prompt injection, leakage and agent misbehaviour — and what evidence you need.

    15 min

What learners say

Sign in and enrol to leave a review.

No reviews yet — be the first once you have worked through it.

More in AI security

AI security intermediate

Securing RAG, tools and agents

Access control across a retrieval index, the confused deputy problem in tool use, and keeping an agent inside its blast radius.

4 lessons 1 hr 3 min Free