Transcription
What if you could cut your most mind-numbing cyber security tasks in half without writing a single line of code? Sound too good to be true? Well, stick with me because in this course, I'm going to show you exactly how to make that happen using free generative artificial intelligence or Gen AI tools that are free to use and available right now. And no, this isn't just another hype-heavy course telling you AI is going to replace you. This is about using a powerful tool and putting it to work for you.
Welcome to AI prompt engineering for cyber security pros. This is where your journey begins. And I want to set crystal clear expectations on what this course will do for you, what it won't, and how to get the absolute most out of every lesson. So, be sure to watch this video until the very end. And by the end, you'll know exactly who this course is for, what you're going to walk away with, and how I'll help you become the kind of cyber security pro that leverages GenAI as a game-changer.
Now, if you're wondering who I am and why you should trust me to guide you through this, I'm Brandon Spencer. I'm a senior instructor here at Dion Training with over 22 years of experience in IT and cyber security. I've worked in the trenches of large enterprise environments and lean, fast-paced teams at smaller companies as well. So, when you hear me talk about time pressure, never-ending documentation, compliance headaches, alert fatigue, and more, I'm not just guessing. I've lived it. And I know the need to find ways to make your job easier and more efficient.
When it first came out, I started using GenAI right away. Not just casually, but strategically. I used it to automate my work, to build better workflows, and even plan and help create professional training content just like the course you're watching now. So, when I tell you that GenAI can multiply your productivity, I'm not saying it because it's cool or trendy. I'm saying it because I've done it. I've used it in real working environments and it's highly effective when done right.
But let me be very clear about one thing. GenAI is incredibly powerful, but it's not absolute. It's artificial intelligence, not actual intelligence. It can't replace my judgment. It doesn't override my intellect, and it doesn't excuse me from thinking critically about what I'm seeing. That's the mindset I want to help you develop throughout this course. GenAI is not your boss. It's not the final word on anything. It's just a tool. It's a force multiplier, and it's not a replacement. And when you use it that way, that's when the magic happens. Okay?
Now, let's be real for a second. Cyber security is overloaded with time-consuming, repetitive tasks, right? You know the ones I'm talking about. Manually summarizing threat reports, writing up compliance documentation, repetitive scripting, explaining technical findings to non-technical people, and yeah, let's not even talk about the soul-crushing policy and security reviews before an assessment or an audit. I know these aren't the glamorous parts of the job, but they're very necessary. The downside is they eat up hours of our time. They pull us away from work that we really want to be doing. That's the problem we're tackling in this course. We're not securing the AI infrastructure. We're augmenting your work using Gen AI prompt engineering. When used strategically, GenAI can automate or accelerate a huge chunk of this work, freeing you up to focus on what really matters.
So, who is this course built for? If you're a security engineer, a SOC analyst, a GRC pro, a cyber security auditor, threat intelligence specialist, or anyone juggling multiple roles in a lean security team, this course is for you. And even if you're brand new to GenAI or maybe a little skeptical, that's perfectly fine. You're exactly who this course is designed for. I'm going to show you how to automate the five most tedious, time-consuming cyber security tasks using free Gen AI tools. We're talking about ChatGPT, Claude, and Perplexity. But this isn't just a tools course. You're going to learn how to think like a strategic GenAI power user. That means understanding when to use AI, how to shape its responses, and how to build repeatable workflows that multiply your productivity without compromising security or accuracy.
So, I'll walk you through hands-on real-world use cases like summarizing threat intelligence, drafting and reviewing documentation, automating security awareness scripts, writing logic for playbooks, accelerating vulnerability management, and more. And yes, I'm going to give you plenty of copy-and-paste prompt templates, workflows, and there will be plenty of exercises and live demos along the way. You'll also learn how to critically evaluate outputs, how to improve your prompts and prompt outputs, how to responsibly integrate GenAI into your workflows without losing control, and more. And again, this is all about empowerment, not replacement. You will stay in the driver's seat at all times. That's how it should be.
And just to be clear, here's what we're not doing in this course. We are not going to dive into securing AI systems. That's another course all in itself. This is about security with AI, not security of AI. We're also not going to build AI models. The models you use does not matter. In fact, you may see me using an older AI model than what's available right now. The output is what matters. The prompts I'm going to teach you will work in any model and get the output that you need. I'm also not going to teach you to blindly trust AI or use it to cut corners. In fact, I'll show you exactly how to challenge it, tweak it, and verify what it gives you. Again, I'm not promoting unsafe or unethical use of GenAI in any way. There are no risky prompts. There's no pasting sensitive data into public tools or anything like that. And AI does not replace your judgment or your experience. If anything, it makes your judgment, knowledge, and experience even more critical. This course is all about responsible, professional-grade use of GenAI in your work. You will also not be required to script, code, or wrangle any complex theories. And I'm not going to waste your time with AI trend slideshows or any empty hype. So, if you want some flashy presentation, this isn't going to be it. But if you want real hands-on skills that are going to transform your daily workflow fast, you're in the right place.
Now, let me give you a sneak peek of what you can do with just one good GenAI prompt. Imagine that you've been handed a 14-page threat intelligence report filled with technical jargon and MITRE ATT&CK references. Instead of spending 45 minutes parsing through everything manually, you drop the report into ChatGPT with a well-structured prompt and within seconds you've got a three-paragraph executive summary, highlighted threat actors, mapped tactics and techniques, and a prioritized list of action items. That's awesome, right? I mean, that's just one workflow that you're going to learn in this course. Imagine having multiple workflows like this. How much time, energy, and headaches would that save you? That's the kind of impact we're aiming for in this course.
By the end of this course, you'll have plug-and-play prompt templates that you can use immediately. You'll get plenty of real-time demos using tools like ChatGPT, and you will have time-saving workflows for triage, reporting, policy reviews, vulnerability management, and so much more. This training is designed to be fast-paced and modular. There's no fluff. There's no filler. Every lesson is hands-on, practical, and focused on real outcomes. You'll also get downloadable prompt playbooks, a cyber security prompt engineering guide, and a responsible AI use policy to guide you in your day-to-day decision-making. The appropriate files will be available in each section of the course. And again, don't worry if you've never used GenAI before. It's perfectly fine. You won't need technical skills, coding chops, or any AI theory. Everything is broken down into simple, plain language. You'll learn by doing and get results without the overwhelm. It's going to be intense. It's going to be practical, and it's going to be a lot of fun.
So, here's what I want you to remember about this course. This course automates the five most tedious cyber security tasks with free GenAI tools. And yes, they can be adapted for other tasks that I might not cover as well. You'll learn real-world workflows, not just tools, trends, or other GenAI hype. And you're going to get plenty of hands-on guidance, prompt templates, and plenty of demos, and practical walkthroughs. You'll walk away with the skills that you can actually use, and save you a ton of time on the job. So, are you ready to save hours on repetitive tasks, boost your output, and become the go-to AI pro in your team? Let's dive in and let's get started.
In the next lesson, I'm going to break down what GenAI really is and why it's different from anything cyber security has seen before. So, thanks for watching to the end. I really appreciate it and I'll see you in the next one.
What if I told you that the biggest breakthrough in cyber security isn't a firewall, a SIEM, or a zero-day detection engine, but a chatbot? That sounds crazy, right? But that chatbot is actually powered by something far more powerful, which is generative AI. GenAI is not just another buzzword. It can help you write code scripts, analyze threat intelligence, decode logs, summarize reports, and even teach you unfamiliar concepts, all in plain language. And it does it all without having you write a single line of code, unless you actually want to.
Now, here's the craziest part. It works completely different than the tools that you're probably used to. And in this lesson, we're going to pull back the curtain on GenAI. I'm going to explain how it works under the hood and show you exactly why it's such a game-changer, especially if you come from a background that's rooted in scripting, machine learning, SOAR platforms, or even traditional automation tools.
For years and years, cyber security professionals have leaned on scripting languages like Python, PowerShell, Bash, and more to build out repeatable workflows. We've set up logic trees, rules, playbooks, regex filters, SIEM alerts, and scheduled scans. And this all worked, and it still does to this day. But these systems have limitations. They're deterministic. That means they only do what you explicitly tell them to do. If X happens, then do Y. But what if you want to ask, "What might a malicious attacker be trying to do here?" Or, "Can you summarize this alert in plain language for an executive?" Or, "Write me a phishing simulation email that matches this campaign's style." That's not easy to script, and that's definitely not deterministic.
This is where GenAI breaks away from everything else that you're used to. GenAI is a type of artificial intelligence that can generate new content like text, images, code, and much more. And it's all based on patterns it has learned from massive data sets. Unlike traditional automation, which runs fixed instructions, GenAI can produce flexible, creative, and context-aware responses.
Now, at the core of most GenAI systems is the Large Language Model, or LLM. The LLM is a machine learning model that's trained on billions and sometimes trillions of words from books, websites, manuals, codebases, and so many more other sources. So, think of it like this. Imagine if you had a friend that read the entire internet and remembered every single sentence. You can then ask them, "What's the NIST standard for handling incident response?" Or, "Can you write a Python script that parses a log file and finds failed logins?" Or, "Ask them to translate this firewall configuration into something that I can explain to my boss." And instead of having to Google or click links or copy code, they give you the answer instantly. That's what an LLM does.
Now, LLMs don't understand the world the way that we do. It's not thinking. It's predicting. It's predicting what the next best word should be based on your prompt or input. But the magic happens because the predictions are often shockingly accurate and useful. And while that's awesome, there is a catch. Sometimes LLMs can make stuff up. That's why we might need a second ingredient sometimes, and that is RAG. RAG stands for Retrieval Augmented Generation. It's a technique that helps fix one of the biggest problems with LLMs, which is hallucinations. A hallucination is when AI gives you a completely wrong but very confident-sounding answer. RAG solves this by combining an LLM with your actual data. Here's how it works: One, you ask a question like, "What's our internal procedure for handling ransomware?" Then two, the system first retrieves relevant documents from your knowledge base. Then three, it feeds those documents into the context window of the LLM. And then finally, four, the LLM generates a response based on your data. It's like giving your friend access to your company's private procedures, logs, or documentation before they even answer. RAG is the secret sauce behind trustworthy GenAI in cyber security. And soon, every SOC team will have its own private GenAI assistant trained on their own data.
Okay, now let's talk apples to oranges for a second. Traditional scripting is about clear logic. You write a script. It does exactly what you say. It's predictable and auditable, but it's also rigid. GenAI is about probabilistic reasoning. It guesses the best response based on what it's seen before. It's flexible and conversational, but it's not always predictable. So, here's a quick side-by-side to help: Scripting is great for known tasks, repeatable logic, and deterministic outputs. GenAI is great for unknowns, creative tasks, summaries, explanations, and pattern recognition. Does that make sense?
Now, let's say you want to write a YARA rule to detect a new malware strain. A traditional script can't do much here unless you already know the patterns and sit down to code them manually from scratch. But GenAI, it can analyze the malware characteristics. It can cross-reference similar samples and even suggest a draft rule structure for you, saving you tons of time and helping you spot patterns that you might have missed. So, this isn't about picking one over the other. It's about pairing deterministic power with intelligent creativity. Script and GenAI together, this is where the magic happens.
So, where does GenAI really shine in cyber security? First, speed. You can write and debug scripts 10 times faster by having an AI assistant. Understanding. You can ask for explanations of complex code, logs, or alerts, all in plain language. Translation. It can help bridge technical knowledge to non-technical stakeholders. Pattern matching. GenAI can compare artifacts, threat intelligence reports, or logs all in a contextual way. And then lastly, creativity. It can generate phishing simulations, write detection rules, and even draft remediation steps.
For example, let's say that you're threat hunting and you want to use your endpoint detection logs to detect potential lateral movement across the network. XDR or EDR logs have tens of thousands of entries per log file. So, that's a lot of data to sift through. Normally, that would have meant building complex queries, manually hunting through anomalies, and cross-referencing system behaviors for hours and hours. Even using a SIEM system, things can easily be missed just through exhaustion and complacency. However, if you drop the data into GenAI, you can quickly summarize unusual remote access patterns, flag uncommon process relationships, and suggest high-risk hosts for deeper investigation. And you can do it all from the raw event log data. And in a matter of minutes, GenAI can identify devices that showed suspicious use of tools like PowerShell and RDP connections that would have otherwise needed hours upon hours to uncover manually. That's the power of GenAI. What would normally take you a day or two to review and analyze, GenAI can do in minutes.
Now, I know that sounds awesome, but I do want to pump the brakes for just a second. I want to be honest and clear about something. GenAI is not magic. While it's incredibly fast and powerful, it comes with serious limitations that you need to understand, especially as a cyber security professional. One is hallucinations. It can confidently make up wrong answers. Two, lack of real understanding. It doesn't really know anything. It predicts based on patterns. No real-time awareness. It doesn't know your live network state unless you feed it that in context. Security risks. If misused, it could leak data or suggest insecure configurations. And auditability. It's harder to trace why it gave you a specific answer compared to a script. So the rule of thumb here is very simple: Trust, but always verify. Always validate AI-generated outputs before acting on them, especially in a cyber security environment. And we'll dive more and more into the risks and ethics in an upcoming lesson.
For this lesson, remember that GenAI is not a script. It's a pattern-predicting, content-generating system. LLMs are trained on massive data sets and generate flexible, human-like responses. Traditional automation is about precision while GenAI is about context and creativity. RAG adds reliability by grounding GenAI in your own private data. GenAI is fast, flexible, and powerful, but it is not perfect. You always want to validate outputs before you use them.
Okay, the world of cyber security is changing fast. And GenAI isn't just the new shiny toy. It's a new way of thinking and a new way of working. And now that you understand what it is and how it's different than the tools you've used before, you're ready to start applying it in real-world problems. In the next lesson, we're going to explore why GenAI matters right now for cyber security and what you can do today to stay ahead of the curve. You're not just learning a new tool. You're upgrading how you think, how you solve problems, and how you deliver value in your career. So, let's keep going and I'll see you in the next lesson.
Are you overwhelmed with your tasking, drowning in alerts, burned out staring at another 300-page compliance report? Or maybe you've gotten halfway through an incident investigation when another fire breaks out and your team is short-staffed again. And if you've ever found yourself thinking, "There's just not enough of me to go around," you are not alone. Most cyber security teams are being crushed under the weight of their responsibilities. And that's exactly why this lesson matters.
In this lesson, we're going to break down why GenAI isn't just a nice-to-have for security pros. It's quickly becoming a non-negotiable tool in your arsenal, and it's a skill that needs to be on your resume as well. So, here's what we're going to cover in this lesson. We're going to talk about the reality of today's cyber security battlefield, how GenAI is changing the rules of the game, where it can make the most impact right now, real-world use cases across SOC, threat intelligence, pen testing, and audits, and the new role of cyber security pros in an AI-assisted world. If you've ever wished for a second brain or needed another pair of hands, you're about to meet your new assistant.
So, let's paint the picture of a typical day in cyber security. Maybe you walk into the SOC and there's a backlog of 3,000 alerts. Your SIEM tool like Splunk or Elastic is yelling at you. Your EDR platform is eerily quiet, which is more concerning than if it were noisy. And oh, you've got a meeting at 11:00 a.m. with the CIO to explain why last week's threat report is still in progress. Meanwhile, another analyst is running on 3 hours of sleep and your threat intelligence person just left because they got hired by a tech startup. That's a lot to deal with, right? And here's the truth. The volume of data we're expected to process sometimes is inhuman. The number of tools that we use has ballooned. And each of them has their own alerts, notifications, dashboards, and let's be honest, quirks. We're expected to not only detect threats, but to understand them, explain them to the business, and prove resolutions and compliance. Plus, we're doing this all with a skeleton crew and rotating personnel. And I won't even get into the other parts about hours, pay, and other issues. It's just not sustainable. And we know it. Our teams know it. Our companies know it, too. And honestly, our adversaries know it as well.
So, let's not pretend that GenAI is a magic wand because it's not. But in the hands of a smart, strategic cyber security pro, it can certainly feel like one. So, where does GenAI actually help out? For one, it speeds up the work that's slowing you down. You know, there's repetitive tasks that eat up your day, right? Writing compliance documentation, summarizing security incidents and after-action reports, creating assessment and audit reports, parsing through log files. Yeah, GenAI can eat these things for breakfast. You can use GenAI to draft up security incident summaries in just seconds, to auto-generate playbooks from observed actions, and to write regex queries, Python scripts, or even PowerShell commands based on natural language.
It can also help translate "tech speak" into business clarity. Security pros often struggle with this translation. We use too many buzzwords. We speak in CVEs, indicators of compromise, and lateral movement. Executives don't care about this. They want to hear risk, impact, and budget. GenAI can take a threat intelligence brief and turn it into a plain-language executive summary for your CIO or your CEO. It can write both the board-ready paragraphs and the technical mitigation steps all at the same time, all from one single prompt.
It can also make scalable analysis a reality. Instead of manually digging through logs from six different tools, you can drop them into a well-designed prompt and ask AI to find correlation patterns. Want to compare findings from 100 vulnerability scans across five different regions? AI can do that for you, too, in seconds. Plus, it catches what we as humans might miss. Human fatigue is a real vulnerability, and we are all guilty of it. When your SOC analyst hits their ninth hour of staring at alerts, something's going to slip. But GenAI doesn't even blink. It can continuously review data, summarize anomalies, and flag gaps, even if the human eye glosses over them.
Now let's walk through how different roles can supercharge their work with GenAI right now. Not someday or in theory, but right now, today. Let's start with SOC analysts. Security Operations Center teams are the front lines. They face alert fatigue, triage pressure, and data overload. With GenAI, analysts can paste raw alert payloads and ask, "What is this trying to tell me?" It can generate quick summaries of incidents for shift turnover. And it can automate Tier 1 triage responses using GenAI paired with SOAR platforms. It's like adding an intelligent assistant who never gets tired and knows how to speak Splunk, QRadar, Wireshark, all at the same time.
What about penetration testers? Red teams love creativity, but almost everyone hates writing reports. With GenAI, you can turn raw notes into well-structured, evidence-backed executive summaries. You can auto-generate attack paths and MITRE ATT&CK mappings from test logs. You can also draft realistic phishing emails or payload scripts with just a concept prompt. It cuts reporting time in half, freeing up more time for actual testing.
How about security auditors or GRC analysts? Both live in spreadsheets, GRC tools, and frameworks. With GenAI, you can map your current controls to NIST, ISO, or CIS frameworks with natural language. You can analyze logs and summarize control effectiveness. You can also create plain-language explanations for policies as well. It's like having a compliance consultant living inside your text editor.
What if you work in threat intelligence? Intel folks swim in OSINT, threat feeds, and PDF reports. With GenAI, you can summarize multiple news sources into one cohesive intelligence brief. You can translate foreign language threat reports instantly, and you can compare multiple indicators to known TTPs in seconds. Now again, it doesn't replace your analysis, but it can turn 8-hour mundane tasks into a near real-time insight engine.
Now, let's bring it all home. GenAI matters right now because it helps solve real problems that security teams face every single day. Here's what I want you to remember. Cyber security professionals are under siege from data, tools, time, and threats. GenAI isn't a gimmick. It's a force multiplier. It saves time, reduces error, and frees you up to focus on high-value, human-on-human work across roles from SOC to auditing. GenAI can immediately remove friction and increase impact. And those who learn how to use GenAI now will have the edge. Those who wait will be left behind. The world doesn't need more burnt-out cyber security professionals. It needs empowered ones. And GenAI is here. It's capable, and it's ready to help you do more with less and do it better than you ever could before.
Now, in the next lesson, we're going to tackle something just as important: how to use GenAI responsibly. Because with great power comes, well, you know the rest. So, I'll see you there.
What if I told you that the biggest security threat in your AI workflow is, well, you? That might sound kind of harsh and maybe dramatic, but here's the truth. GenAI is like handing a powerful weapon to a well-meaning but slightly reckless intern. It can do amazing things, but only if you know how to guide it, safeguard it, and take full responsibility for what it produces. That's why in this lesson, we're going to shift gears a little bit. Up until now, we focused on the promise and potential of GenAI tools like ChatGPT, Claude, and more. And it's pretty exciting, right? But in this lesson, we're going to talk about the dark side of GenAI. Now, this isn't meant to scare you away or anything like that. It's meant to show you how to use it safely, ethically, and smartly. We're going to talk about the risks, the responsibilities, and the real-world implications of using AI in a cyber security context.
What we're going to talk about are things like operational risks like hallucinations and bad prompts, security concerns including data exposure and plugin vulnerabilities, ethical use guidelines that protect your credibility, and legal and liability boundaries that you must respect at all times. And I've also included a downloadable responsible AI use policy that you can adapt in your organization.
Now, obviously, GenAI is a game-changer in our work, but it's also a black box. While it sounds confident with answers and it's lightning-fast with its responses, it doesn't know truth from fiction. It doesn't know context from confusion or ethics from exploitation. That's why it's called artificial intelligence, not absolute intelligence or actual intelligence. And in cyber security, it can be very dangerous, catastrophic even, if we trust it too much. For example, let's say that you use ChatGPT to draft a vulnerability report and you blindly go with the results. Then that report is passed up the chain. Decisions are made based upon it, and two weeks later, your organization gets breached. And come to find out, ChatGPT misinterpreted a prompt and it incorrectly downplayed a critical risk. Now, that's bad, right? But here's the question: Who's responsible for that? Well, you are. It's not GenAI. That's why we need to understand not just what AI can do, but what it shouldn't do without your oversight.
Now, let's break down the responsible use of AI into four key areas: Operational risks, security risks, ethical use, and legal and liability. So, let's start with operational risks. One thing that catches people off guard is AI hallucinations. AI models sometimes produce outputs that are factually incorrect, but they're presented with confidence. And this isn't a bug or a flaw. It's how the language model works. They predict the most likely word sequence, not the most truthful or accurate one. You're using GenAI to summarize a CVE or explain a threat vector. You might get complete nonsense, but wrapped in a nice bow. Why does this happen? Well, prompt errors can lead to bad outputs. A vague or misworded prompt can impact the entire AI decision-making process. For example, "Explain how to mitigate this vulnerability" might trigger generic, outdated advice if you don't specify the environment or even the use case. Prompt engineering is your new skill set. Think of prompts as configuration files for your AI assistant. The better you are at engineering them, the better your outputs and the fewer hallucinations and misfires you'll get. In future lessons, we'll go deeper on this and I'll teach you how to prompt engineer like a pro.
But from an operational perspective, how do you decide what kind of model to use to ensure that you get the best results? Well, you need to ask: Is this data confidential, sensitive, or regulated? Does this model need access to internal tools or systems? And are you testing, prototyping, or deploying? So, in general, you want to use public SaaS models like ChatGPT, Claude, Perplexity, and more for brainstorming, generic research, or external-facing comps. Now, the model you use does not matter. What matters is the output you get from it. You also want to use private or self-hosted models like Llama 3, Mistral, and Claude on-prem for anything involving protected data, proprietary code, or internal incident response. And you also want to use local models for maximum control, auditability, and compliance with regulations like HIPAA, GDPR, and FedRAMP.
Now, what are the security risks of GenAI? This is where we really put our cyber security hats on. And again, we're talking about security with AI, not security of AI. Protecting the AI system is another course all in itself. This is about prompt engineering. Now, these are some of the general best practices, and you need to follow your organization's governance and data protection when using AI. First, never input sensitive configurations, logs, or keys. Don't paste logs, API keys, token headers, or sensitive IP addresses directly into public AI tools. Assume that everything you input is stored, used to train the language model, or is otherwise seen by the AI company unless explicitly stated otherwise. We always want to sanitize, redact, or anonymize data first, then use it for prompting. Use local scripts or AI-assisted tools to redact sensitive data before we submit it. For example, we want to replace real domains or user information with placeholders like `[domain]` or `[user_id_1]`. Also, be careful with browser plugins. Some GenAI tools allow third-party plugins that can access your prompts, files, and even your clipboard. So, always check data handling policies before enabling them. Add. Be sure to turn them off in sensitive environments. Something else that I highly recommend is to treat prompts like external data. Just like you sanitize or redact inputs to a database or API, you want to treat every prompt or response as untrusted. Validate it, test it, cross-check it, make sure it's valid before using it anywhere in your work. Also, use local LLMs when needed to keep data safe. There are fantastic open-source models that you can run on-prem like Llama, Mistral, and Mixtral. These give you full control. There is no risk of leaking IP addresses or violating compliance requirements. And we'll discuss these in a future lesson.
Now, let's talk about ethics when it comes to AI. It's easy to get dependent on using AI for just about everything, but that doesn't mean you should in every case. First, always disclose AI involvement in your work. If you've used AI to generate a report, draft a security recommendation, or summarize a briefing, say so. Transparency builds trust and it covers your back as well, especially when it comes to things like clients, customers, and compliance. Never blindly trust GenAI outputs. Verify everything that it generates. Use AI for drafts, summaries, or idea generation. But remember, you are the expert. You're the professional. Never rely on GenAI for final decisions without human review and validation first. Also, watch out for bias when it comes to security risk. GenAI models are trained on internet data. That data may contain subtle biases that affect how they rank risk, describe threats, or recommend actions. GenAI does not know your organization's objectives, its policies, or its risk tolerance levels. So always check outputs for assumptions that don't align with your environment.
And of course, be aware of the legal liability when it comes to GenAI. You are always accountable for what comes out of GenAI. Even if it writes the words, AI is your co-pilot. It is not your scapegoat. If an AI-generated analysis causes harm or leads to a failed audit, it's still your name on the result. So we never want to use outputs verbatim for policy or enforcement. GenAI does not understand nuance or organizational context. So always vet outputs before embedding them into policies, tickets, documentation, or enforcement procedures. Use AI to accelerate your work, but the output should go through the same reviews, approvals, and oversight as any other official communications or technical recommendations.
Now, again, as part of this lesson, I've included a downloadable responsible AI use policy template. This isn't just a checkbox item. Adapt it, share it, and enforce it across your teams. It includes guidelines on data handling and prompts, disclosure and attribution of AI use, roles and responsibilities for human review, model selection and access controls, as well as plugin and extension usage policy. So, make it your own and make this policy part of your internal governance toolkit. Treat it like you would your incident response or change control policy because AI is a part of your workflow.
Now, so here's what I want you to take away from this lesson. AI hallucinations are real. And while AI might sound confident, always validate its output. Bad prompts equal bad decisions. Learn to engineer prompts thoughtfully, which I will teach you in this course. Sensitive data never belongs in public models. Follow your corporate governance and use redacted data or use local GenAI tools when necessary. Transparency builds trust. Always disclose GenAI involvement in your work. You're legally and ethically responsible for all AI-generated content. And be sure to download the responsible AI use policy and make it your own.
Now you've completed one of the most important lessons in this course. While GenAI can help you move faster, write better, and think broader, it can just as easily undermine your security posture. It can erode trust and expose your organization to massive risk if it's misused. But that's not going to be you. You now have the framework, the mindset, and soon you'll have the hands-on skills to make GenAI your safest, smartest tool in the shop. Next up, we'll recap what we've covered in this section and then move on to building your GenAI toolkit. So, I'll see you in the next lesson.
Welcome to the recap of our first and arguably the most eye-opening section, the introduction to generative AI for cyber security. You just made it through the fundamentals. You've seen what GenAI is, why it's different, and how it's reshaping cyber security right now. Not in 5 years, not in some lab setting, but in real environments, audits, and incidents right now. So, as we wrap up this section, here's what we're going to do. We're going to lock in the most important ideas from this section so that they stick. I'm also going to show you how to put those ideas into practice through a hands-on, real-world scenario. And then I'm going to get you primed for the next section, which is building your GenAI toolkit. This is where we're going to start assembling your actual AI workflows.
Okay, so now let's rewind real quick. You started this course with a familiar frustration: there's too much to do, not enough time, and the tools don't talk to each other. In cyber security, we're expected to analyze threats, document compliance, educate users, write scripts, and so many other things without losing our minds in the process, right? And AI, well, up until recently, it either sounded like magic or marketing fluff. But now you know better. You've seen that GenAI isn't just some future tech. It's your new teammate, but only if you know how to use it ethically and responsibly. But the truth is, GenAI can accelerate your work, or it can magnify your mistakes. It's not automatic. It's strategic. And that's what this section was all about.
Okay. Now, let's recap the five big ideas you should now own. First, GenAI is not automation as you know it. It doesn't follow scripts. It predicts patterns. That means it's creative, flexible, and conversational, but it's also unpredictable. It can help you generate rules, write phishing simulations, and summarize logs, but it can also hallucinate and make confident mistakes. Second, it's a force multiplier, not a replacement. GenAI helps you do more with less. Whether you're in a SOC, working GRC, threat intelligence, or even red teaming, but you remain the decision-maker. Third, prompt engineering is your new essential skill set. The way you talk to GenAI is the configuration. Good prompts equal great outputs. Bad prompts equal misleading, risky, or just plain wrong results. Fourth, GenAI comes with real risks: hallucinations, data leakage, ethical blind spots, legal liabilities, and more. You are responsible for what it produces. That means validating everything, disclosing AI use when appropriate, and never pasting sensitive data into public models. And fifth, GenAI is already practical. It can help summarize a 14-page threat report, translate a firewall configuration into business terms, or identify suspicious PowerShell activity in massive log sets.
Okay. Now, let's say you're working as a SOC analyst. You've just been handed an incident report from a few days ago. Your manager wants two things from you by 10:00 a.m. for an important meeting. One, they want a short executive summary for the CIO. Two, they want a list of top action items the remediation team can work on. And oh, by the way, it's 9:40 a.m., leaving you 20 minutes to do this. So, you need to act fast. And because you've taken this course, you know the fastest way to do this is have GenAI help you.
So, step one is to open a browser window or a tab, go to ChatGPT or another GenAI tool of your choice, and you can paste this prompt: "You are a cyber security analyst. Summarize the following incident report into a three-paragraph executive summary suitable for a C-suite audience. Focus on risk impact, timeline of events, and current containment status. Then provide a prioritized list of five technical remediation steps for the IT remediation team."
So what I'm going to do is go to my course artifacts and I'm going to drop in that incident report sample. And so now ChatGPT will analyze that for us. And in a matter of seconds, here is our executive summary. We have compromised credentials that belong to a service account. The geolocation is Eastern Europe. It was flagged by the XDR platform, and so on. So you can see that this is a pretty detailed summary of what happened. Now, if you scroll down a little bit, here are our top five technical remediations: First, we want to enforce multifactor authentication, audit and rotate credentials, perform full forensic analysis of the Jenkins server, harden the VPN gateway, and deploy continuous monitoring for lateral movement. In seconds, this is a lot of information.
Once this is done, step two is to evaluate the results critically. Does the summary make sense? Are there any hallucinations anywhere? Did AI leave out any critical details? That's where our judgment comes in. Step three is to edit and finalize the output. Remember, you are the editor here. You're in charge. So, tell AI what you want to do. You can ask it to say something in plain language, tell it to research deeper, or update anything you see that might be questionable. This is where you add your own judgment or refine the wording based on your expertise. If you're not sure how to do that, I'll show you how to do this as we progress through the course. Step four is to be transparent. Write a sentence at the top of the summary that discloses AI involvement. Something like, "This summary was AI-assisted and has been reviewed for accuracy by [whoever it is]."
Okay. And as a bonus challenge, you can add this prompt to your notes and experiment with it. Tweak this prompt to give you different outputs, format things differently, go deeper than what we did here, and more. Again, I will show you how to do all of this throughout this course. The point is this is how you'll build your GenAI skills, not by reading or watching, but actually doing.
Okay, now, at this point, you should walk away with five big lessons from this workflow: One, GenAI works differently from automation. It predicts patterns, not logic. Two, you are the editor, the validator, and you are the one accountable for the output. Three, prompts are everything. Better prompts equal better results. Four, responsible use is non-negotiable legally, ethically, and operationally. Five, GenAI can already save you time today with the right mindset and the right setup.
Now, this section was just the beginning. In the next section, building your GenAI toolkit, we're going to move from theory to systems. I'm going to walk you through the essential tools that you'll want to have on hand for the rest of this course. You'll learn how to pick the right AI for the right task, how to plug AI into your existing security stack, and how to set up workflows that run faster with less effort and better results. So, as we close out this section, you are GenAI ready, and your future workflows are going to thank you for it. Okay, so let's get into building out your GenAI toolkit and I'll see you in the next lesson.
Did you know that the right GenAI platform could make you 10 times more effective at your cyber security job? However, choosing the wrong one might leave you spinning your wheels. So, how do you pick the right one? If you want great results, you need the right tools, and you need to know when and how to use them. That's why in this lesson, we're diving into one of the most important decisions you'll make as a cyber security professional who works with GenAI, and that is choosing your platform. I'll walk you through the major players in the AI space. I'll show you what they're best at, and I'll give you real-world advice on how to pick the best ones for your role. We'll also cover the differences between cloud-based LLMs and local LLMs, and why that even matters to you. And by the end of this lesson, you'll know exactly which tool to start with, how to expand your toolkit, and why starting simple will build your success faster.
Now, here's the real challenge. With so many GenAI tools out there, and there are a lot, with all of them claiming to be the best, which one do you pick? I know it's easy to get overwhelmed. It's like selecting a SIEM system, right? There are dozens of choices out there. Do you pick Splunk because that's what's hot right now? Or do you pick Elastic because of its flexibility? Do you go with QRadar because your company uses IBM? Or do you go with LogRhythm, AlienVault, or whatever other tool is out there? Or do you pick the one that meets your requirements and actually gets the job done? In cyber security, time is everything. Whether you're triaging incidents, writing reports, or analyzing threat logs, you need a GenAI tool that fits your workflow, not one that slows you down. And if you pick the wrong AI tool, you'll waste hours struggling with a tool that's way too limited, too complicated, or too rigid, just like a SIEM system.
So, let's cut through the noise and get crystal clear here. First, let's talk about the top cloud-based LLMs that I recommend for cyber security pros. While you might have your own preference, that's totally fine. These are just the ones I recommend. You are welcome to choose whatever works best for you in your working environment. Okay, so first, what are cloud-based LLMs? These are large language models that live in the cloud. Basically, you just create an account on a website and just start typing away. There's no heavy setup or anything else you really need to do.
The first and most popular at this time is ChatGPT by OpenAI. This is your all-around Swiss Army knife. Whether you're automating emails, drafting incident reports, creating triage workflows, or even scripting basic automations, ChatGPT nails it all. Now, here's a pro tip for you: I highly recommend getting ChatGPT Plus, which will cost you about $20 a month. It unlocks plugins, web browsing, and other advanced capabilities that can take you to another level. So, if you're serious about leveling up, it's 100% worth the money.
Next is Claude by Anthropic. Think of Claude as your document heavyweight. Got a giant SIEM log that you need to digest? Claude is built for chewing through large data sets and giving you clean summaries and action items. And the last one I recommend is Perplexity. Imagine a sharp research assistant who gets you fast, verified results. That's Perplexity. It's amazing for fact-checking, quick research, and validating sources without getting caught in AI hallucinations. It's also great for when you're writing policies, running audits, need citations, and more.
Now, again, these are just the ones I recommend, and these are the ones I will focus on in the course. Of course, there are a lot of other tools that you're going to bump into out there like Microsoft Copilot, Hugging Face Models, Darktrace's AI, Elastic AI, and Security Scorecard's new tools, plus many others that I did not mention. Each has its place, especially when integrated into your organization's ecosystem. But remember, the best tool is the one you actually use. And I want to keep this course simple and easy to follow so that you get the best results. There is no right or wrong answer here. However, the three tools I recommend here are all free to use and will give you very, very good results. If you want to use other GenAI tools, that's totally fine as well.
Okay, now let's talk about local LLMs. These run directly on your machine. They give you more privacy, more customization, and they don't rely on cloud access. The first one to look at is GPT4All. This is a fantastic open-source project that lets you run a small but capable AI on your laptop. It's great for offline work and sensitive data as well. You can also look at something like NexChat, which is another good option that's focused on local privacy and flexible performance. And something like Jan is designed to be user-friendly and extremely responsive. It's growing rapidly as a local solution that's good for document handling and internal automation.
And again, there's no right or wrong answer here. Do some research, see what feels right for you, and pick the one that works best for you and your working environment.
So, do you go with a cloud-based LLM like Chat GPT or a local LLM like GPT for all? Well, it's important to understand the risks and benefits of cloud-based LLMs versus local LLMs. As a cyber security professional, recognizing these trade-offs is super important.
With cloud-based LLMs, you get easy access from anywhere with no complicated setup, powerful cloud infrastructure for faster and better results. It's always updated automatically with the latest improvements and features, and its easy integration with APIs, plugins, and workflows as well.
However, some of the risks are data privacy concerns. Your inputs might be logged or stored based on the provider's policies. You also have limited control over the model's inner workings, and it also requires a very good internet connection to use. For example, pasting sensitive incident details into Chat GPT could accidentally expose private company data, even if anonymization is promised. So, we always want to sanitize data before sharing sensitive information when using a cloud-based LLM.
With local LLMs, you get full control. Your data stays on your own machine. You also have the ability to customize models for your specific needs. And you can have offline access with no need for internet connectivity.
However, some risks are the technical complexity of it all. It requires strong hardware and setup knowledge. It also requires maintenance responsibility. So, you must handle the updates, patches, and security. And performance might be a little slower compared to cloud-based LLMs. For example, running GPT for all locally lets you analyze private logs securely, but without regular updates, you might introduce new vulnerabilities.
Now, with all of that said, which one should you choose? For me, I highly recommend cloud-based LLMs like ChatGpt, Claude, Perplexity, and more. These will handle most of your work because they're faster, smarter, and where innovation is happening the quickest.
However, you need to be very careful about what you share inside these cloud-based platforms. You never want to input client data, confidential reports, proprietary security methods, or personally identifiable information or PII. And you always want to summarize, sanitize, or simulate sensitive information as well.
If you want to work with real sensitive data, you should set up a secure local LLM environment. This way, you get the power and security of both worlds.
Now, here's a little secret. In real-world cyber security work, pros don't just use one tool. They chain them together. For example, you might start by outlining a triage report in Chat GPT, then push a giant SIM log through Claude to extract the critical events. Finally, then you verify your thread intelligence using Perplexity. That's how you get elite-level results without breaking a sweat. This is, of course, after you sanitize any sensitive data.
Right now, if you're just starting out, grab a free Chat GPT account. It's enough to get hands-on practice with everything we're going to cover here, and it's very powerful. If you're ready to invest a little in yourself, ChatGpt Plus is a game-changer. Not just because it's faster and better, but because it gives you access to real-world professional-grade features and access to more advanced models that you'll consistently use.
Now, we'll go through all the details about which models, versions, and more later on. For now, here are the key points that I want you to take away from this lesson. Cloud-based LLMs are easy and fast. We'll mainly work with Chat GPT throughout this course, but I'll also demonstrate Claude and Perplexity as well. Local LLMs like GPT for all, Next Chat, and JAN are great for privacy and offline work. You want to use tools that fit best into your workflow, not one size fits all. We also want to chain different AIs together for powerful professional results. And you should start with a free Chat GPT account or upgrade to Plus if you want the full experience.
Remember, choosing your Gen AI platform wisely is the first real step to mastering Gen AI and cyber security. You don't need to know them all. You just need to start using one, get comfortable with it, and build from there. And in this course, I'll show you not just how to use these tools, but how to dominate with them.
All right. Now, let's move on to the next lesson and let's get our hands dirty with setting up your AI workspace and I'll see you there.
Have you ever spent more time setting up a tool than actually using it? I know I have, and that is not happening in this lesson. And cyber security speed matters, and that includes setting up your Gen AI workspace. In less than 10 minutes, you'll be fully ready to start using Gen AI like a pro. No tech headaches, no complicated installs, just pure focused setup so you can jump right into the good stuff.
In this lesson, you'll learn how to quickly create your GenAI accounts with no friction, how to navigate the Chat GPT interface like a pro, and how to organize your prompts and work smarter, not harder. We'll also talk about the simple security best practices that you must know when working with GenAI and also where to grab two powerful downloads that make sure you're secure and ready to go.
Okay, now let's start with getting you set up fast and smartly. I know that there's way too many cyber security pros that get stuck at the starting line. They waste time fumbling through signup pages, bouncing between browsers, and feeling overwhelmed by features that they don't even really need. And to be honest, they get caught up in what's hot, trendy, and most recent. Meanwhile, the goal here is very simple. We need to get you operational fast, safely, and efficiently without turning all of these steps into another agile sprint because the faster you start practicing, the faster you can level up.
Three main accounts that you'll need. They're all free and web-based. Now, one tip I want to give you before we get started is to use a professional email address. If you're going to use these tools for work, you want to use a professional email address. This makes account management and security compliance much easier if you're ever questioned about using GenAI for your work.
Now, the first and most important is OpenAI Chat GPT. This is going to be the primary focus for the course. To create your account, go to chat.openai.com openai.com and then you're going to sign up with an email address and you can click this login button right here and you can see where it says ChatGPT. So you click on that and then you can say sign up for free and then walk through the steps to set up whether you want to set it up with a private or professional email address or you want to use one of your Google, Microsoft or Apple accounts. And it's really that simple. You'll verify your email and phone number, and your phone number is just for account verification. OpenAI won't text you, call you, or anything like that. And right from there, you can start using Chat GPT for free. That's it. If you want to upgrade to ChatGpt Plus at this time, you can. This is optional, but it is highly recommended if you want better outputs and better results.
And next is Claude. The easiest way to set up Claude is to go to httpsclaude.ai/lo and then you'll sign up with an email and in this case again use your professional email and you'll click continue and just follow the steps. It's very, very simple, or you can use your Google account if you want to. You may also be asked to verify your age and some other details, but make sure you click stay on free plan and then you'll go through a few onboarding questions and get started. And that's it.
Finally, there's Perplexity. The easiest way to set this up is to go to perplexity.ai. Sign up with your email address again, and you can click right here, or you can use Google or your Apple account. And remember to use a professional email. And that's it. That's all you need to do to get these three accounts set up.
Now, I want to go back to Chat GPT. Once your Chat GPT account is live, let's get comfortable with it. First, the conversation window is where all of your prompting magic happens. You'll type your prompt at the bottom or in the middle like you see here, and Chat GPT responds above in the window. Also, conversation threads will automatically save into your history, which is on the left sidebar. For example, if I wanted to type this simple prompt, "Please explain to me why GenAI is valuable to cyber security professionals." I'll hit return and you can see Chat GPT automatically start responding and once it's done responding, you will see it appear in this left sidebar and you can see that it says that it accelerates threat detection and analysis. It enhances incident response. It speeds up cyber security training and knowledge sharing. Assists with threat intelligence and reporting. Improves security operations and automations. Helps with red team and blue team simulations. Closes the skills gap and so on. There's a lot of information that Chat GPT just gave us, much of which I'm going to teach you here in this course, but as you can see, it didn't populate on the left. So, what I'll do is I'll just reload this page real quick. And now you see that there's a chat thread here. And the more chats you have with ChatBT, the more chats you will see on the left-hand side.
One other thing is that you can set up custom instructions. This can boost both the effectiveness and efficiency of your conversation. Custom instructions allow you to set Chat GPT's context, who you are, what you're trying to do, your experience level, and how you'd like responses to be framed. For example, if you're a SOC analyst, you can tell Chat GPT to focus on SIEM queries, log correlation, or threat intelligence summaries. And you can set that by clicking on the avatar right here. And you can say customize Chat GPT. And when you do, you'll just follow a couple prompts and then you can open this right up. To do that, you would click on the avatar here, click on settings, then go to personalization, and you can see custom instructions right here. And when you click on that, it will open the window. And now you can give it a nickname where you can say SOC analyst if you want. You can say security engineer. You can say whatever you would like. And then what we can do is we can talk about who we are, what we're looking for, and all kinds of different things. Now again, I want to keep this simple. So we're not going to focus too much on creating these instructions.
Now I sometimes personally I find it cumbersome when I'm looking back through conversation. And if you go down here to the advanced tab, you can see that it will search web. It will do code for you. It'll break things out into a canvas. And it'll do advanced voices. All things that we'll talk about later on in the course. Okay. Now, personally, I like to turn canvas off. Canvas is a feature that lets you work on code or documents side by side with Chat GPT in a visual editor kind of thing. Me personally, I find it cumbersome when I'm looking back through conversations and I want to copy certain things. I prefer to see the entire conversation in the window, so I disable it. If you like it, awesome. Just know that it won't have any effect on your outputs from this course. It's just a personal preference setting. I've included a download with some examples of what you can include for customizing ChatCBT to make it easier for you.
Okay. Now, again, all of your conversations are automatically saved unless you disable this, and you'll see those on again on the left side of the screen here.
Now, let's talk about how to organize your prompts. Everyone will have their own preference on how to do this, and I'll give you a few suggestions here, and then we're really going to deep dive this later on in the course. A simple document or spreadsheet works great. Something like a Google Doc or an Excel spreadsheet. These are simple and effective options. You can also look at tools like Obsidian or Notion. These are free tools that allow you to save local files and keep things private. I don't recommend posting your operational prompts on SaaS products like Notion online or any other tools like that. The point is, there's a ton of options out there, and there's no right or wrong way to do this. It's whatever tool works best for you and gives you fast access to your prompts. My only advice here is to keep it simple. Don't get bogged down and spend a ton of time worrying about the tool or the fancy features that they have. Worry about being able to find your prompts quickly when you need them. I recommend setting up a page, folder, or directory to organize your prompts like operational prompts for prompts that are proven to work, working prompts for ideas and experimentation, and then prompt chains and workflows, and create shortcuts or bookmarks so you can quickly access your prompt library. Trust me on this one. Your future self will thank you when you have a prompt ready to copy-paste instead of starting from scratch every single time.
Okay. Now, there's one other thing that we need to take into account, and that is security best practices. This part is non-negotiable. Gen AI platforms are amazing, but they are not secure environments for sensitive data unless explicitly configured by your IT or security teams. We never want to paste things like live credentials, client or customer information, personally identifiable information, PII, internal security policies, vulnerability reports, incident response or breach reports, and so on. We always want to treat Gen AI inputs as if they someday might become public. If you need to test prompts with sensitive concepts, use fake data or redacted examples. Remember that Chat GPT, Claude, and Perplexity are external services. It's on us to control the exposure, not on them.
Okay. Now, in this lesson, I've included two helpful downloads to make your workspace bulletproof. You get a "Secure Prompting Guidelines for Cyber Pros" PDF, and this is going to help you with best practices and show you how to sanitize your data and how to craft prompts safely without leaking any information. The other is a "Ready to Prompt Setup Checklist." This checklist will help make sure that your AI workspace is 100% ready to go. The links for both documents are here below the video.
All right. Now, what I want you to take away from this lesson is that you created your accounts for Chat GPT, Claude, and Perplexity. You know your way around the Chat GPT interface, the conversation window, custom instructions, history, and more. You also bookmarked your tools for quick access. You know that you should organize your prompts in a note-taking tool. And you know to follow security best practices and never expose sensitive information.
And there you have it. In under 10 minutes, you'll have a powerful AI workspace ready to help you work smarter, faster, and safer. Setting up your AI workspace is the first victory in mastering Gen AI for cyber security. It's simple, fast, and gets you out of setup mode and into results mode.
In the next lesson, we're going to focus on designing your AI workflow for speed and safety. So, get ready because this is where the real power starts. And I'll see you there.
As we start this lesson, I want to clear something up right away. You don't need a dozen Gen AI tools. You need a smart system that works for you. A lot of analysts and engineers get sidetracked chasing flashy extensions, new browser plugins, or the latest AI hack that's on social media. But the real game-changer here is a repeatable AI workflow that fits your day-to-day job and doesn't break security rules. That's why in this lesson, we're going to build exactly that. We're not building a lab or a sandbox. Our goal is to build a lightweight, secure, and effective toolkit that you can start using right now. Whether you're in a SOC doing threat intelligence or just trying to survive your alert queue without burning out, this lesson is the bridge to everything else in your AI-enhanced cyber security journey.
By the end of this lesson, you will know how to design a daily Gen AI workflow that boosts speed without compromising safety. You'll learn how to stay focused by organizing your prompts, tools, and outputs. You'll also be able to apply smart security guardrails to stay compliant and protected. And you'll also be able to build a personal system that gets better the more you use it.
So, let's start by grounding everything in what really matters, which is your daily work. We need to define a baseline workflow for cyber tasks. Whether you're in alert triage, threat hunting, or writing reports, the daily motions of cyber security are actually pretty repeatable. Here's where Gen AI fits in beautifully. Let's break it down into a simple basic Gen AI-powered workflow.
Step one is that we receive some kind of input. Something has to start the workflow. For example, say an alert pops up in your SIEM. Maybe it's Suricata, or you get an XDR hit, or a login issue. Whatever it might be, that's our input for the prompt.
Now, step two is that we need to sanitize or redact any sensitive information before we paste it into an AI tool. For example, we can replace real IP addresses with something like internal IP1. Or we can mask usernames like jdoe@corp.com to userA. Or we can swap host names like prod-db1 with critical-asset-1.
Now, for this course, I have created artifacts for you like reports, tool exports, and other supporting files that are simulated and don't contain any real or sensitive data. And because of that, no data sanitization is required for you to use them for exercises or demonstrations. However, if you like to practice the process of data sanitization as a learning exercise, you can open each file using tools like Microsoft Word, Google Docs, or Notepad++. From there, you can manually find and replace sensitive data such as usernames, host names, IP addresses, file paths, and more.
Okay. Now, step three is to use AI to summarize or suggest any next steps. This is where you drop the sanitized alert into the Gen AI prompt with something like this: "You're an experienced cyber security incident response analyst. Please analyze this XDR alert and identify any threats. Rate the severity of each threat and provide any recommended next steps. Provide your response in a summarized report that I can provide to my team."
And boom, just like that, in a matter of seconds, you get a summarized version of the alert, any threats that are present, and a recommended action plan.
Now, this is awesome, but again, we cannot blindly trust that AI is correct. So, step four is to validate the output from Gen AI and confirm its findings. So, by comparing the raw log against what Gen AI discovered, you can quickly see if it's correct or not. So you can ask, "What evidence supports this finding and risk ratings?" Ah, Gen AI highlighted that for me, and I agree with those results. Perfect.
So now, the next step, step five, is to store or share the result. You can update your case management or ticketing system like Jira, ServiceNow, or The Hive and document your findings. And your AI-generated report is clearly structured and communicates what is needed for any next steps. This is the exact loop we're going to refine and build on throughout the rest of this course. It's simple, it's scalable, and it keeps you in control. Pretty awesome, right?
So, that's a straightforward AI workflow and one that we're going to revisit all throughout this course. Now, let's talk about one of the highest leveraged things you can do, which is to organize your prompts. If you've ever found yourself writing the same AI questions over and over or trying to remember what worked for that CVE alert last week, you already know that pain. So, what we want to do is create a personal prompt library. And here's how I recommend doing that.
What I like to do is I like to create two main categories for my prompts. The first one is operational prompts. These are your prompts that you have used and they've been proven to be effective. For example, these are prompts that summarize this alert in MITRE format, or write shift notes from these events, or generate remediation steps for this incident. These are tried and true, and you can trust the output from these. Put those prompts in this category.
The second category is experimental prompts. These are for exploration, learning, or testing. So maybe you're trying to figure out how to rewrite this log into plain language for new analysts, or what detection rule could help catch this earlier, or maybe suggest Yara rules based on this behavior. In short, these prompts aren't proven yet. They do give you consistent results, but they can't be trusted in an operational setting. Put those prompts in this category.
And under both categories, operational and experimental, I have a directory or folder for prompt playbooks. These are multi-step prompts that simulate the analyst process. And I use these for all kinds of things. For example, let's say you have a playbook like this: Prompt number one is to summarize the alert. Prompt number two is, "What follow-up log should I check?" Prompt number three is to create a timeline of events. And prompt four is to generate a response plan. You'll have some playbooks that are proven to work. So keep those in operational prompts, but you'll also have some that you're working on, you're refining, and you're trying to get consistent. So those belong in experimental prompts. This ensures that you don't mix these up when you're actually doing real work.
Now, you can name these however you like, but the point is to keep proven working prompts in one place and test prompts completely separate to avoid any operational impacts. And a pro tip is to save each prompt with a label. Like have an emoji at the front, and then have something like "IDPS alerts work great on Suricata alerts," or have an emoji for "fire" and have "firewall configs compliance audit review," and so on. Over time, you'll build your own personal AI playbook that saves you hours each week. Plus, you can then start organizing your prompts based on platforms, purpose, and more. Pretty cool, right?
Now, where should you store this prompt library? Well, again, that's totally up to you. As I said before, the tool or the app is irrelevant. Remember, this is about speed and effectiveness, not trendy or flashy. So, keep it simple. You can use apps like GitHub, which I highly recommend because it has version control for operational prompts. Notion is super popular as well, but it does lack some security features in the free version. Or it could be something as simple as a Google Doc or Sheet in a secure Google Drive. There's also Obsidian, which is similar to Notion, but offers more privacy for free. Whatever works for you and gives you immediate access to your prompts is what really matters. Try them out. See which one works best for you and your situation.
Okay. Now, one more thing that I want to mention here is that you need to make Gen AI tools easy to access. I highly recommend creating a folder in your browser with the links to all of your AI tools. Here's how you can do that. First, create a Gen AI toolkit folder in your browser with links to your AI tools like Chat GPT, Claude, and Perplexity. Then have a link for your prompt library, a link for redaction guidelines, a link for any other helpful doc that you've built. I also use pinned tabs to keep the most frequent AI tools that I use accessible. Now, if you're using local LLMs, I create a directory or a folder with all of the shortcuts in it. That way, I don't have to go hunting around for tools. I just go to my folder, and all of my links are right there when I need them. This turns your daily discoveries into long-term productivity gains.
Okay, now before we wrap up, I definitely want to talk about AI safety because this is a non-negotiable topic and I want to repeat it just in case you missed it earlier. If you're using Gen AI on real operational cyber data, you must follow these basic guardrails or basic security practices. Never input production credentials, private keys, internal domains, real asset inventories. Always use placeholder tags like internal IP1, userB, or asset-critical01. You also want to use different user profiles, browser profiles, or containers for AI tools versus sensitive internal tools. We want to keep the line clean between what's secure and what's experimental. We want to sanitize or redact any sensitive information before inputting that into any AI tools, especially cloud-based or SaaS-based versions. For example, before you might have like a source IP, a username, and a host name. Before you put that into AI, we sanitize it, and then it looks something like this where you have a source which is internal IP1, user which is userA or userJS for the first two letters in the username, or host name like win10-asset-1. This is an important habit that keeps you compliant, private, and professional.
Okay. Now, let's bring it home again. You don't need trendy apps, Chrome extensions, or command-line AI Swiss Army knives. What you need is a repeatable, secure, and focused workflow that makes you faster, not frazzled. So, here's what I want you to take away from this lesson. You need to build a simple daily Gen AI workflow: Input, sanitize, prompt, validate, store. You also need to organize your prompts into categories: operational, experimental, and chained as well. And then also, we want to keep our tools at our fingertips. We want to use browser folders, pinned tabs, and personal documents. And we want to apply strict security guardrails: no sensitive data, separate environments, and we need clear sanitization and redaction of sensitive information. And we also want to focus on tools that work, not tools that impress.
Okay, don't build a lab. Build an effective toolkit, one that you can use every day under pressure without compromising security or your sanity.
Okay, now that you've got your Gen AI workflow dialed in, in the next lesson, we're going to recap everything we learned in this section. So, let's move on and I'll see you there.
If you opened up your laptop right now, do you have an AI toolkit that could help you write an alert summary, prep for an audit, or map a CVE to a response plan in under 10 minutes? If the answer isn't a confident yes, then this recap lesson is going to change that. Welcome to the final lesson of building your Gen AI toolkit. This section was all about getting practical and choosing the right tools to set up your workspace and create workflows that make you faster without compromising security. But it's not just about tools. It's about turning them into something repeatable. So in this lesson, we're going to recap the key decisions you've made so far. We're going to walk through a real-world use case using your toolkit, and we're going to prep you for the next section where we will dive into prompt engineering and unlock the full power of Gen AI for cyber pros.
Okay, so why does a Gen AI toolkit even matter? Well, let's play out a real-world scenario. You're in the middle of a high-pressure workday and a Suricata alert pings your inbox. It's noisy. It's unclear. And it landed right in the middle of your shift handover. You don't even have time to figure out which tool to use, where to find your best prompt, or how to redact sensitive information before even using Gen AI. This is where most people freeze, or worse, where they make a mistake. Either they copy and paste sensitive logs into the public model, or they waste 20 minutes trying to engineer a prompt from scratch. Why? Because they don't have the system that we just covered in this section. But now you do.
First, you learned how to choose the right Gen AI platforms for the job. Whether it was Chat GPT, Claude, Perplexity, or even local LLMs like GPT for all or JAN. Next, you set up your AI workspace in under 10 minutes with clean browser folders, secured login practices, and a fast way to switch between tools. Then you built a lightweight, effective, and secure daily AI workflow that mirrors real-world security tasks like receiving input, sanitizing and redacting sensitive information, using a tailored AI prompt, validating the output with your own judgment, and storing, sharing, or escalating the result. And finally, you learned how to organize your prompt library into two core categories: operational and experimental, with multi-step playbooks for recurring workflows. And we also talked about creating a folder for chained prompts as well. This isn't theory anymore. It's your actual system.
Now, let's put that toolkit to work right now and let's see how good it works for you. So, here's your real-world challenge. You're a GRC analyst preparing for an ISO 27001 compliance check. You just received a draft of an access control policy from a teammate, but it's super long, inconsistent, and missing clear language for end users. You have 15 minutes before the review call. Your job is to use your Gen AI toolkit to rewrite the policy summary into plain, actionable language that is suitable for a companywide distribution email.
Now, here's how to do it. If you recall from the lesson on designing your AI workflow, the first step is to receive input. That starts the workflow. And in this case, the policy draft is your input. And you can find a link to a simulated policy right here below the video. The next step, or step two, is to go through the policy draft and replace any internal names, system IDs, or user data with placeholders. And again, this is simulated data, so I've already done that for you. But if you want to practice that, you can change "Entra ID Finance Admins" to "Access Group A" or any other data that you want to change.
Then, step three is to prompt GenAI to analyze the policy. So you want to use a prompt from your operational library, and it looks something like this. I'll paste the prompt right here so you can see it: "You are a cyber security compliance analyst. Rewrite the following policy summary into clear, concise language suitable for non-technical employees. Focus on what actions users need to take, why it matters, and any dos and don'ts. And keep it under 200 words."
And so what I'll do now is I will upload the policy to Chat GPT, and it will analyze this for us. And as you can see, Chat GPT is now processing this and created a nice summary for us.
Step four is for us to validate the output. We're going to check the AI response against the policy and make sure nothing critical is lost or misrepresented. So what we need to do is open the document, take a look, and then also look at the output. The output is pretty clean. "What you need to know to protect company data. All access to systems like Outlook, Teams, and SharePoint is managed through groups in our Entra ID system. And here's what you need to know." And you can see the bullet points. So, this makes it very, very easy for you to understand what that policy says in just a few words. And if needed, we can tweak the prompt. We can also use a playbook or chain prompt to follow up. So, what we could do is we could add one sentence explanation of why this policy is important: "preventing unauthorized access." And I'll send that, and it'll go ahead and make the update for us. And there you go. "This policy helps prevent unauthorized access by making sure only the right people have the right level of access at the right time." Pretty awesome, right?
So, now we know that both of these prompts work. Are we happy with these results? If we are, step five is to store and share the results. We can paste this output into a shared GRC workspace or tool, or you can ask AI to create a report for you. And I'll show you how to do that later on in the course. Then we want to save this prompt to our operational library. And we can call it something like "Access Policy Simplification." And that's it. You just turned 45 minutes of work into a two-minute Gen AI conversation without leaking sensitive data or relying on any guesswork. How awesome is this? And without the foundational lessons in this section, you would not be able to do this.
Because of what you learned in this section, you know how to choose the right Gen AI platform for any cyber task. Whether it was Chat GPT for workflows, Claude for long documents, or Perplexity for quick research, you set up a workspace that's clean, secure, and ready to go, so you can launch into any Gen AI task without any friction. You've also built a daily AI workflow that mirrors how you actually work: from alert triage, redactions, prompt refinement, and reporting. You also have a prompt library that grows with you, one that separates what's proven from what's still experimental. And you also know the security guardrails: no credentials, no private logs, no unredacted data ever. So you've gone from a curious learner to an operational user in this section. And we're just getting started in this course.
All right. Now, take a second and look where you are. You don't just understand Gen AI anymore. You're starting to use it like a pro: responsibly, securely, and efficiently. In the next section, you'll learn how to take full control of the AI engine. You're going to learn prompt engineering for cyber security professionals. We'll cover how to craft prompts that consistently produce accurate, secure, and useful results. Not just for simple tasks, but for deep investigations, technical summaries, malware analysis, and even simulated red teaming. This is where you become not just a user, but a true AI operator. So, let's build on what we've created in this section, and I'll see you in the next section.
Have you ever typed a prompt into Chat GPT, hit enter, and gotten back something so vague, so generic, or just so plain wrong that you thought, "What in the heck is this?" Well, here's the hard truth. Often times, the problem isn't Gen AI, it's the prompt that you're using. In cyber security, where accuracy matters more than anything else, a sloppy prompt is like deploying a firewall without any rules. It looks like it's working, but it's dangerously ineffective. And in this lesson, we're going to transform the way that you write prompts. Specifically, I'm going to teach you how to engineer prompts for cyber security tasking. You'll learn how to design prompts that get sharp, relevant, actionable results, especially for demanding use cases in cyber security. We'll cover a simple but powerful structure for writing effective prompts, break down real-world examples, and walk through the anatomy of a great prompt using a well-known RACE framework. We'll also cover the three golden rules of prompt writing, the anatomy of a high-performing prompt, the RACE framework for prompt design, why poor prompts are risks in cyber security, and I'm going to show you some real-world examples, both bad and good prompts. And by the end of this lesson, you'll be writing prompts that are precise, powerful, and built for complex realities of cyber security work.
Okay. Now, let's be honest about something. Most AI prompts are bad. They're vague. They're missing the point. They're not specific enough. And worst of all, they waste your time. Poor prompts can lead to irrelevant or shallow answers, missed security issues, over-reported false positives, and endless follow-up prompts to clarify what you really wanted in the first place. In cyber security, this isn't just annoying, it's risky. You could easily overlook a misconfiguration in a firewall or misinterpret threat intelligence just because the AI wasn't told what to focus on. That's not just inefficient, it's dangerous.
So, how do we fix this? Let's start by mastering the three prompt rules every cyber security pro should follow. Rule number one is to be specific about the task. Don't just say "analyze this." Tell the AI exactly what you want it to do. Are you asking it to find misconfigurations? Are you asking it to summarize an incident or identify anomalies? Be clear and specific. Rule number two, provide context. What's the system? What's the asset? What role does it play in the environment? Gen AI needs a background to make accurate judgments, especially in cyber where one port open on a test system might be fine, but on production, that's an incident waiting to happen. And rule number three is define the output format. Is it going to be a table, a summary? Do you want it in JSON? Do you want an executive briefing, or do you want a long-form analysis? If you don't tell the Gen AI what kind of output you want, it'll guess for you, and guessing leads to garbage.
Now, to make it even more actionable, I want to talk about the RACE framework. It's a well-known framework in the Gen AI space, and it's a great place to start with prompt engineering. Here's how it works. R stands for Role. Tell Gen AI who it is. Is it a senior SOC analyst? Is it a red team operator? Is it an incident response consultant? A stands for Action. What exactly do you want it to do? Do you want it to analyze, summarize, compare, explain, or visualize? C stands for Context. What does it need to know to make an informed decision? This includes system information, threat models, policies, standards like CIS and NIST, or environmental factors. And lastly, E that stands for Expected Output. What should the final product look like? Should it be a table, an executive summary? Should it be in JSON code? Is it a numbered list with explanations? That makes up the RACE framework.
Now, let's bring it to life. Think of your prompt like a cyber security brief. First, it needs to include an input. What are you feeding the AI? Are you giving it a firewall configuration, a CVE, SIEM log entries? Don't make it guess. Tell it what input it is and what to focus on. Then apply the RACE framework, and that starts with roles. You need to assign AI to play a role. So when you say "you are a," the AI shifts modes and aligns in tone, depth, and thinking to match that specific role. Action, what is the job? Do you want it to identify gaps, summarize findings, or translate for executives? Context. What background info does it need to do the job correctly? We want to mention what kind of system or firewall it might be, its purpose, the stakes or policies that it should align with, and the expected output. We want to clearly define the deliverable. Do you want a list, a table, a bulleted summary, or JSON code that you can plug into another tool?
Let's look at two examples to compare. Here is a pretty generic prompt: "Check this firewall configuration and tell me if anything's wrong. List any of your findings in a table." Now, on the surface, that sounds okay, but I want to be honest. It's lazy. It doesn't tell the AI who it is, what the system is for, or what "wrong" even means. This might get you some results, but it's going to require a lot of follow-up to really get what you want here.
On the other hand, when you use the RACE framework, you get much better results with a prompt like this: "You are a senior network security engineer specializing in firewall hardening and secure architecture for enterprise environments. Review the provided firewall settings and identify any security misconfigurations, overly permissive rules, or deviations from best practices. This firewall is deployed at the edge of a corporate network and is responsible for filtering both inbound and outbound traffic. The configuration must align with CIS controls and NIST guidelines. Present your findings in a table with these columns: Rule ID, Concern, Recommended Changes. End with a brief summary explaining the top three risks if these misconfigurations go unaddressed."
Now, do you see the difference in output? That's how you write a prompt. It tells the AI what role to play, what action to take, what context to consider, and what output format to use. And it tells GenAI what "wrong" means: non-compliance with CIS and NIST, overly permissive rules, and so on.
Now, here's why this is so important in cyber security. In most industries, a generic response is inefficient. In cyber security, it can be catastrophic. Imagine if your Gen AI misses an RCE vulnerability because your prompt didn't mention the CVE context. Or worse, what if it flags a false positive and your team wastes time chasing a ghost? When the stakes are high, precision beats creativity. Vague prompts aren't just inefficient, they're irresponsible.
Now, don't worry if this seems like a lot to remember. We're going to cover this all throughout the course, and I've put together a downloadable guide called the "Cyber Security Prompt Engineering Guide" as a quick reference for you. It includes prompt templates, the RACE checklist, output formatting cheat sheet, and examples by use case. You'll find the link below this video or in the course resources section.
So, here's what I want you to take away from this lesson. When it comes to prompts, be specific. Always clarify the task. Add context. System type, use case, security framework. It all matters when it comes to your prompting. Define the output format. Tell it the role, action, context, expected output. This is your formula going forward. Writing better prompts is a cyber security skill. Now, the better your prompt is, the better your intel analysis and decisions.
Now, in the next lesson, we're going to talk about avoiding hallucinations, lazy output, and risky prompts. I'll show you how to spot when Gen AI is making things up, why vague and poor-structured prompts lead to weak results, and how to write precise, safe prompts that get you the insight you actually need. Until then, practice writing prompts using the RACE framework that I showed you. Trust me, this is the fastest way to level up your results with Gen AI. You're not just talking to a chatbot anymore. You're building a force multiplier for your cyber security workflow. So, let's make it work for you. Okay, I'll see you in the next lesson.
What happens when you ask your AI tool for help and it gives you a completely made-up answer, but it sounds confident about that answer? Now, imagine if you acted upon that made-up answer in a live production environment. In cyber security, bad output isn't just annoying. It could lead to breaches, compliance violations, and career-ending mistakes. This is exactly why we need to talk about hallucinations, lazy answers, and dangerous prompting habits.
In this lesson, you'll learn how to prompt more securely, ethically, and intelligently using Gen AI and cyber security. We're going to tackle some of the most misunderstood but mission-critical issues when using tools like Chat GPT. We're going to talk about why hallucinations happen and how to stop them before they start. The "Yes AI" syndrome and how to avoid it with prompt anchoring. Ethical and security-related red flags when prompting. Why your mindset matters as much as your syntax. And how to make the RACE framework your ethical AI compass. And by the end of this lesson, you'll not only be able to avoid these common pitfalls, you'll be able to teach others how to prompt responsibly and effectively in high-stakes cyber environments.
Okay. Now, we know that Gen AI is fast and powerful, but it's also fallible. When used carelessly, it can invent information that looks real but isn't, which is what we call hallucinations. It can echo back bad logic just because you told it to. This is what I call the "Yes AI" syndrome. It can also expose sensitive data like API keys or personally identifiable information if you paste it in. You should know better by now since we covered that in depth in an earlier lesson, but it can happen. And it can cross into gray areas of ethics and legality if you prompt it the wrong way as well. In cyber security, the consequences of trusting the wrong output are far more serious than in any other fields.
So, how do we stay safe, ethical, and accurate? We do it by understanding how these issues happen in the first place. We also understand it by learning how to structure prompts to avoid them. We use the RACE framework, not just for clarity, but for control. And we also reinforce secure and responsible use of Gen AI as your co-pilot, not an all-knowing oracle.
Now, let's break it down. What is a hallucination and how do you prevent them? In Gen AI, a hallucination is when the model gives you an output that looks correct but is completely false, fabricated, or misleading. It can happen when the prompt is too vague or open-ended. It can happen when the model tries to fill in gaps with best guesses. And it can also happen when there's no defined structure or boundaries for the output response.
So, an example of a hallucination prompt is: "What are the default ports for all firewall brands and their attack vectors?" Now, that looks smart, right? But here's the problem. This is asking for specifics across thousands of products, many of which have no documented defaults or known exploits. So, guess what Gen AI is going to do? It doesn't want to disappoint you. So, it's going to give you an answer, which is why I call it the "Yes AI" syndrome. It will get you some ports, and some of those ports will be right, but AI might invent details that sound right but are completely wrong. And it'll do it just to follow through on its instructions.
So, here is how you prevent AI hallucinations. First, be specific about the system or product. The more specific, the better. Include very clear context. Ask for references when possible. And also use structure to limit creative guesswork. So a better prompt example
Using the RACE framework is something like this. You are a network security analyst evaluating firewall configurations for Palo Alto appliances in an enterprise DMZ. Based on the current configuration provided, identify any ports that are unnecessarily exposed. Use NIST 800-41 and Palo Alto's latest hardening guide for reference. Present findings in a table: Port, purpose, risk, recommended action.
With a prompt like this, Gen AI is no longer guessing. It's now anchored in specifics. This leaves it very little room to hallucinate. Does that make sense? The more specific, the better, and that's why we rely on the RACE framework.
Now, let's talk about the "Yes AI" syndrome, or why AI agrees with bad logic. If your prompt includes faulty assumptions or incorrect statements, Gen AI may accept them as true unless told otherwise. It aims to be helpful, not confrontational. Here is an example of a prompt that leaves room for the "Yes AI" syndrome: "Explain why it's safe to leave port 23 open in a corporate environment." If you don't anchor it with a role or context, Gen AI might give you reasons why it could be safe, even though we both know it's a terrible practice to have Telnet open.
So, how do we fix this? We use prompt anchoring. We give Gen AI a clear and specific starting context to guide the response in a focused and reliable way. So, here's an example using the RACE framework: "You are a cyber security consultant performing a network audit for a Fortune 500 client. Analyze whether allowing port 23 (Telnet) on public-facing systems aligns with secure configuration best practices. Consider risk exposure, encryption standards, and modern alternatives. Provide your analysis in a risk table and conclude with a recommendation." Do you see? Now, the AI has no choice but to approach it from a security-first lens. Pretty cool, right?
Now, let's talk about risky and unethical prompts. Sometimes the danger isn't about being vague, it's about being irresponsible. Examples of risky prompts are things like, "Show me how to bypass MFA in Office 365," or "Generate a phishing email template that looks real," or "Simulate a malware payload in Python." Even if you're a red teamer or you're doing this in a lab, Gen AI doesn't know that. And what's even worse is you're now teaching the model these behaviors in your interaction history. So the ethical line here is clear: Don't simulate or ask for exploits, bypasses, or real-world attacks using Gen AI. Keep that work inside approved tools and frameworks like Metasploit, Cobalt Strike, and your sandboxed lab. If you're doing red team work, focus your prompt on education and analysis.
So, here's a much safer prompt to use: "You're a red team operator preparing a risk report for executives. Summarize the most common techniques used in credential phishing campaigns and suggest three detection strategies SOC teams should implement. Use MITRE ATT&CK references."
And again, I want to drive home the point that you need to protect sensitive data by practicing good prompt hygiene. Never paste real credentials, API keys, encryption secrets, or PII into your prompts, ever. Even if the session seems private, your inputs can be stored, logged, or retrieved depending on the AI platform settings. Also, avoid pasting internal company documentation, proprietary configuration files without redactions, and sensitive intelligence like customer data or breach details. Do not paste these into Gen AI for any reason. Instead, sanitize or redact what's sensitive. Use representative examples like I showed you in the previous lessons, or use a localized LLM or a self-hosted Gen AI model when working with real data.
Okay. Now, to drive this lesson home, remember that Gen AI is not your boss. It is your assistant. That means that every piece of output should be verified, validated, and filtered through your expertise. Gen AI can suggest, but you decide. It can summarize, but you verify. It can draft, but you verify. When you treat Gen AI as a co-pilot, not an authority, you can reduce risk. And by using the RACE framework, you can avoid hallucinations, lazy output, and risky prompts.
Remember:
* **Role:** Define who the AI is (like a SOC analyst, a security auditor, and so on).
* **Action:** What task is being performed? Are you asking it to analyze, summarize, or evaluate?
* **Context:** What background does it need? Does it need a threat model? Does it need an asset type? Or does it need a specific framework?
* **Expected Output:** What form should the result take? Should it be in a document, a table, a summary, or a PDF brief?
And by embedding structure and specificity, you can eliminate confusion, reduce hallucinations, and keep your prompts ethical and precise. To make this easier to remember, I've included all of this in the Cyber Security Prompt Engineering Guide. It covers red flags to watch for in prompts, the do's and don'ts for cyber security use, a checklist for secure ethical prompting, prompt templates for safer AI use, and I've also included the link here below this video or it's in the course resources. Whenever you're in doubt, use this guide as your prompting firewall before things go sideways.
So, let's lock in what to take away from this lesson. Hallucinations are caused by vague prompts, and structure will destroy that. Yes AI syndrome is caused by unanchored logic, so we want to use roles and context like the RACE framework to fix that. Risky prompts create red flags, and we want to avoid any offensive or unethical asks of Gen AI. We never want to paste sensitive data into Gen AI. We want to treat prompts like public code. The mindset matters. Gen AI is your co-pilot, not your compliance shield. And we want to use the RACE framework to create safe, structured, and secure prompts. The more powerful the tool, the more carefully we need to wield it. Prompting isn't just about asking the right question. It's about protecting the systems, data, and the people that depend on you to get it right.
In the next lesson, we're going to talk about saving time with reusable prompts and chained workflows, and we'll look at how to speed up your workflow without sacrificing clarity or control. And I'll see you in the next lesson.
Have you ever felt like you're typing the same prompt over and over again? Like you're copying logs, pasting configs, and tweaking the same task slightly just to make it work for different teammates or tools? Well, what if I told you that you could create it once and reuse it forever? That's the power of reusable prompts and chained workflows. And in cyber security, where speed, precision, and repeatability matters, this isn't just helpful, it's critical. That's why in this lesson, we're going to take your prompting skills to the next level.
So far, you've learned how to write better prompts and avoid risky ones. And this is great. Now, I'm going to show you how to save time, reduce friction, and scale your impact by using reusable prompt templates, and chaining workflows together for complex multi-step tasks. Here's what we're diving into in this lesson: You're going to learn how to create modular, reusable prompts using placeholders. You'll learn how to build powerful chained workflows to automate multi-step cyber security tasks, how to store, organize, and retrieve your best prompts, and how to use the RACE framework for each step in the chain to keep your structure strong. By the end of this lesson, you'll have a system that lets you drop in any log, CVE, or configuration and instantly generate useful, tailored, actionable output without starting from scratch every single time. Sound good?
Now, here is the challenge. Most cyber security work is repetitive, but it's all high stakes as well. We analyze logs, we scan configurations, we pull indicators of compromise, we write reports, and so much more. But often times when we prompt with Gen AI models, we start from zero. No prompt memory, no workflow chaining, no reusability, and that just wastes time. It increases inconsistency, and it often leads to errors as well. And worse, without chaining, we can limit what Gen AI can actually do for us.
So, let's fix that by making your prompts reusable and modular. I want you to think of a good prompt like a well-tuned script or a bash function. If it works, we don't throw it away, we reuse it, right? And here's how we can do that in cyber security. We can use placeholders to create flexible prompt templates, things like "insert log data here," or "insert CVE," or "target system," or "audience," or "compliance framework." Now, instead of writing 20 different prompts for 20 different scenarios, you write one great prompt and just swap the input.
So, here's an example of how to do this. Let's say that you're a SOC analyst. So, your prompt would be something like this: "You are a Tier 2 SOC analyst. Please analyze the following logs: [insert log data]. Please identify any indicators of compromise, known suspicious patterns, and align your findings with MITRE ATT&CK tactics. Make your output in the following table format: Timestamp, Event, IOC, Attack Technique, Severity, Recommendation, and end with a short summary prioritized by risk level." And there you go. Now, this is a reusable asset that you can use whenever you want to. And all you need to do is replace "[insert log data]" and you're ready to go.
Now, the next step is to store and manage prompts like this. Gen AI pros don't just wing it. They save and store what works. This is exactly why I showed you how to build a prompt library in the first section of this course. If you recall, I showed you how to use GitHub, Notion, Google Docs, and other tools for building and storing your prompts for speed and efficiency. And because all of your prompts are saved, you can now build out a chained workflow. So instead of cramming everything into one mega prompt, what I like to do is break the workflow into clear sequential steps. This ensures that you get clear, focused output and prevents any hallucinations, oversights, or lazy outputs. It's very similar to a SOC runbook or even an incident response playbook. You run through your prompts step by step to make sure you get the desired output.
For example, here's a classic four-step chain prompt workflow:
* **Step 1:** Log analysis. We feed in raw, sanitized, or redacted logs and parse events and IoCs.
* **Step 2:** Extract any indicators. From parsed logs, we can pull out IP addresses, hashes, domains, usernames, and more. Some might be placeholders from the sanitization process or it might be contained in the logs.
* **Step 3:** Generate a summary. We'd turn any finding into a security summary report that we can use to determine any next steps.
* **Step 4:** Draft up and communicate. We tailor the summary into a report, an email, or a presentation for engineers or executives.
Now, the flow might be different in your organization, but these are just the general steps, and for each step, we would use the output of the previous step as input. So we run a prompt, take that output, and use that data for our next prompt. That's how we create the chain. Does that make sense? If not, stay with me because I'm going to show you exactly how to do this.
Now, here is what makes chain workflows so powerful. You can use the same data but you can adjust the tone, the depth, and language based on the audience, and we can do that with the RACE framework. That means a detailed technical breakdown can be from a SOC analyst. Then we can perform a configuration recommendation checklist for a network engineer, and then we can generate a risk-level summary and business impact overview for our CISO. And you can do all of that from the same base prompt. You just need to tweak the role and the expected output, and you will get the result.
Okay, now I know that might seem like a lot. So let's walk through it, and I'll show you a simplified chain workflow. Step one is that we need the initial input for parsing the logs. So we get the raw logs, we sanitize or redact any sensitive information, then input it into ChatGPT or another Gen AI tool. In this case, we're going to use the simulated artifact that I've provided in the course, which is going to be from the Palo Alto Cortex XDR. And then in that case, we're going to use the following prompt: "You are a Tier 1 SOC analyst. Analyze the following Palo Alto Cortex XDR alert logs." And in this case, I've attached it. So, I'm telling it that the log data is present. "Please identify any concerns, anomalies, or suspicious activity in the logs. Please provide your output as a table with Timestamp, Event ID, Description, and Risk Level." Also, one thing I want to point out is that you can also tell Gen AI to "see attached," and in that case, it will look for the attachment. And now I'll execute the prompt. And you can see that it's analyzing. And in just a few seconds, it'll start generating some results. There you go. So now it's got the timestamp, the event ID, description, and risk level. So you can see here that we have a PowerShell concern that's a high risk. We have an explorer.exe concern that's low. And then we have a zoom.exe that's medium. So right now, the obfuscated PowerShell command is what is of concern. So we need to chase that down. And as you can see, it tied it to MITRE. So we need to chase that down a little bit.
So the next step is to extract any indicators. Once you have the analysis output like you see here, we can switch roles from a SOC analyst to a threat analyst to look deeper into the findings. So in that case, I'll go ahead and paste this prompt from my prompt library. And it goes like this: "You are a cyber threat intel analyst. In the above log table in the previous chat, please extract any relevant IoCs (IP, domain, hash) and note any that match known threats and use MITRE ATT&CK tags where applicable. Please provide your output as a table with Timestamp, Event ID, Description, MITRE ATT&CK Tags, and Risk Level." So, I'll go ahead and execute that, and in a few seconds, we'll get some results, and then we can move forward.
And as a part of the analysis, you see here that ChatGPT says, "It seems like I can't do more advanced data analysis right now. Please try again later." This can happen from time to time with Gen AI tools. This is why I prefer to run one prompt at a time so that I can get the outputs that I want. So in this case, all you're going to do is click this edit message and then resend it. And it could be a network issue. It could be a server issue on their end. It's really hard to say, but sometimes you might run into this. And as you can see, it's still struggling to run that advanced research. But here's a question to take note of: "Would you like me to do that?" So, what it's asking me to do is, "I can help you manually identify potential indicators of compromise and MITRE ATT&CK mappings from the earlier table using the visible data. Would you like me to do that?" And I would say, "Yes, please." And we'll execute that. And then it will go ahead and go through it again. And so now it's going to give you the findings and some of the commentary that goes with the findings. And as you can see here, here's some findings and commentary where it found a specific IP address that we need to take a look at. It's related to the PowerShell finding that we have from earlier. And there's also something tied to the Zoom usage, which you can see is a 1985.100.10 address.
So in that case, the next step is to generate a summary report. And for that, we're going to switch roles again. And so I'll copy a prompt out of my library. And we'll use this prompt right here: "You are a blue team lead writing a threat detection report based on the above IoC analysis. Using the IoCs and log summary, please create a summary report for each of the findings for our internal records. Start with an analysis overview. Then highlight each finding one by one and identify any key behaviors, entry points, risk levels, and recommended fix actions based on industry best practices. Please provide a reference to each industry reference as well." So, go ahead and execute that. And look how fast it responded. And now you can see that it's generating an actual report for us. And you can see the analysis overview. You can see that there's finding one where it's an obfuscated PowerShell execution with external connection, and you can see this timestamp, the event, J Roberts is the offender, you have the device name, the actual executable file name, the IP address that it came from, the risk, and the MITRE tag. So everything we asked for is right here, and that's why we use the RACE framework to build solid prompts so we can get a solid output. And as you can see, there's the rest of the report, more findings, and whatnot. Now, depending on how you run this prompt, you may get a different output. You may get a different format. It may be in a different structure, but for the most part, you're going to see the same data. Okay? Some might have emojis, some might be formatted in markdown, and other things, but you will still get the same data. Okay?
Now, the last step is for us to prepare to send this report to any stakeholders. So, we'll switch roles from a blue team lead to a security manager to provide more of a leadership structure and tone. So, again, I'll copy the prompt from my prompt library and I'll go with this prompt: "You are a security manager updating the organization about the above threat analysis based on the summary report you generated earlier. Please create an internal email communication to notify system administrators of the risk and the required action steps. Please keep your communications clear, non-alarming, and action-oriented. Also, ask the reader to reference the attached report." And so, I'll go ahead and run that prompt. And as you can see, it quickly generates the result. And here is your communication. You have a subject line, to, from, the date, the attachment, and everything. And you can see it's a very simple email that gives you a quick summary, a summary of the findings in a bullet list, and the required actions where we want to isolate that device, review recent activity, correlate this activity with any other logs, ensure antivirus and endpoint detection systems are up to date, and verify Zoom meeting activity. Now again, we want to validate all of this information before we act on it. But now we have all of our artifacts if our validation is correct. And just like that, you have built a chained workflow that can handle real incident analysis from raw logs to internal communications using AI prompts alone. And you also saw some errors that can happen along the way and how to possibly handle those. Pretty cool, right?
Now that we've gone through all of this, here's what to take away from this lesson:
* Reusable prompts save time, so use placeholders to make them modular.
* Store your best prompts in a system that works for you so you can quickly access them. Whether it's GitHub, Notion, Google Docs, and more. You saw how fast I moved from my library to ChatGPT and dropped my prompt in and executed, and how fast we got results. And that's why that prompt library is so effective.
* Also, the RACE framework works for each step. Structure matters at every level. Just like I showed you in the different prompts, we can change roles, we can change context, and more.
* Role-based outputs ensure communication lands correctly with every single audience.
* And lastly, prompt once and use forever. Build your playbook one block at a time.
In cyber security, time is pressure in some cases. When a threat hits, every second counts. So, reusable prompts and chain workflows let you respond faster, communicate clearer, and help you think smarter.
In the next lesson, we're going to focus on how to tune AI when you get bad responses or outputs. Until then, keep building your prompt toolkit. Try out your first chain workflow like I showed you here and start saving hours where it matters most. And I'll see you in the next lesson.
Have you ever read an AI-generated security policy and thought, "Wait, this could get us sued"? Or worse, used an AI-written CVE summary in a report only to realize that it had key details completely wrong? That's exactly why this lesson is so critical. In this lesson, we're going to zero in on one of the most essential Gen AI skills every cyber security pro must have, and that's fixing bad responses fast. You'll learn how to take a piece of AI-generated content like a firewall remediation plan or an executive briefing and course-correct it like a pro without starting over from scratch. We're going to cover a full workflow from diagnosing why the output went sideways to tuning it step by step to building a toolbox of reusable prompt modifiers that make you faster and more precise every single time.
Now, here's the uncomfortable truth. Gen AI gets things wrong, and it gets things wrong often. That's why it's called artificial intelligence, not actual intelligence. It can be vague. It can be misleading. It can certainly be overconfident, and it can be dangerously incorrect, especially in cyber security where precision and context are everything. And if you accept these flaws at face value, you're going to introduce technical, reputational, and even legal risk. Imagine authorizing a firewall rule change because Gen AI seemed pretty sure about it, or just copy-pasting a security policy that subtly contradicts regulatory requirements. The biggest danger here is thinking that Gen AI is right just because it sounds confident. That's why you need to stop being a passive prompt user and start acting like a Gen AI operator. Someone who is actively managing, guiding, and refining the outputs that you get.
So, let me show you how to do that step by step. And we're going to use a real-world example to make this hands-on and actionable for you. So, let's say you're in ChatGPT and you ask it to write a summary of CVE 2024-12345 for an executive audience, and you hit enter. And all of a sudden, ChatGPT is going to go ahead and start generating some content. "A new cyber security vulnerability has been identified," and so on and so forth. "Here's your risk to the organization," down here. And then, "Here are your recommended actions." Okay, cool. That sounds great, but as you can see, it's a little vague and it's not very technical either. So, what we want to do is fix this.
So, first, we're going to audit the output. We want to start with a critical evaluation of it, and we want to use what I call the FACT-R framework.
* **Factual Accuracy:** Are the technical details correct? Does it match the NVD or vendor disclosure? So, in that case, we need to go over to MITRE CVE and see if it matches. So, what I'm going to do is I'm going to go and I'm going to look: Is there a CVE 2024-123345? And it looks like there is. And you can see that right here. So, I'm going to click on that. And you can see right here that this is the title of the CVE. So, when we go back to ChatGPT, you can see here that there's no mention of that title at all. So, we have no way of knowing if this is legitimate output from ChatGPT or if it's hallucinating.
* **Alignment:** Does it match your intended audience (the C-suite, SOC analyst, or compliance)? In this case, it obviously doesn't.
* **Clarity:** Is the language plain, readable, and logically organized? In this case, it's okay, but we could probably make it better.
* **Tone and Format:** Is the output professional? Does it follow your reporting or communication standards? Probably not.
* **Risk Lens:** Does the output downplay or exaggerate the security risk? And in this case, we're not really sure because we're not sure if this is an actual CVE that ChatGPT found from MITRE.
So, just by using the FACT-R framework, we can see that there's a lot wrong with this particular output.
So, the next step is to diagnose the prompt failure. Now, go back to the original prompt and ask yourself, why did Gen AI get this wrong? In most cases, it's one or more things:
1. **Lack of Context:** We didn't use the RACE framework, so we didn't include any links. We didn't give it any specificity, so it just kind of made some assumptions.
2. **Undefined Role:** We also did not define the role. We didn't tell Gen AI who the audience is: "You are a cyber security advisor briefing executives or SOC analysts."
3. **Vague and Open-Ended:** And it was way too vague and open-ended. We didn't really ask for a specific output like a non-technical business impact analysis.
So, here's how you might reframe that prompt and get a way better result. So, I go back to my ChatGPT window and I input this prompt: "You are a cyber security advisor briefing senior executives. Summarize CVE 2024-12345 in plain language. Focus on what the vulnerability is, which system it affects, potential business impact, and urgency for action. Use information from cve.mitre.org." And so then I'll go ahead and execute that.
So, now once I run this prompt, it should be going directly to MITRE now to collect this information. And you can see here, just by specifying to go to MITRE and look for the information, you can see this GBO.ASPX. Then when we go over to MITRE, you can see clearly right here that GBO.ASPX is directly coming from MITRE. So, we can basically trust this output to an extent. Okay. So, now we can dig a little further and we can see some other data that we recognize from the CVE. So, we can start to trust this a little bit more, certainly than our previous prompt.
Now, let's say you're happy with the results, but maybe you don't like the wording or the language or a certain sentence. Here, this is where you can start tuning the output even more to get actionable information. For example, you can add a prompt like this: "Please simplify the language so that even a beginner will understand this." And when you execute it, ChatGPT will now summarize this into very easy-to-understand terms. And just like that, you have an output that's very easy to understand: "A newly discovered software flaw affects a tool used in some business systems. It allows someone on the inside of the network to overload part of the system by entering specially crafted data." So, this is definitely a concern.
I can also go to my prompt library and grab a prompt like this: "Please add a summary paragraph that answers, 'Why should a CISO care about this?'" And when I execute that, it'll recreate everything we just talked about and it will add, "Why should a CISO care? While this vulnerability doesn't enable data theft or remote hacking, it poses real operational risk. If exploited, it can take internal tools offline and disrupt team workflows." So, this is obviously a concern for us.
So, the key here is that we're using iterative loops. We're tuning one aspect at a time. We're looking for clarity, accuracy, and structure. And each pass through should get you closer to the ideal output that you're looking for. And again, as you see here, I'm not restarting the prompt from scratch. I'm steering it in the right direction.
Now, there is a secret weapon that most people overlook, and that's reverse prompt engineering. In this case, you can ask AI something like this: "What assumptions did you make when writing this?" And it will tell you what it was thinking when it created the output that it gave you. You can also ask it, "What parts of the CVE entry did you rely on?" or "Why did you say this vulnerability allows whatever it allows?" And sometimes when you see the model's thinking, you can often spot hallucinations, outdated data or references, or misunderstood context. And it's like shining a flashlight on all of its blind spots. Then you can correct the assumptions and refine even further.
Now, something else to add to your prompt library are tuning modifiers and prompts like you saw here. Over time, you're going to notice that you're often making the same corrections, and that's where your prompt library comes in. Build a set of reusable prompt modifiers like tone modifiers. For example, you can change the tone to "formal executive briefing," or you can make it "plain and friendly for end users." You can also add structure modifiers like "begin with an executive summary," "follow with bullet point risks," and "end with next steps." You can also talk about format modifiers, "return the response as a one-page memo," or "use markdown format with headers and bullet points." So, think of these like Lego bricks. You can stack and combine them to shape your output with speed and precision. And when you put this into action, you can get laser-focused results from Gen AI. For example, you can use this tuning process in daily security workflows like CVE summaries, firewall remediation plans, security policy creation, and executive briefings.
And before we wrap up this lesson, I want to mention ethical and operational guidance when it comes to tuning outputs. And there are two golden rules:
1. Never prompt Gen AI to invent or justify any risky behavior. Don't ask it to bypass controls or write fake reports. This undermines trust and can violate laws, compliance, and internal ethics policies.
2. You are still the human in the loop. No matter how good the output looks, you are still responsible for checking accuracy, compliance, and risk. Remember, Gen AI augments you, not the other way around. You are the authority. Gen AI is not.
This is the real mindset shift for casual Gen AI users. You're not a person who asks ChatGPT stuff. You're now a Gen AI operator. You understand prompt structure, error diagnosis, and output tuning. And you don't accept "close enough." You work with the machine to get it right.
Okay. Now, here is what I want you to take away from this lesson:
* Tuning Gen AI is a critical skill in cyber security, and bad outputs create real risk.
* You learned a full step-by-step tuning workflow from audit, diagnosis, iteration, reverse prompting, and building tools.
* Real-world use cases showed how this plays out in CVEs, firewall changes, policies, and more.
* And you are ethically and operationally responsible for the output always.
* And your job is to actively guide AI, not to blindly trust it.
Tuning is where the real power lies. It's the difference between getting a generic draft and producing something that saves your team hours, improves clarity, and earns trust from leadership. You now have the skills to fix bad responses fast, and more importantly, to get amazing ones on demand. So, let's keep that momentum rolling into the next lesson, and I'll see you there.
Ever wish you could just hand off a complex cyber task to Gen AI and get back something sharp, specific, and actually useful? Well, now you can. If you know how to ask it the right way, you can get the right results. And in this section recap, we're going to lock in the skill that transforms Gen AI from a chatbot into a cyber security assistant that you can trust. And that is called prompt engineering.
In this section, you learned how to structure your prompts using the RACE framework, avoid lazy or dangerous outputs, chain complex workflows, and tune AI responses like a pro. In this lesson, we're going to do three specific things: We're going to cement your understanding of the RACE framework with examples. We're going to walk through a hands-on simulation using everything you've learned here. And we're going to set you up for the next section where we will apply these skills to vulnerability management and risk prioritization.
Okay. Now, think back to the last time you saw a vague Gen AI answer, one that looked polished but completely missed the mark. When it comes to cyber security, that is very risky. Poor prompts can lead to a hallucinated attack vector, false positives in alert triage, or policies that don't comply with your frameworks. You've seen how generic prompts like "analyze this CVE and give me a summary" end up wasting more time or, worse, it creates misleading recommendations. But when you use structured, role-driven prompts, you guide Gen AI. You own the output.
So let's lock in the key tools you now have at your fingertips, which is the RACE framework: Role, Action, Context, and Expected Output. This turns vague prompts into laser-focused instructions. Prompt anchoring. You've learned how to stop "Yes AI" syndrome by rooting prompts in specific roles and standards like NIST, CIS, and MITRE. Reusable prompts and chained workflows. You've seen how to build prompts with placeholders and stack them into multi-step processes. And output tuning. You now know how to audit, revise, and steer flawed responses using tools like the FACT-R framework and reverse prompting. So, you're no longer experimenting, you're building.
Right now, let's bring all this together in a hands-on, realistic simulation. Let's say that you're handed a new CVE: that's CVE 2025-7657, which affects Google Chrome. And this is the primary web browser used all throughout your organization. And your CISO needs a technical breakdown for your SOC team, a high-level summary for your executive team, and a recommendation email for your IT team or IT Ops. So here's how to prompt with precision using the RACE framework step by step.
First, let's create the technical breakdown for your SOC team with this prompt. So I'm going to go over to my prompt library and I'm going to copy this prompt: "You are a Tier 2 SOC analyst. Analyze CVE 2025-7657, a vulnerability in Google Chrome. Your goal is to summarize the CVE's attack vector, affected configurations, potential lateral movement risks, and any observable IoC patterns. Reference MITRE ATT&CK and NIST guidelines where applicable. Present your analysis in a structured table: Attack Vector, Vulnerable Config, Impact, Detection Opportunity, and MITRE Mapping." So I'll go ahead and fire that off, and you can see that it's searching. And now you have some output. So what it's showing is that this is a use-after-free vulnerability in Chrome's WebRTC component. So the attack vector is remote. The vulnerable config is obviously going to be Chrome. The impact can lead to arbitrary code execution, and so on. And you can see that it's clearly mapped to the MITRE ATT&CK framework with the ID numbers. Pretty awesome. Here's some NIST and remediation notes, some lateral movement risk like we asked for, and some indicators of compromise and some recommended actions as well. And look how fast Gen AI did that and how good that looks. It's pretty awesome.
Right now, let's create a high-level summary for the executive team with this prompt. So, I'll go back to my prompt library and I'll copy this one: "You are a cyber security advisor preparing an executive brief for C-suite stakeholders. Summarize CVE 2025-7657 in clear, non-technical language focused on potential business impact, likelihood of exploitation, and the urgency of mitigation. Use a plain tone and structure your response in three short paragraphs: What it is, Why it matters, and What action is being taken. Reference industry alerts from CISA or NIST if available." So, we send that off. Might take a few seconds, but here you go. "What it is," and now it explains what the security flaw in Google Chrome is. "Why it matters." This vulnerability puts businesses at risk of targeted attacks, data theft, and system compromise. And then, "What action is being taken." Google has released an emergency update that fixes the issue. And CISA, sometimes called SISA, has included this vulnerability in its public alerts. Look how different the language is versus the previous prompt because now you know how to properly ask it. So, Gen AI knows how to create executive-level results in a matter of seconds.
And lastly, let's create a recommendation email for your IT or IT Ops team with this prompt. So, I'll go to my prompt library and I'll copy this prompt: "You are a cyber security lead drafting an internal email for the IT operations team based on CVE 2025-7657. Write a notification instructing the patching of all affected servers and workstations. Use concise language. List the remediation steps and clearly identify the impacted assets. Include a link to the CVE advisory and remind the team of the internal deadline for remediation. Keep the tone professional, action-oriented, and non-alarming." So, we'll send that off. In a matter of seconds, we're going to get our email. Pretty awesome. So here's your introduction, remediation steps: Verify the version, update Chrome to this version, restart Chrome, confirm completion. And here are your impacted assets: Windows, Mac OS, Linux, and then admin or shared-use servers with Chrome presence are impacted as well. Here's the deadline and the CVE advisory. It even asks them to prioritize this task and report anything to security ops immediately.
And something else you can add to this is you can audit Gen AI's response by asking this. So I'll go to my prompt library and copy this: "Explain how you derived the risk level and impact for this CVE. What sources or assumptions were used to prioritize this critical issue?" And it might take it a few seconds, but it'll come back with this. And so now you can see that it's justifying why it came up with the response that it did. It talks about the vulnerability officially acknowledged by Google. Google assigned it a high severity, and CISA or CISA issued an alert placing it on the KEV, the Known Exploited Vulnerabilities catalog, and the NIST Vulnerability Database (NVD) currently mirrors the same thing. So here's some derivation where you have the likelihood and impact, and it talks about exploitation, no user interaction, the impact, and so on. And it even talks about the framework and some assumptions and a conclusion as to why it prioritized it as critical: There's active exploitation, low barrier to trigger, high value impact on business assets, and broad attack surface. So that's pretty amazing, isn't it?
So, here are your big wins from this section:
* You've mastered the RACE framework to write role-driven, high-clarity prompts that deliver real results.
* You can now prevent hallucinations and the "Yes AI" syndrome by anchoring your prompts in reality.
* You've built reusable prompts and chained workflows to reduce workload and increase consistency.
* You now know how to audit and tune outputs so that even when Gen AI gets it wrong, you can fix it without having to start over.
* And you are now an operator, not just a user. You guide Gen AI and you own the results.
And now that you're armed with real prompt power, it's time to put it to work. In the next section, you're going to learn how to break down CVEs for different roles, how to map vulnerabilities to MITRE ATT&CK, how to prioritize remediation based on risk and not just severity, and also to generate audit-ready documentation from AI outputs. This is where prompt engineering becomes your secret weapon in threat management and operational defense. And now that you've built the foundation, let's start using it to drive real-world impact. And I'll see you in the next lesson.
Have you ever stared at a CVE description and thought, "Okay, great. But what does that actually mean?" If you have, you're not alone. Most cyber security pros, even sharp security analysts, see a scary-looking CVE, glance at the CVE score, and jump straight to the severity. But here's the problem with that: The number doesn't tell the full story. If you can't explain what a CVE actually does, then you can't prioritize it, defend against it, or even communicate it effectively. And in today's fast-paced threat landscape, that's a serious gap.
But here's the good news. Gen AI can break CVEs down into plain human language, and it can do it fast. There's no more decoding cryptic vectors or waiting through dense technical jargon. So, in this lesson, you're going to learn exactly how to do that. This lesson is all about breaking down CVEs, or Common Vulnerabilities and Exposures, into plain language using Gen AI. You'll learn why understanding CVEs matters beyond the score, how CVEs are structured and where Gen AI can help, how to prompt Gen AI to translate CVEs for different audiences, how to turn CVEs into easy-to-read tables, and how to avoid common pitfalls when using Gen AI for vulnerability analysis.
Now, this isn't just theory. These are hands-on tactics that you can use right now to improve your threat triage, communicate risks clearly, and take smarter action in your cyber security workflows. But here's the challenge: CVEs are often written for machines or deep technical engineers. They're not really written for human analysts trying to make fast or smart decisions. Let's say you pull in a fresh CVE from one of your feeds and you see this: CVE 2025-6170, which is a stack buffer overflow in XMLint interactive shell command handling. That's it. There's no context. There's no clear explanation of what the attack looks like, how it happens, or what the real-world impact might be. And even worse, when you try to explain this to compliance leadership or even your patching team, you're met with blank stares or overloaded inboxes with more and more questions.
So, here's the truth: If we can't communicate vulnerabilities clearly and quickly, then we can't take action. And that's where risk multiplies. So, let's fix that. We'll break this down into five clear steps you can follow to become a CVE decoding machine using Gen AI as your assistant.
First, let's break down the format of a CVE. Everyone follows the same naming structure. You'll see the CVE here at the top, which stands for Common Vulnerabilities and Exposures. You'll see the year, in this case, it's 2025. And then you'll see the unique identifier, which is 6170. Pretty simple, right?
Now, let's look at what type of data typically comes with a CVE entry, especially when it's from MITRE or the NVD, the National Vulnerability Database.
* **Description:** You'll see the description, and as you notice, it's pretty vague. It'll just tell you what the vulnerability is, and that's about it.
* **CVSS Score:** You'll see the CVSS score right down here, and you can see that it's a 2.5, which is low. Low doesn't mean safe. Low just means it's a low severity, but we still need to investigate it and figure out what's going on.
* **Product Status:** You'll also scroll down and it'll talk about the product status, and these are the affected products from the CVE.
* **References:** You'll see references like Red Hat and also Bugzilla, and then obviously they're recognizing somebody who reported this issue.
Now, here's where Gen AI shines. It can easily rewrite this wall of jargon into something humans like you and I can understand. So, let's say you find the CVE and you want a quick, understandable summary. So, I'm going to go over to my prompt library and I'm going to grab this prompt and drop it in right here. And as you can see, it is pretty long. So, I'm not going to read the whole thing, but you can see it here on the screen. And you can also get this from the course resources as well. You can drop this into ChatGPT, Claude, Perplexity, whichever tool you prefer, and then go ahead and run it.
So, as you can see, it starts to parse through it real quick, and you can see the CVE here. One thing to take note of is the CVSS score, which is obviously not correct. We noted from before it was 2.5 low, where ChatGPT is telling us it's an 8.1 high. So, again, this goes all the way back to the discussion on hallucinations. ChatGPT is hallucinating in this case. It thinks it's right. It thinks it's solid, and it's telling you that this is the score when we clearly know that is not the case.
Now, there's a lot of other data here. It talks about what's a stack buffer overflow and what does this vulnerability allow an attacker to do. So, it simplifies a lot of things for us. And again, I'm not going to go through all of that here, but you can see what data we get when we just use a good, effective prompt.
Then, as a follow-up, we can start chaining prompts to get the best results. We can ask Gen AI to pull out key insights like these: the attack method in plain language. So in this case, we can drop that prompt right there where we ask for tools, tactics, and techniques, and then we can go ahead and run that prompt, and as you can see, it will start generating some responses, and it clearly breaks it down, and you can see the IDs right here, which is going to be mapped back to MITRE ATT&CK. So it will show you the initial access, execution, privilege escalation, and more. And you can see persistence and defense evasion, and so much more. And again, I'm not going to go through all of this here, but you can see when you run these prompts, you will get so much good information.
And again, what if we wanted to follow up on detection and monitoring techniques for our SOC team? In that case, we can drop a prompt like this in: "What should a SOC team member monitor for to detect potential exploitations of this CVE?" And then we also ask for logs, behaviors, and more. And that will give us so much more information to parse through and make a good decision. So, as you can see, it's focused on XML in here. The log source is like Sysmon, auditd, or journald for different versions of Linux. There's EDR or XDR tools like CrowdStrike, SentinelOne, and so on. And there's so much more that we can find from this. Look at this summary. And then you have a summary of all the IoCs. It'll give you recommendations for detection rules. And we can go deeper on that with more prompts. There's so much more that we can do here.
Something else important to us might be the impacted systems. So we can also ask ChatGPT what systems are affected, and we can use that prompt right there. And as you can see, the most vulnerable systems are Linux-based developer workstations. Anything running XML is going to be vulnerable.
CI/CD pipelines, scripting environments, and more. And again, it goes through all this detail for you and breaks this all down in simple, easy to understand terms.
Now, let's get down to what we really care about as security professionals. How do we mitigate or remediate any findings from this CVE? And in this case, we're going to ask it to comply with ISO 27,001. And we want technical and long-term hardening strategies. So in this case, I run that prompt. And now you can see that we obviously want to patch affected systems. We want to disable or restrict the use of XML int. We want to monitor for exploitation attempts, audit the system for misuse, and it goes through everything in detail for us. And then some of the long-term hardening strategies is to use lease privilege for development tools. Secure the development and code environment and actually do some code review as well. Implement software allow listing and application control. And then you also have conduct regular vulnerability scans, user awareness training.
Something else I'd like to see in here is maybe something like supply chain. So you can just follow up with a simple question. What about supply chain risk management? Right? Great question. That's very crucial. Why it matters and so on and so forth. Now, it'll start giving us some more information about supply chain and why that's related to this CVE. Pretty awesome, right? And this prompt chain can go on and on. We can ask it about risk context, test and assessment, organizational impacts, training, and more. Anything that you would ask of a human or an administrator or anything, you can ask Gen AI. That's super awesome.
Right now, let's go a level deeper. While the prompt chain is super cool, not everyone in your organization needs the same level of information. And Genai can shape the same CVE details into different outputs depending on who you're talking to. To do this, we can pull from an earlier lesson where we discussed a placeholder for sanitized data. But in this case, we're going to use it to make the prompt universal. So, we only have to grab a single prompt from our prompt library and add the details. So, I'm going to drop the prompt here in the window. And you can see right here that this is the prompt. Let me scroll down a little bit so you can see. And so, you can see that we have placeholders like RO, analysis focus, and target audience. And as you go to the bottom of it, you will see RO equals security analyst, analysis focused equals CVE6170. target audience equals executive leadership. So in this case, all I have to do is change security analyst to security engineer or security officer, security manager, whatever I want that to be. And I can also drop additional CVEEs as an analysis focus. And my target audience could be a sock team, it could be a patch team, it could be executive leadership and more. So now you have a universal prompt that you can just replace these roles and you can create multiple versions of this as well. You can run this prompt as a different role or targeting a different audience each time you run it. Does that make sense?
Now imagine using all of that in a single meeting. You've just become the translator between risk operations and strategy. And that is highly valuable in any organization. It's amazing right now.
One other thing you can do is turn multiple CVEes into structured tables. So what we can do is we can use a prompt like this. Please extract and summarize the following CVEEs into a table with columns. And then you list out the columns that you want to see. And notice that I have CBE 20256170. But I have some other CVEEs that might be related or similar. Maybe it's a similar platform, a similar attack vector, whatever it might be. So, I'm going to couple these in and then I'm going to run this through chat GPT and it's going to grab all of our data for us and then it's going to formulate our response. And as you can see, it starts creating a table that we can now work with. And notice that we have a buffer overflow, a buffer overflow, a buffer overflow, and a buffer overflow. So, these are very related in terms of the vulnerability and the potential exploit that could happen. So now we can couple these together and then we can start working with this data to formulate a plan to address everything, not just one CVE. And as you can see, tables like this cut through the noise and help drive action. Awesome.
Right now, before we wrap up, let's cover the watch outs when using Gen AI with CVEes. First, hallucinations. Sometimes Jin AI will flat out make up things just like it did with the CBSS score that you saw. It might say the vulnerability uses an exploit method or something that doesn't exist or that it affects Windows when it really applies to Linux. Those are known hallucinations and they are dangerous because they sound authoritative. So always cross-check technical claims against trusted sources like the National Vulnerability Database, MITER CVE, Vendor Advisories, or Exploit DB. If you're unsure, add a citation check to your prompt. You can just say include supporting references or a link to the NVD entry. If unknown, say so and then it will go ahead and it will give you the reference.
Also, look out for outdated information. Most base Gen AI models aren't connected to the internet. That means their knowledge of newly released information might lag behind sometimes by months. So, we can always add something to our prompt to say check the latest CVE details on NVD or MITER. and that would help.
Also, look for oversimplification. To sound more readable, Jin AI might smooth out details a little too much. You'll get summaries that feel clean, but they'll skip over some critical details that you need to know, like attack vectors or privilege level requirements. So, be specific in your prompt. Say, include the CVSS score or attack vector or authentication requirements or real world exploitation. You can always ask it exactly what to include like CVSS scores, attack vectors, and more. And you can also tell it don't oversimplify. And that'll make sure that you get all of your technical information. You can also ask it what details might be missed if it was oversimplified. And then it might give you some more technical information as well.
Okay. Now, here's what I want you to take away from what we learned in this lesson. CVEes contain valuable but dense data. Sometimes Gen AI can break it down into plain language for you. Understanding the structure of a CVE will help you craft better prompts. Tailoring your Gen AI output to your audience will help boost clarity and action. You can turn complex CVE feeds into easy to scan tables using Gen AI. And always validate Gen AI outputs to avoid errors, hallucinations, and missing context. Remember, your ability to translate technical risk into human language is one of your most powerful tools in cyber security. And now with Jin AI by your side, that superpower is easier to access than ever before. So the next time a fresh CVE drops into your feed, don't just look at the score, ask what it actually means. Then use Chat GPT, Perplexity, or Claude to help tell the story so you can clearly and confidently understand it. In the next lesson, we'll take this a step further by learning how to prioritize risk based on real context, not just the raw CBSS scores. You're building serious muscle here. So, keep going and I'll see you in the next lesson.
Have you ever looked at a vulnerability report and thought, "There is no way we can patch all of this? Where do we even start with something like this?" Well, I know I have, so I know you're not alone. In fact, this is probably one of the biggest challenges in cyber security today. CVSS scores are everywhere. And while they're useful, they don't tell the whole story. You wouldn't treat a vulnerability on your domain controller the same way you would treat one on a lab test box, even if they both have the same CVS score. And yet, that's exactly what most vulnerability management programs do. That's why in this lesson, we're going to fix that. I'm going to help you understand why CBSS scores alone can't drive smart decisions. How to identify the context factors that truly impact risk. How to prompt Gen AI to analyze and prioritize vulnerabilities based on your actual environment. How to compare static scoring to contextual prioritization and how to avoid common pitfalls when using Gen AI for risk analysis. We're going to break this down in plain language, walk through real world use cases, and show you how to level up your prioritization game using Gen AI. And we're going to do it all step by step.
So, let's start with the problem. Most vulnerability management tools rely on CVSS scores to rank risk. That's a decent start, but it's also dangerously incomplete. CBSS is like one sizefitsnone. That's the scoring system. It tells you how dangerous vulnerabilities could be in theory, but it doesn't tell you what that vulnerability means in your environment. And here's why that matters. Imagine this. You've got two systems. One is a domain controller facing the internet. It supports your authentication infrastructure. The other is a development machine on an isolated subnet that's not even connected to your production environment. They both get hit with the same CVSS score of 9.8. Are you going to patch both of those systems with the same urgency? Of course not. That would be a waste of time and energy. But that's exactly what static CVSS-based prioritization does. And it's how teams end up drowning in patch backlogs and chasing the wrong fires.
Now, let's walk through how to prioritize risk based on real context with help from Gen AI. Now before we can teach Gen AI to prioritize effectively, we need to understand what context actually matters. So think of it like layering reality on top of CBSS. Here are the most important details that you need to add. One is asset sensitivity. Is the vulnerable system holding sensitive data. Is it a domain controller, a payment processor, or a customer-f facing app? The exposure level. Is the system on an internal network? Is it in a screened subnet or DMZ? Is it in a public subnet? The more exposed, the higher the risk. Thread activity is the next one. Is there known exploitation in the wild? Are attackers actively scanning or targeting this CVE? And also patch feasibility. Can we patch this quickly or does it require downtime, testing, or a maintenance window? These are the ingredients that define real risk and they're exactly what we're going to feed into Gen AI.
So, let's take a look at the contextaware prompt to begin with. I'm going to go over to my prompt library and then I'm going to paste this prompt. And again, this is long, so I'm not going to read the whole thing, but again, you can see it here on the screen and you can also reference it in your course materials. So, I'm going to run this and it's going to give us some context on a CVE 20253891. As you can see, it's already starting to generate some results. This is a denial of service CVE. And as you can see, we're going to go down more and more. It looks like Apache is part of it. And there's a lot of other information here. So, this is going to help give us some context. Here's your overall risk rating. It's moderate to high. And then some recommended actions as well. Identify all Apache servers with this specific open ID connect installed and then check if the open ID connect preserve post is enabled. If not, disable it and so on. So it gives us a quick action report which is great.
Now what I'm going to do is I'm going to use another prompt to follow up in the chain to give it some more context and give it some more details. So again, this is a very long prompt, so be sure to reference your course materials. But here's basically what it's doing. Now that you've assessed the CVE in context, I want you to evaluate how this realworld risk compares to standardized CVSS scores. So what we're going to do is we're going to look at what MITER CVE says and what we believe in context related to what we want in our organization. So I'm going to go ahead and run this. And now it's going to say the real world risk is significantly higher than what CVS is indicating. And so now it's going to go down the overall list of all the different factors that it's considering and why it made that decision. As you can see here, there's some evaluation here being done. Context aware of course because that's what we prompted it to do earlier. And we just keep going. And now you'll see a comparison table with CVSS and real world impact. And you can see that CVSS is right here. And then you can see that the exploitability is the same, but everything else is higher in terms of asset exposure, business criticality, compensating controls, and impact amplification. Let me turn that off. Just keep going down and look at some of the other information that chat GPT gave us. And then here's your prioritization recommendations. you're definitely going to want to consider the exploitability. So this is something that's going to go right to the top of our list and we're going to put this as our top priority to go get resolved. So again, now it concludes that the standardized score of 6.0 is a lot lower than what is really present in our environment.
Now that we've guided Genai through the technical analysis and contextual risk assessment, the next step is translating those insights into actual action, specifically into language that decision makers can understand and use. So let's prompt Genai to generate a leadership ready summary that condenses everything here into a concise and role appropriate output. So I'm going to go to my prompt library and I'm going to grab that prompt. You're a cyber security risk analyst preparing a summary for IT leadership and based on your analysis of the CVE, write plain language report that gives us a short explanation, contextual risk, a clear explanation, and recommended next steps. So that's what this prompt's going to give us. As you can see, it's explaining the vulnerability in layman's terms so that a leadership can understand it, how it affects us. This is the most important thing. How is this impacting the organization? Here's the risk and it's telling you right away it's high. Why does this matter? Because this can lead to widespread downtime, loss productivity, and potential impact of customerf facing services. This is all scary stuff when it comes to leadership. Here's your next steps. You want to disable OIDC preserve post. You want to implement a WFT, a web app firewall. You want to apply vendor supplied patches as soon as it becomes available. And then of course, we want to monitor.
Now, why is all of this important? Because risk management isn't just a technical task. It's a communication task. Your ability to summarize threats and risks clearly and confidently is what's going to drive prioritization decisions. And Genai just helped us with this. But it can only do it if you teach it to think like you do. And now that we have, we can provide this summary to leadership so that they can make a risk decision. Once they do, we can create a remediation report with specific recommendations to defend against this CVE. So, I'll go to my prompt library and I will grab a prompt that helps me create a remediation plan. Please create a concise remediation plan based on the current state of the effective system. Start with an executive summary and so on and so forth. So, the idea here is once we give this report to IT leadership and they say yes, go forward with this. Now we have a remediation plan and we can create it. So now it gives us the remediation plan. There's your executive summary, the immediate technical actions that need to be done. Temporarily disable this setting in Apache configuration. And then you can also monitor for an official patch or security update. You can add compensated controls. For example, implementing access restrictions, more monitoring and alerting, implementing a W like we saw earlier. And then here's a step by step. Okay, so there's quite a bit of detail here. In just a matter of a few minutes, we moved straight from a generic CVSS score to a contextual riskbased judgment and a remediation plan to address the CVE. How powerful is that?
Right now, before we wrap up this lesson, here's what I want you to watch out for when using Gen AI for prioritization. First, we never want to assume that AI knows your environment because it doesn't. You have to give it very specific context like we did here. The more specific, the better. That's where the value is going to come from. Also, we never want to let AI override our judgment. AI supports your thinking. It shouldn't replace it. So, if something doesn't feel right, validate it. Ask it. Also, we don't want to ignore any business impact. That's why we do security in the first place, to empower the business. So, just because a CBE sounds scary doesn't mean it's a top priority. Or because a CBE is low doesn't mean it's not a top priority as well. Think about how it affects your systems and your business or the mission.
Now, here is what I'm hoping you took away from this lesson. CVS scores and other risk scores, they are helpful, but they're incomplete without context. Real world prioritization requires understanding asset exposure, sensitivity, threat intelligence, and patch feasibility. Gen AI can reason through this context when given the right prompts. Structured Gen AI outputs help drive faster and smarter decisions. And lastly, clear prompting and validation are essential to avoid any hallucinations or misjudgments. In a fast-paced world where vulnerabilities pop up almost daily and patching every CVE isn't realistic, context is your compass and Jin AI can help be your guide. And the better you can feed it context, the better it helps you prioritize. Now, next up, we're going to take a look at what you've learned here and apply it directly to vulnerability scan results, turning those massive scan dumps into focused, actionable insights. So, keep going. You're building some serious riskmanagement skills here and I want you to keep up the momentum. So I'll see you in the next lesson.
Nessus, InsightVM, Qualas, Green Bone, OpenVas. These are all great vulnerability scanning tools, but have you ever looked at their reports and thought, "How the heck am I supposed to make sense of any of this?" I know, me too. It can feel like drinking from a fire hose. I mean, hundreds, even sometimes thousands of lines of raw data, technical plug-in IDs, CVE numbers, port numbers, XML, JSON, acronyms after acronyms. Some of the report features are good, but still they can be pretty overwhelming, right? And somehow you're expected to turn that into actionable risk insights. That's the bad news. Now for the good news. Genai tools like chat GPT, Claude, and Perplexity are the assistant you've been missing. Because Gen AI doesn't just read fast. It summarizes, organizes, and prioritizes. So you can move from data overload to strategic decisionmaking in minutes, not hours. That's why in this lesson, I'm going to show you how to break down overwhelming scanner outputs into bite-sized AI friendly inputs. I'm going to show you how to prompt Ginai to extract key risks, explain their significance, and suggest next steps. I'll also show you how to structure findings into risk summaries, remediation tables, and actionable priorities. And I'll also show you some common mistakes to avoid when analyzing scan data using Gen AI. So, we're going to walk through real examples, step-by-step prompts, and practical workflows that you can use immediately in a sock, in GRC, or in vulnerability management.
Now, let's start with the real world pain here. You run a scan on your DMZ web servers and maybe you're using Nessus, and the report spits out over 250 findings. Okay, great. Now, what? You open it, and the report is full of plug-in titles like TLS version 1.0 O protocol detection or some CVE or an SMB signing not required vulnerability. There are some severity ratings and a few paragraphs of plug-in outputs. And maybe there's a solution buried deep in the weeds somewhere. So what's your job? Your job is to take all of that noise and figure out what do these findings mean? What's the actual risk to the organization here? What should be fixed first? What is okay to leave for later? So manually parsing through all this data can take you hours, sometimes even days, and even then critical items might get missed through fatigue. This is where Gen AI changes the game.
So let's break this down into a practical Gen AI workflow that helps you analyze vulnerability scans like a pro. First, we want to start smart. We don't want to just drop the entire XML or JSON or RAW scan export into your prompt. That's like tossing someone a technical manual and saying, "Tell me the story." It overwhelms more than it helps. So, step one is for us to feed Gen AI the right information and extract the essentials. For example, we're looking for things like asset info like host names, IP addresses, or even a system role. We're looking for CBE IDs, ports, protocols, services, severity score or labels, and maybe even a plug-in output that has a brief summary of a description or a solution that makes it easier for Gen AI to process and respond accurately. Plus, we want to summarize the report with context. So, let's say you exported a Nessa scan with multiple findings and you drop it into chat GPT and use this prompt. So, what I'm going to do is I'm going to grab the course artifact for the vulnerability scan and I'll drag it in here or you can paste it in here. And then I'm going to use this prompt. You are a senior cyber security analyst. Please review this report. This report covers over 100 systems in a hybrid cloud environment. Identify the top 10 vulnerabilities based on severity, exploitability, and exposure. And then summarize this for us and explain risk in non-technical terms. So, I'm going to go ahead and execute that. And as you can see, it already processed the table. So now it's going through everything. And now here's our output. So it found three findings. One on VPN gateway local, finance DB local, and finance DB local. So we have two assets that are affected with three different vulnerabilities. So it didn't find 10, which means there wasn't 10 present. There's only three vulnerabilities present in that scan. And again, now it found the vulnerabilities where it's an SMB v3 and that's on VPN gateway local. And then we have the database DB stands for database that has a principer issue with remote code execution rce. And then we have the database that has an S channel security bypass. So those are the three things that were found. And so now you have a clean human readable short list of vulnerabilities that actually matter.
Now once we have these vulnerabilities from the initial summary, it's time to dig deeper and really understand what we're dealing with. So step two is to understand the actual risk here. This is where we can use chain prompting to get some pretty good detail. We would ask Genai something like this where I'll go over and I'll paste this prompt for each of the top three vulnerabilities. I'm going to go ahead and delete that part and I'm just going to say for each of these vulnerabilities, please tell me how many systems are affected. Are there known public exploits? What would typically happen if someone exploited this? What's the actual risk here? And is there any recent data showing that this has been exploited? So now what I'm going to do is hit send. And so now it's going to parse through this again. And as you can see, it recreated the table. And now it's going to go ahead and talk about are there known exploits? Yes, there's a proof of concept out there and metas-ploit has something. There's a typical outcome if exploited. actual risk of exploit, active use in the wild, and so on. Okay? Now, I'm not going to take time to go through all of this, but you get the gist, right? It printed all of this out for you in very easy to understand terms, so you can clearly understand, is this a risk or not? And this right here is your biggest indicator. Known exploits. If there is, we have a risk, right? Known exploits, yes. And then on this one, known exploits, yes. So, all three of these are vulnerable to exploit. And then here's a quick summary table that it created for you, which is awesome. This helps you really dial in what's going on. And this makes it really easy to copy and paste into reports, emails, and more.
Now, let's bring in what really matters, and that's your environment. So, step three is to add business context to prioritize even smarter. So, what I'm going to do is I'm going to drop this prompt in. You are an enterprise vulnerability analyst. Here's a list of our most critical systems and the servers they run on. Prioritize the vulnerabilities based on this. If any of the top ones affect these systems, bump them up in risk. So, what I'm going to do is go over to the course artifacts and I'm going to drop in our inventory list that I created for you. And then I'm going to go ahead and run this. And as you can see, it's starting to parse through and analyze all the data. And here we are. And so now it shows that finance DB local VPN gateway local and finance DB local the same server were found in this list. Now we can see the updated top priorities with critical system waiting. So now this pertains specifically to us and now we know that there's an adjusted score because we're elevating this to a critical priority because we do have this system and it is vulnerable. We're vulnerable to the SMB ghost and we're vulnerable to the S channel security bypass. So everything that was found we need to take care of. Pretty awesome, right? Now, this is important because this helps you understand that not all vulnerabilities are equal.
Now, the next step is to spot the patterns that others might miss. So, I'm going to use this prompt to look through the full scan results as a security operations analyst. Do you see any trends or repeated issues? Are there specific operating systems or server templates where the same problems show up? And so now we're going to go ahead and run that. And as you can see, it's having some trouble displaying the visualization. That's totally fine. That doesn't mean that it's not parsing through the data. Just means it can't show the table. So now it's going to go ahead and do an analysis. And now there is no systematic vulnerability repetition that's detected. Despite scanning over 100 systems, no single vulnerability was found across multiple operating systems or templates. So what that means is we have a single instance of an issue that's spread across the environment. Okay. Inconsistent server provisioning, environment specific builds. It goes through all kinds of different things for you to review and take in consideration when considering a risk response. So when you scroll down and you see the recommendations, it's talking about using golden images for all server types. That means you harden and you use a base image and just update that or you do infrastructure as code or something like that. Baseline scanning on new deployments, centralized patch management, run configuration audits and so on. So it gave us some action items which is very good.
So now what we want to do is use Jin AI to help us filter out what doesn't matter. So step five is to cut through the noise. In this case, we're using a very simple example, but if you're dropping hundreds and hundreds and hundreds of hosts in here, these kinds of prompts will be very helpful. So in this case, I'm going to post this prompt. Some of these vulnerabilities might be false positives. Based on the results, which ones should I double check for each? Tell me why it might be inaccurate and how I can confirm it. So now this helps us root out any kind of false positive. Now you can see there might be a false positive on workstation 22. So let's scroll down and see why. There's a plug-in ID. The CVE is not assigned. There's no score. Why this might be inaccurate. There's no CVE identifier. So in our scan results, there was no CVE associated with the finding. So that could be a concern. But if it's a vendor release, then there wouldn't be a CVE finding, right? So that's why we have to double check it. So how to confirm accuracy is we review the plug-in output. So we go back to Nessus, we open the details of that plugin and we see what it is and then we do a cross check manually. So that's when we look into is it a vendor release? Was it a CVE? Maybe the report just didn't catch it. We need to dig a little deeper on that. Again, Genai won't make the final decision for you, but it can give you a list to investigate first and it'll save you a ton of time.
And finally, you'll need to communicate your findings. And that means tailoring your message to different audiences. So step six is to create a report. So what we're going to do is we're going to go to our prompt library and we're going to get this prompt. You are a cyber security communications lead. Create a one-page report for the CIO based on these findings. Keep it non-technical. Focus on the business risk. What's at stake and what we need to do next? And then Jin AI will create this report for you. And here you go. Vulnerability risk summary, executive report, and then you can see a recent vulnerability scan of over 100 systems, so on and so forth. Here's the risks, right? That print nightmare that we saw earlier. That's our highest risk. That's what we want to look at. Then we also want to take a look at the SMB ghost. And then we have some patch gaps and inconsistent configurations. And then some recommended actions with days, like how long that might take us. Pretty amazing, right? And what's at stake here? If left unressed, here's what can be impacted. Operations, regulatory compliance might be impacted and damage to customer reputation. These are all big things that a CIO or a CISO or a CEO would want to know. What is at stake here for us, right? And that's why we put it in this language.
Now, this will address the executive level. For your DevOps or engineering teams, you're going to need to use a prompt like this. Now write a summary for our technical team. Include the effective hosts, CVE IDs, severity levels, and exactly what needs to be patched or reconfigured. And keep it clear and straight to the point. So then I'll run that prompt. And now it will give me a technical summary or a vulnerability remediation summary like you see here. Priority one is to go and take care of the print nightmare. That's what we're going to focus on first. and then even gives you some commands to run. Second, we'll deal with the SMB ghost. And then third will be to deal with the S channel security bypass. And then we did have a false positive with workstation 22. And so we need to go and check that out. Okay, how awesome is that? That's the kind of value we are after when we use prompt chains like this.
Now, before we wrap up, let's talk about a few common mistakes that can trip you up when using Gin AI for vulnerability analysis like this. First, we want to avoid overloading the prompt. If you throw in too much raw data all at once, AI can struggle to process it effectively. It's much better to break things into smaller chunks and guide Jin AI step by step. Second, don't forget to include context. Jin AI doesn't automatically know if a server is public-f facing, missionritical, or part of a dev environment. If you want smart prioritization, you need to feed it that background information. And finally, and this is the most important, don't blindly trust the AI's interpretation of severity. Gen AI tools can make a very educated guess, but they don't know your environment the way you do. So, always cross-ch checkck CVSS scores, validate exploitability, and factor in your own critical assets. Your judgment always takes precedent. Do not blindly trust Gen AI.
So, here's what I'm hoping you took away from this lesson. Vulnerability scan data is dense and overwhelming, but Gen AI can help make sense of it. Extract and feed Gen AI only the essentials: CVE, ports, protocols, services, severity, and so on. Break findings in small, manageable batches for better output. Use environmentaware prompts to improve prioritization. Expect summaries, remediation steps, and optional tables from Gen AI output. And avoid overloading and always verify high-risk findings with trusted sources. Now you are equipped to turn massive vulnerability scan reports into streamlined, prioritized, and actionready intelligence using Gen AI. No more drowning in scan data. No more chasing the wrong patches. Instead, you've got a smarter, faster AI assisted process that helps you focus on what really matters, which is protecting the systems that matter most. Now, next up, we're going to take a step further by learning how to generate action plans and remediation steps with Gen AI, so you can go from knowing what to fix to actually planning it out. So, let's keep up the momentum and keep going. I'll see you in the next lesson.
You've got the scan results from the previous lesson. You've used Genai to identify and prioritize the top risks. You even know which ones hit your crown jewel assets. Now, here comes the hard part. Fixing them. But here's the truth. Discovering vulnerabilities isn't the real challenge anymore. Fixing them is. That's where teams get stuck. So, in this lesson, we're going to turn those vulnerability findings into something useful, which is a clear rosp specific remediation plan. We'll cover how to extend the prompt chain from the vulnerability scan analysis. How to generate step-by-step fixes based on CVEEs and asset context. How to tailor output for different audiences like CIS admins, IT managers, and GRC teams. How to use Gin AI to draft tracking sheets, change tickets, and even downtime notifications. And of course, how to avoid the pitfalls of using Gin AI blindly in real world remediation.
So, let's pick up where we left off in the previous lesson. In the last lesson, you generated that top list of vulnerabilities using Gen AI. And if you remember, there was three in the list. You prioritized based on severity, exposure, and critical asset alignment. We even look for patterns and false positives. But the next question is now what? Because most scan tools don't give you a true remediation. They just plug in blurbs and vague vendor notes. What you really need is a concrete patch plan, a roll back strategy if the patch breaks things, and a way to hand this off to the right team without having to rewrite it five different times. So, let's walk through how to continue the Gen AI prompt chain and produce ROSP specific remediation plans from your existing vulnerability analysis.
So, step one is to build on the vulnerability summary prompt that we used in the last lesson. We used prompts to identify the top vulnerabilities based on severity, exploitability, and exposure. You then followed up with the prompt to find how many systems were affected, whether exploits exist, and the typical impact plus any recent activity in the wild. Then we use Genai to create a summary report for the executive level and your technical team members. So now we have a vulnerability remediation summary which is in the course artifacts. Let's use that as input and continue the prompt chain. So I'm going to drop that report into chat GPT and I'm going to use this prompt using the attach report. Please create a remediation plan for each vulnerability in the list. Assume that this is a Linux and Windows-based environment. Provide patch instructions, config changes, verification steps, roll back plans, and who would be the best role to apply the remediations. So with that said, I'm going to go ahead and send it. And here's a complete vulnerability remediation plan for you in just a matter of seconds. Priority one is of course to tackle the print nightmare. And we talked about that in the previous lesson. There's some verification steps. There's a roll back plan. If something goes wrong, how do we roll it back and get it back to where it was? Then the next step is to tackle the SMB ghost. And it gives you the same exact steps. patch instructions, configuration changes, verification steps, roll back plans, and more. So, as it keeps turnurning through this, it's giving you a very detailed step-by-step plan of what to do. As you can see, again, more configuration changes, patch instructions, verification steps, roll back plans, uninstall if the patch isn't needed, and so on. And again, because this was potentially a false positive, this is not something that needs immediate action. And then there's some remediation guidance. And there you have it. And just like that, Jin AI moves from, hey, what's wrong? To here's exactly how to fix it and who can help fix it. Pretty awesome, right?
Now, the next step, step two, is to tailor the remediations to specific roles. Not everyone needs the same information and that includes administrators. So you should tailor Gen AI's output based on who it's for. And to do that, we'll go to our prompt library and we'll grab this prompt. You are a cyber security operations assistant. Please review the following plan and identify the distinct roles or teams mentioned and create a detailed step-by-step remediation plan. for each identified role, give them step-by-step action plan with only the relevant information that applies to the role. Right? So that's going to specify that. So we'll let that run and based on the remediation plan you've provided, here is the role-based breakdown. So you need a Windows system admin, you need an infrastructure administrator and a network security engineer, a security analyst, DevOps engineer, system architect, security engineer, and IT manager. And so now it's going to tell you exactly what needs to happen and who's going to do what. This is amazing, isn't it? Like how powerful this is. So you can see that it says the action is that you're going to apply this update and it gives you a very specific Windows update. Notify the IT manager and security team when the patching's complete. So you're going to hand this task off to them. And then for the S&P Ghost, you're going to apply this patch. You're going to block TCP port 445 from external sources. Like this is incredible. How long would this take you to do normally? It's amazing. So now you can just keep going and you'll see exactly what each role needs to do in order to remediate this situation. The IT manager needs to track remediation progress against service level agreements right here. And then you get a really fancy summary table that helps you clearly understand what needs to be done in terms of the CVEEs, who needs to do it, what their deadline should be, and then here's their main tools and tasking. And using this one prompt, you get multiple outputs for one vulnerability, and it's all generated in just minutes. It's super cool.
So now that you have the plans and all of the roles, remediations don't just happen. They need to be tracked. They need to be communicated and managed to closure right now. Remember again, Gen AI is not perfect. So, step three is a quick reality check. We want to validate and verify the results. Genai might suggest restarting services that can't be restarted during business hours or patches that aren't yet tested in your staging environment or even fixes that skip important dependencies. So, we always want to follow up with a prompt like this. Double check this remediation plan against specific vendor recommendations, best practices, and advisories. Flag anything that may be environment specific or present a risk to the operational environment. And so we'll fire that off. And just in a few seconds, it's going to go ahead and tell us. And so now if we go down a little bit, the specific risks to the environment are things like disabling the print spooler. What does that do? Well, it breaks print to PDF functionality and it also disrupts application services that generate or route printed reports. Okay, is that a huge impact? Depends on your business. It depends on your organization. Same if we keep going down here, we're going to disable SMB v2 and three. And that's going to break file sharing between systems and it's also going to impact applications relying on file shares. Now, this might be a bigger deal, especially if we're doing a lot of collaboration. If we scroll down on the S channel vulnerability, when we enforce TLS 1.2, this might break compatibility with legacy applications. So that might be a huge impact. So those are dependencies and other things that we may not have seen or thought about, but Genai thought of it for us. That's pretty amazing. We scroll down and it's still talking about the false positive. And then there's some other things like systemic observations where again we want to use golden images, we want to harden images using CIS benchmarks and so on and so forth and some best practices. And then again here's a fancy table for us just to break it down nice and simple what the risks are. And here's some final recommendations. Communication is number one for sure. Change control roll back plans and so on. This step acts as your quality assurance layer. It ensures that Gen AI responses align with trusted sources and doesn't overlook anything that might break your environment. Remember again, you are responsible for the outputs. Gen AI is your assistant. It's not your final answer and it's not the authority. So, we always want to check the output for accuracy. If Jyn AI finds anything, we can refine the remediation plan with something like this. So we can drop this prompt in and say now update this remediation plan based on what you discovered from the latest vendor advisories updates community best practices and highlight any changes so I can see them. So now it's going to go update that remediation plan and you can see right here here's an update. It updated something with patching group policy adjustments. You can even do a PowerShell command to update the GPO. And you kind of scroll down a little bit more as it's still generating information. It updated patch versioning again. An advisory for SMB v1 all the way to V3. Alternative recommendations where you just block the port at the perimeter only, not internally. Some things like that make a big big difference. And also it talked about TLS enforcement using system default TLS versions. And just like that, you have an updated plan with any updates that are highlighted for your review.
Now, once you've got a validated remediation plan, it's time to create the documentation and service artifacts that keep the work moving across teams. You can use JAI to generate service tickets, user stories for agile development, and even update your ITSM platforms. So here are some prompts that you can use to do that. I would use something like this where I say create a service ticket or user story for this remediation plan written for JURA or service now. Include title, description, impacted systems, steps, acceptance criteria, and related CVEes. So this is going to generate the responses we need to put into the tickets. So now here you go. Here's your service ticket or your user story. And it doesn't have to be in this specific format. You can just grab what you want and paste it or you can just download this and create a document and then upload the document to your ticket. And there you go. It's got your impacted systems, your related CVE like we asked for, some steps to complete it and you keep going down. There's some acceptance criteria which are all the things that need to be done before this ticket can close, which is amazing. And then there's some tags even if you want to tag vulnerability management, tag a certain team, tag a certain CVE and so on. You can also drop a prompt in here to draft request summary for our RTSM platform that includes remediation steps, risk impact, effective services, and more. And it'll just shape that information into exactly what you need. So here you go. Your change type is going to be normal. It's not high priority. It might be high priority depending, but you can change that. Here's your start and end dates, description of changes, the remediation steps, and it's going through all of this and exactly what to do. Apply the latest patch, block this port, validate it with an MAPAP or another scan, and then take a look at the firewall rules, and then do not disable SMB v2 or 3 unless we're preapproved and it's been tested. Pretty cool. Same with all of the other findings. And here's a risk and impact analysis where you have rce and wormable vulnerabilities. You have disabling print spooler or TLS enforcement port 445 and also these false positives might result in unnecessary work. So again, we want to go confirm that false positive before we actually input this into the system. This is amazing. Look how much detailed information there is here in just a matter of seconds. And again, here's your approval checkpoints and a communication plan. And here's one last prompt you can use where we write a communication brief for stakeholders to announce patching timelines, possible downtime, and expected outcomes. So, this is what we would send before we start doing some work. Now, you can see that it's going to generate a subject line for you, and then it's going to start putting together a summary. Patching timelines should take about 15 minutes from patch to reboot.
Another one is going to take about 10 minutes for patch and then firewall reload. This one should take no time. There's no downtime, no impact. And then gold image updates is offline, so it's not going to impact any running systems. And then it'll talk about the scope of work. You have the possible service disruptions. And really the one you're worried about is the finance database. That's the biggest thing. And then your expected outputs and then some support information. Here's an email alias to send your email to or maybe you put a phone number in there for your network operations center or whatever it might be. And there you go. And everything's generated for you in just seconds. It's crazy, right? This turns Gen AI into your project assistant writing templates, tickets, and change notes that you would normally spend hours and hours on. Isn't that amazing?
Now that we walked through the entire workflow and the prompt chain for generating remediation plans, action plans, here is what I hope that you take away from this lesson. Use the vulnerability summary output as the base to chain remediation prompts. Always include context, operating systems, application versions, criticality, and the audience. Ask Genai to generate role specific outputs. Technical for CIS admin and engineers and strategic for managers and executives. Also let Genai assist in writing your documentation whether it's your change tickets, tracking tables or notices. And always always validate Genai output against vendor guidance and your environment. And there you have it. You've just moved from scan results to strategic remediation in record time and all with the help of Gen AI. You didn't just find problems, you planned the fixes. You empowered every stakeholder to act. And you did it in a way that's consistent, scalable, and smart. So, keep iterating, keep prompting, and keep building those skills. You're doing outstanding work throughout this course. All right, I'll see you in the next lesson.
What's more dangerous than a vulnerability with a 9.8 CBSS score, a 6.8 CBE hiding in a critical server that no one's prioritized until it's too late. But that's not going to happen to you. By now, you've built the muscle memory to go beyond surface level scanning. You can now break down CVEEs in plain language. Prioritize risks based on real world context and not just CVSS scores. tame massive vulnerability scan reports and generate remediation plans and action steps that are tailored for specific roles. And this lesson will help you tie it all together with a real world challenge and prep you for the next stage in this course.
Traditionally, vulnerability management has looked like this. You run a scan, you export a PDF or a report, you glaze over thousands of findings, you patch what you can, and you hope for the best. That's not a strategy. That's survival. And in cyber security, hope is not a control. You've learned that CBSS scores are starting points, not decisions. Not all vulnerabilities deserve equal treatment, and risk is contextsensitive, and so are your decisions. That's why Jyn AI matters to you. It doesn't just replace you, it extends you. You now have the skills to drive an intelligent AI assisted risk workflow. You can take a raw CVE like CVE 20256170 which was that stack buffer overflow in XML that we talked about and translate it quickly with GAI. Then you can prompt Genai to evaluate risk all based on your environment not just public scores. You can then go further to prioritize findings from a scan using more prompts. And finally, you learn to turn Gen AI into your remediation assistant. These aren't just prompts. These are decision engines.
Now, let's put everything you learned together in this section and we'll put it into practice. Let's say you just received a vulnerability scan report for your public facing systems and your CISO needs a clear breakdown of the top three critical vulnerabilities, a prioritized action plan with remediation tasks per role, and an executive summary that they can understand and share with the board. Now, before we drop anything into Gen AI, we need to pause for a second. Your scan data, your CVE notes, or your system logs might include sensitive information like internal and external IP addresses, usernames, business logic, or even personally identifiable information. Remember to treat Gen AI prompts like external systems. Always sanitize before you share. So, we want to use redactions like internal IP1, user a, app server, client name, and so on. And if you're using a public or cloud-based geni model, we never want to paste in any production credentials, configuration files, or anything related. That's why I provided the artifacts so that you can work with them without any risk.
Now, let's say that you've got a handful of high-risk CVEes coming out of your scan, but your sock team doesn't need a copy paste from MITER. They need context. They need clarity, and they need some insight. So, step one is to break down the CVEEs. And I'll go to my prompt library and I will drop this prompt in. You're a senior cyber security analyst. Explain the following CVEEs in plain English for sock analysts. include how they can be exploited, what systems are impacted, and the real world implications of an exploit. Use CVSS and vendor references to support your findings. Provide the output as a bullet list with technical and strategic notes. And then I dropped three just kind of random CVE in here for us to work with. And I'll go ahead and send that off. And as you can see, CatchPT is starting to process this. It's searching the web. And now I thought about it for a few seconds and now here you are. So now you have the 2025 6170 that we talked about in this section. And again the score is 2.5 but we know when we went to MITER that's not the correct score. So we need to go double check that. Also it found another one which is 2025 6128 that we asked it to do and also 6130. Okay. And you can see that it gives you the technical details which is buffer overflow exploit scenario system affected real world impact strategic insights just like we asked for and then here is our table local shells remote and then also stack overflow there's an HTTP post and an HTTP post vulnerability and then it wants you to prioritize the total link firmware vulnerability and then deprioritize guys 20256170 for now unless your environment uses a vulnerable interactive shell. So Gen AI took all the this dense jargon heavy descriptions and turn it into something that we can use fast. We now have a clean digestible breakdown that our team can act on.
Now in step two you need to factor in what matters most which is your environment. We want to prioritize based on our findings and we want to use context to do that. So a CVE affecting a test server is not the same as one targeting your production environment. So to bring that context to play, we want to drop this prompt in. You are a cyber security risk assessor based on the following environment data. Internet facing mission critical app server and exploit activity. Rep prioritize these three CVEes. Provide updated risk rankings and explain how environment changes the threat model. Now, one other thing we could do here is look through the asset inventory and determine if anything might be affected. So, we'll go ahead and run that. And it might take a few seconds to go through the spreadsheet and find anything that might be affected. And here you go. And so, now it's updated the CVE risk prioritization. And so now CVE 2025 6128 is critical. This one is critical. So, let's scroll back up for a second. and 6128 was second. 6170 was first in that table, right? So, it wants us to step up 6128 because it is more critical based on our inventory list. So, you can see how when you feed Gen AI more information, it can make better, more effective decisions for you. So, now it wants us to address this buffer overflow. And if we scroll back up, let's see if that matched what it told us before where it broke down 6170, 6128, and 6130. And it didn't really give us a priority. It just gave us the table. But now we asked it to focus more on the risk. And now it's saying this is the priority to address. And then it's going to go through some details on why it's number one. And it's a network level rce attack action for the sock. So check whether any sight to side or cloud to office connections include uh small office home office routers and so on and so forth. Okay. So now we have a good action plan that we can start working with. So Gai assessed risk through our lens not just through a CVSs score. It might downgrade one issue like you saw, but it might flag another one as urgent because of how exposed the system is. And now you've moved from guessing to precisionbased prioritization.
Now that you've got your risk ranked vulnerabilities, it's time to start fixing things. So step three is to generate a remediation plan. This is where JAI becomes your remediation assistant. So I'm going to go to my prompt library and I'm going to grab this prompt. You're a remediation planner for each CVE. Create a step-by-step fix for CIS admins. Include patch steps, config tweaks, validation commands, roll back guidance, and any change control flags, and format it in a table like we asked before. So, I'm going to go ahead and send that. And here's your remediation table. And it's going to take a few seconds. So, here you go. For 6170, you're going to do this. and it's identify systems and you're going to run this and all kinds of different steps. And then you have 6128 and it shows you exactly what to do. And then you also have 6130 and it shows you exactly what to do. Pretty awesome. And then now it's going to go through the change control flags. And some flags that we need to consider are things like downtime. So if we're going to patch anything, normally when we patch, we have to reboot. So that's going to cause some downtime. And with downtime, we could have user impact. We need an emergency change window. If we're going to make the change now, we need to make some notifications and let everyone know this is an emergency and to expect some downtime. Now, this gives you a clean table that you can drop into Jura Service Now or even a remediation worksheet. But there is one thing that I didn't see. I didn't see a roll back plan. So that's not included. So, I'm going to ask chat GPT, please include a roll back plan. Something real straightforward and simple. And then it'll regenerate all of this for us, giving us a roll back plan. So now there's your action steps, your verification, and if I scroll over a little bit, you can see the roll back plan, roll back trigger, factory reset, all kinds of different things like that. Okay. And then again, here's your change control reminders and so on. Pretty awesome, right? You go from chaos to clarity in just one move.
Now, the final step is to package everything up with an executive summary. The CISO doesn't want technical details. They want to know the big picture. What's the risk? What's the exposure? And what's the plan to keep the business safe? So, in this case, we're going to go to our prompt library. We're going to use this one last prompt. You are a cyber security leader writing for the board. Summarize the findings and risk in three paragraphs. The vulnerabilities, the exposure, and the fixed timeline. Use clear non-technical language. And we'll fire that off. And it will take everything we found to this point and convert it into something very simple for our executives to understand. As you can see, here's our vulnerabilities. Lays it all out. Here's the exposure. Lays it all out. And here's the fixed timeline. Pretty awesome, right? You can even go so far as to ask, create a bullet list, create a table, and so on. So it's something easy for the executive to see. So you could ask chat GPT, please also include a quick, easy to read table for the executive audience. And as you can see now, it's going to generate a quick table that we can drop in there. Here's your risk level, impact if exploited, exposure, fixed, timeline, and now your executive can quickly see what's going on because let's be honest, do we really want to have a talk about an XML tool that's a low impact or do we really want to focus our efforts right here? And that's what your executive needs to know. Pretty awesome, right? Now, if you want to go the extra mile, you can follow up with other prompts to rewrite the summary into a short email so you can send it off and so on and so forth. But with just a few prompts, you've taken raw CVEes and turned them into clear analysis, tailored the fix to each role and created updates for both your sock and your seuite. And all of this was done using Genai with the race framework for your prompts.
Now, here's what I want you to walk away from this section. CBEEs are more than ID numbers. They're stories, so learn to translate them with Gen AI. Context is everything. Risk lives in your environment, not in a number. Scan reports are data, but Gen AI will help you turn them into decisions. Fixing vulnerabilities requires clarity across teams, and Gen AI helps tailor the plan for each of them. And you are the operator. AI is the assistant. So, use the race framework to generate your prompts, validate the outputs, and own the process. And with that, you have just crossed a major milestone. You've learned to analyze, prioritize, and act on vulnerabilities like a pro. Now, what we're going to do next is we're going to shift our focus from long-term risk to real-time response. In the next section, we're going to focus on using Gen AI to triage alerts. And you're going to learn how to cut through alert fatigue with Jin AI powered triage. You'll learn how to summarize alert payloads into actionable insights. You'll learn how to escalate or dismiss alerts using structured AI workflows. And you'll also learn how to reduce time to response without compromising accuracy. This is where JAI becomes your daily partner in the fight against attackers. So, let's keep building. You're not just managing vulnerabilities anymore. You're becoming an AI augmented defender. And that's amazing. So, I'll see you in the next lesson.
Ever feel like you're drowning in alerts, jumping from one blinking red light to the next, and by the end of your shift, you're not even sure if you actually solved anything? I know I certainly have in my career, and I'm sure you have as well. So, let me hit you with this. The average tier one sock analyst investigates thousands of alerts per day, and many of them are false positives. That's not just inefficient, it's dangerous. Real threats hide in the noise. So imagine if you had a partner who never sleeps, never gets burned out, and could constantly look through the mess to tell you what matters and what to do about it. That partner is Gen AI. In this lesson, we're going to dive into how you can use Gen AI to not only just triage alerts, but go one step further to generate realworld actionable remediation steps. So, we're going to walk through why alert overload is killing analyst efficiency, how Jin AI can help you identify root causes faster than ever, how to use Gen AI to autogenerate action plans that are customized for your environment, and practical prompt examples that you can use today to lighten your workload and make smarter decisions. This is where everything we've learned in the previous lessons come together. Because once you've triaged an alert, you don't just want to know about the issue. You want to be able to fix it and fix it fast.
So let's say that you're a tier one sock analyst. Your SIM is pinging every few seconds. Some endpoint alert, then a firewall hit comes in, then a suspicious login, and again, you bounce from Splunk to Crowd Strike to Microsoft Defender, juggling tabs while just trying to figure out, is this real or is it just another false positive? Is it urgent? and what do I even do about it? Welcome to what I call the triage nightmare. You're looking at dozens of noisy alerts, tons of context shifting between tools, overwhelming ratios of false positives to real threats, and a race against time, knowing that one missed alert could be the one that impacts your business. And when you add this up over days and weeks, the result is analyst burnout. Not just mental exhaustion, but operational risk. the constant fire hose of data that trains your brain to ignore alerts rather than to investigate them. That's exactly what attackers are betting on. But here's the good news. Gen AI was built to handle this kind of pattern chaos. Its ability to work across semistructured or even unstructured data makes it your ultimate ally. So, let me show you how you can do that. Before prompting Jin AI, make sure to include the alert source. whether it's XDR, SIM, an email gateway, or whatever it might be. You also want to include the affected user or asset, and any timestamp or environment metadata. This helps Gen AI give you more accurate results, especially in noisy environments. And remember, always sanitize any sensitive data like IP addresses, usernames, and so on. But I have included artifacts in this course that you can use that does not contain any sensitive information.
Now, step one is to summarize multi-line alerts. So, let's say you've got an XDR alert that includes 150 lines of process activity, command line invocations, child processes, hash values, network calls, and more. Look, we don't have time to read through all of that, especially not if 20 other alerts are waiting on you. So, let's use Gen AI to help with this. And here's a prompt you can use. So, I'm going to go to my prompt library and I'm going to drop in this prompt. You are a highly experienced security analyst assisting with incident triage in a sock environment. Please review the following XDR alert data and provide a concise summary. Focus on explaining what occurred, whether the activity is likely malicious or benign based on the context and what the potential impact could be if the behavior is part of an active threat. Aim to deliver a clear and actionable assessment that helps guide the next steps in the response process. So, what I'm going to do is I'm going to drag the artifact from the course for the Palo Alto XDR alerts and then I'm going to execute this prompt. So, as you can see, it quickly processed the CSV file and it's actually going through it. And here's an initial triage summary of the XDR alerts. So, you can see there's an alert ID, there's a device, there's a user, a process, and MITER techniques. Okay, it only found three things, but this file isn't gigantic, but it's just meant to be used for this course. So, here's a deep dive on the alert. 2218 is a suspicious PowerShell execution. Jay Roberts executed PowerShell exe on sales laptop 22, and it could indicate that this person might be trying to offiscate something. So, we might want to take a look at that. There's a strong indicator of malicious behavior. So, that's something we definitely want to dig into. Again, the same user on the same asset is executing something else. And looks like they did a select command with explorer and this is likely benign. So this is probably a false positive. Nothing really to take a look at. Then we have another one. M. Carter using zoom. This is standard zoom usage. So nothing suspicious here. No IC's. So some actionable recommendations are to prioritize the investigation of this particular alert. So now we know where to focus our efforts, right? See how fast and effective that is. you get a plain language summary that highlights any suspicious activity.
So now step two is to look for more patterns across noisy logs. So I'm going to go in my prompt library and I'm going to follow up with this prompt. Review the provided logs which include endpoint activity, network traffic, and identity access events for specific users. Correlate this activity across all three data sources over time and identify any patterns that may indicate credential misuse, lateral movement, or other suspicious behavior. Highlight any anomalies or sequences of actions that suggest this user account might have been compromised. So, what I'm going to do is I'm going to drag the XDR alerts again just so it has it for context. And I'm going to drop the malware alerts in there as well, just in case there might be something to take a look at. So I'll go ahead and execute this. And now it's analyzing and comparing the files with the findings. And as you can see, there is no timestamp data that's present in these logs, which prevents the full correlation. So you can see that right here does not include timestamp data with full correlation. So that is a problem for us. However, it did go through and still analyze and now it's still it identifies J. Roberts as a problem. Suspicious PowerShell execution gave us some minor attack framework IDs to look through. And then you can see that there's something else. There's some behavior overlap in the malware logs. And you can see that J. Roberts does not appear in the malware logs. So that has nothing to do with what we're seeing in terms of the malicious activity. Scroll down a little bit more. It gives you a statement that says the malicious payload likely deployed as a Java archive or something like that. So, we might want to look into that a little deeper. Then there's some indicators of credential misuse where there's no direct logs provided. So, we can't really dig deeper on that. But here's a summary of all the suspicious behavior that we've detected to this point. It's pretty awesome. All right. Now, here's some next recommended steps to isolate the affected endpoints, decode PowerShell, collect memory and registry artifacts, do some threat hunting here, reset credentials, and correlate with any other logs that we have.
Now, what if we want to turn some raw logs into clean actionable checklists? In that case, we can use a prompt like this. Based on the alert data provided, generate a structured incident summary that includes suspected attack type, relevant MITER attack techniques, risk priority, affected systems or users, and recommended next steps. And use bullet points or a table for clarity. So, we'll send that off. And here is your summary report. So, you can see that it is a suspicious PowerShell execution, fishing via weaponized word documents, and also the risk priority is high. Then you could see Jay Roberts, the asset involved, the other affected hosts that might be involved from lateral movement. Then you see the relevant minor attack techniques where you have the technique ID and that correlates with PowerShell, another ID that correlates with fishing and so on and so forth. Then when you go down a little bit more, you have a summary by host. And so it walks through pretty much giving you a chain of events where someone opened a word doc that triggered the PowerShell and the macro that executed was based on these two miter attack ids and then there was some navigation right after that to explore.exe and then that related to it08 and that related to this laptop as well. So the risk assessment is the likelihood of compromise is high. So we have a very big problem here. Data Xfiltration risk is very possible. So C2 is present. Command and control is present here. Lateral movement has been detected very likely. And also credential misuse risk is probably pretty high and detection gaps. There's no identity logs present for confirmation. So our recommended next steps is to immediately contain things and then start forensics and analysis. Perform some threat hunting like we talked about earlier. perform some more network analysis and conduct user awareness and reporting. How incredible is that? This is how you remove ambiguity and generate structured response actions that you can actually follow.
Now, let's autogenerate remediation steps for any of these findings. This is step number three. Once you've confirmed a threat, you need to act fast and act precisely. And you can use this prompt to do that. So, I'll go over to my prompt library and I will copy this. Using all of the data above, please create a detailed remediation plan, including immediate containment actions, communication steps for the user, detection enhancements, and follow-up investigations to identify potential secondary compromise. And so, as you can see, it's starting to think about it. And here is your plan. The remediation plan is first we want to isolate the affected systems. Then we want to look at credential protection. So we want to force a password reset for J. Roberts, any user account with recent login and we want to revoke any active tokens or sessions. We also want to disable any malicious processes or artifacts as well. Then in terms of communications, we want to notify end users. We want to also notify internal teams like our sock, the IT help desk, instant response lead and legal and compliance if any data Xfill was detected. We also want to create a management brief and then when we come to detection and prevention, we need to deploy new detection rules. We want to do some network monitoring, harden that email gateway, and follow up investigation with a timeline reconstruction, a secondary compromise assessment, a threat hunt across the environment, memory and disk forensics, and more. And then you can see the post remediation actions as well where we want to reimage the endpoints, validate restored systems, and so on. How incredible is this? How powerful is this to use? Your Gen AI assistant responds with exactly what to do. Disable the user sessions, reset tokens, run targeted threat hunts, notify the user, create detection rules, and more. You didn't have to waste any time researching best practices, checking runbooks, or copy and pasting from a playbook. Genai was your playbook. How incredible is that? And if you want to go a step further, you can even try a prompt like this. Using the MITER attack framework, map the alert sequence below to relevant tactics and techniques. Then generate a remediation and detection strategy using the most recent threat intelligence sources. Focus on actions that would prevent recurrence or escalation in a similar attack. Then we'll run this and in just a matter of seconds, we're going to get a plan. Now you have a correlated alert sequence for MITER mapping. If we scroll down now we can see a table. The initial access was a malicious word doc launching PowerShell. Execution was the encoded PowerShell command executed via word. The defensive evasion was the use of base 64 encoded PowerShell. Persistence discovery C2 or command and control more C2 execution user action and lateral movement. It gives you the entire breakdown from start to finish of what this attack looked like. And then it gives you a threat profile based on the latest intelligence like we asked for. And you can see the malware indicators, the TTPs which are tactics, techniques and procedures. And then you have your remediation and detection strategy. Some preventative controls that we can add where we can enhance our security at the gateway for the email PowerShell policy hardening application allow listing or whitelisting endpoint hardening and then detection engineering where we're actually looking for PowerShell with this command here. Word launching PowerShell some WI queries Java launching cmd and so on. Look how incredible this is. You even get resilience and monitoring enhancements. And you also get post incident recovery actions as well. Just look at these results. Now you're working like a tier three analyst, even if you're just starting out in a sock.
Now, step four is to adapt the remediations to your specific environment. Remember, a remediation is not a one-sizefits-all. So, let's tell GNAI about your environment and get a tailored remediation plan. So, I'll go to my prompt library and I'll grab this. Given that our environment includes Octa, Google workspace, and CrowdStrike, create an environment specific remediation plan that includes identity management actions, endpoint validation, session revocation, and follow-up hunting across cloud systems. And then I'll run that. And here is your targeted remediation plan. Your environment specific remediation plan now includes Octa, Google Workspace, and CrowdStrike Falcon. And so now it tells you what to do in Octa. If you scroll down, it says, you know, force a password reset, revoke MFA factors, check for suspicious login or signins. Here's some precautions to take as an administrator. Then on the CrowdStrike end, you're looking at isolating these hosts using Falcon's network containment, some investigation steps that you can do, and preserving forensics if you want to do a deep forensic investigation. And then also, here's some more Octa and Google Workspace directions, email trace and quarantine, and some follow-up threat hunting using CrowdStrike Falcon. Just look at all of this data that you get back just by using a solid prompt. And here's a summary of actions by platform. So on Octa, we want to reset the credentials or creds, revoke MFA, terminate sessions, audit privileged access, go into CrowdStrike, isolate the endpoints, trace the process trees, hunt for IoC's, and preserve memory and registry. Google Workspace, revoke OOTH access, remove malware emails, and audit drive and login sessions. And some final recommendations are to create octa behavior rules. How powerful is this? This is like having a Gen AI security ops engineer on call 24/7, 365 days out of the year. Now again, remember, you're not outsourcing your judgment to Gen AI. You are augmenting your work, meaning you are responsible for reviewing, validating, and adapting the output here. But Gen AI gives you a 10x starting point by far. So instead of spending all of your brain power googling commands or digging through past notes, you're using that energy to make good decisions and not sifting through or digging through lines and lines of alerts. Pretty awesome, right?
Now, here's what I hope you take away from this lesson. Gen AI can help fight alert overload by summarizing, filtering, and contextualizing noisy security data. You can use it to autogenerate tailored remediation steps based on real alert data and your environment. Jinai excels at turning raw logs into structured, actionable outputs that you can trust and verify. The key is in your prompts. Treatai like a skilled junior analyst who's great at processing, but needs your guidance and review. And when used right, Genai turns triage from a nightmare into a strategic advantage. And remember, Gen AI isn't here to replace you. It's here to make you the most effective, fastest thinking security professional on your team. It's about working smarter with a powerful digital ally by your side. And lessons like this are here to not just help you survive in cyber security, but thrive in it. So, I'll see you in the next lesson.
If you asked someone for directions and then handed them a full road map of the entire country with no context, do you think they would get to the destination quickly? Probably not. And that's exactly what most analysts do when they throw raw logs and massive alert dumps at Gen AI and expect some kind of magic. But here's the truth. Your AI is only as good as the data and instructions that you feed it. If you want smart, accurate, and actionable insights from Gen AI, you've got to set it up for success. So, in this lesson, we're going to tackle a critical but often overlooked skill. And that's how to properly prepare alert data before handing it off to Gen AI. We'll cover why garbage in means garbage out even with the most powerful AI. What types of data work best for AI triage and what to avoid, simple techniques to clean, format, and chunk your alert data for better AI output, and real world examples of data prep that makes a difference. So, you're going to walk away with a repeatable process that you can use every time you're working with Genai for alert triage.
So, here's the problem. Most people don't realize that Gen AI is not a mind readader. It's not looking over your shoulder. While it is capable of interpreting raw data, it doesn't know what's important or what's just noise unless you tell it. And the way that you do that is through your prompt input. So, think about a sock analyst working with Splunk or IBM Q Radar. You've got thousands of raw logs, cryptic field names, irregular timestamps, and sometimes even unstructured alert comments. So, if you just dump that raw data into a prompt and say, "Tell me what's wrong." Genai is not going to know. It's going to struggle. You're either going to get vague, incorrect results, or even worse, you'll get hallucinations that sound confident but are flatout wrong. The analogy I like to use is if you give Jen AI a haystack, don't expect it to find the needle without a map. So, the challenge here is how do we give Jen AI the map?
So, let's break it down in steps that you can actually follow every single day on the job. Step number one is to know which alert data types work best. Not all data is created equal. Some alert data might be AI friendly, meaning that they have patterns that Genai can recognize and reason through easily. Here are the best candidates. Intrusion detection and prevention system alerts. So, snort, sira alerts, things like this are usually rule-based and follow a very consistent structure. For example, you might see something like this. Now, this is gold for AI because it includes clear fields like classification, priority, protocol, and IP addresses. SIM logs from Splunk, Elastic, Q, Radar, and more are also good. These tools normalize logs, making them more digestible for Gen AI. Here's an example of a Splunk event that you could feed it. This is easy for AI to parse through and summarize into security event narratives. Genai can also handle firewall or endpoint alerts as well. They all vary depending on the platform, but what's most important is that it's specific, patternrich, and clear. So, these are exactly the kind of bite-siz data chunks that Gen AI can interpret and evaluate. You can also try other logs as well from other platforms to see if you can gain any intelligence.
Now, step two is to clean up the data. We don't want to just data dump here. Jinai isn't a log parser. It's not built to digest a 500line SIM export or a giant CSV or Excel table. So, don't tell it here's a JSON file with all of our Surraotta alerts for the week. Analyze it. Instead, we can give it a prompt like this. And then what I can do is I can add the surraicotta IDPS logs from the artifacts and I can execute this prompt. So what we're looking for is we're looking for notable patterns, repeated indicators, some correlations and then we want to go ahead and summarize the findings clearly so that we can understand the severity of the activity. So I'm going to go ahead and execute this. And as you can see quickly, it evaluates everything and analyzes everything and then it gives you some repeated suspicious activity and so on. So again, we're seeing just how powerful Chat GPT and other Gen AI tools can be. And just to show you, I'll go over to Claude because I've been demonstrating Chat GPT so much because it is the most popular tool, but I'll give you an idea of what Claude can do as well. So I'll drag the artifact in and then I'll run Claude. And then we'll see what Claude comes up with. And so what we'll see is network reconnaissance, DNS enumeration, SSH brute force and so on. So what we could do is we could test both tools and then compare the results. Pretty awesome, right? Now, what I'm going to do is go back to chat GBT and then I'm going to follow up with another prompt and I'm going to say based on the alerts provided, evaluate whether there's any evidence of beaconing behavior or data exfiltration attempts. And so, we'll run that and let's see what chat GPT comes back with. So, there's some indicators supporting beaconing. There's strong evidence in fact of beaconing from this particular IP address. So this is internal to the network and it looks like it's a command and control alert. So it is something we need to take a look at. Again, we can look for the conclusion. There's no direct evidence of large scale data xfill. So we're not so concerned about that. So we want to take a look at beaconing. And then here's your summary and some next steps. Pretty amazing, right?
Now we can't discuss all of this without talking about redacted sensitive information. So step three is before we do any kind of inputs, we definitely want to sanitize the data. Yes, Genai is powerful, but you still need to be responsible. Never paste production IPs, real usernames, or internal asset names into Gen AI without redacting them first, especially if you're using a cloud-based Gen AI tool. And remember all of the artifacts I've provided are all simulated data. So no redaction is necessary. But it is a very good habit to get into. And then when inputting the data, you can always tell Gen AI in a prompt that all sensitive data fields have been redacted using placeholder labels such as internal IP1, user A, and critical asset one. Please include these in your response where applicable to maintain context and that way you stay compliant and responsible and you still get the value that you need from it. Okay.
Now step four is to provide context where needed. Again we don't want to make Gen AI guess at what it's looking at. So what we want to do is go to our prompt library and copy this prompt. The following IDPS alerts were triggered by Surakraata within a 10-minute window. analyze the alert data to identify signs of suspicious behavior such as internal to internal IP, SMB traffic, RDP activity, and other things. And then summarize your key findings and explain whether they align with known lateral movement techniques and other things. Okay, so I'll drag that artifact back in here for Serakotta and I'll execute this command just to see what kind of results we get. And as you see, it's already done the analysis. So it comes back with SMB traffic or the eternal blue exploit. And then you have some RDP activity things we talked about earlier, but this is just a different way to look at it. Okay. And then there's an internal host with multiple alerts. So this is definitely a problem machine that we need to take a look at. You have end mapap scanning, suspicious outbound DNS going on, some potential SSH activity, like a lot of stuff that we probably want to take a look at, and so on. And as you go through, it will give you more and more information about what to do. And then finally, here's some recommendations. And you can also do this with Windows Defender logs, journal D or audit D logs, and more. This guidance goes a long way toward improving your output.
Now, here's a cheat sheet to take away from this lesson. First, we want to feed AI properly. Structure and clarity will beat raw volume every single time. The best alert data types are IDPS, SIM, logs, firewall, and EDR alerts. Stick to structured, patternrich sources, and you'll get good results. Also, we want to clean up our input. So, keep it short. Split logs into chunks if you have to to avoid full data dumps because sometimes Genai will miss things when the data set is larger. Redact sensitive information. Remember to use placeholders for labels like IP addresses, usernames, and other sensitive information. And then also give light context. Briefly explain what the data is, what you're looking for, and what the AI should focus on. So if Genai is your co-pilot, then clean alert prep is your flight plan. So we don't want to just throw data at the wall and hope that it sticks. We want to feed it the right way so that it becomes a tireless analyst who is ready to help you move faster, think clearer, and reduce any burnout. Now, next up, you'll learn how to prompt Genai to actually triage these alerts effectively with real world scenarios, prompt patterns, and templates that you can steal from me right away. But it all starts with prepping your data like a pro. So, you're starting to build that foundation for smarter cyber security. You're doing great. Keep going and I'll see you in the next lesson.
Have you ever wished that your junior analyst could work 10 times faster, never miss a pattern, and actually enjoy going through the alerts? What if I told you that you already have that analyst, and you guessed it, its name is Gen AI. But here's the catch. If you don't guide it to think like a real analyst, it won't act like one. You've heard the phrase garbage in and garbage out. But when it comes to AI triage, the real lesson is structured prompt in, intelligent output out. In this lesson, you're going to learn exactly how to take what you learned in the previous lesson and prompt Genai to triage alerts the way a real tier 1 analyst would. What we're going to cover here is how to guide GIN AI through logical triage steps, formatting output so that it's instantly useful, customizing prompts for different alert types, and chaining prompts to go from detection to action. And by the end, you'll have a library of practical prompt patterns that will reduce your workload and improve your decision-making speed.
Now, let's talk about the sock daily grind. you get an alert, maybe it's a brute force login, and you start asking yourself, what's the source IP address? Is it external? Is it internal? Is it persistent? Was it successful? What account did it target? And you start flipping through logs, chasing down connections and interfaces, switching tools, and let's be honest, sometimes you miss things, not because you're careless, but because you're overloaded and you're overwhelmed. This is where Gen AI can help you tremendously. But not if you just throw raw logs at it and ask what's wrong. That's like handing someone a 500page book and asking summarize the plot for me. You need to guide AI like a security analyst and tell it here's what to look for, here's how to process it, and here's what to deliver. The more that you can offload repetitive pattern-based work to AI, the more energy you preserve for real threats. And that means less cognitive fatigue, fewer mistakes, and more focus where it matters. So, let's dive into this and let's get hands-on.
Step one is to use prepped alert data like we did in the previous lesson. In the last lesson, you learned how to clean, chunk, and sanitize your alert data so Genai isn't overwhelmed by noise or buried in junk. You also learned that clarity beats volume every single time. So now that you've got well- prepped alert data, whether it's from Surakraotta, Splunk, or even CrowdStrike, what do you do with it? Now, this is where you give Jen AI a mission. Not just look at this data, but how to act like a tier one analyst, identify bad behavior, and rate severity, and give you some recommended next steps.
So, step two is to structure your prompts like an analyst. So let's turn that alert into a structured analysis using the race framework. Remember that stands for role, action, context, and expected output. So I'll go to chat GPT and I'll paste this prompt. You are a tier 1 security analyst. Please review the following alert data and describe the observed behavior. And you can see that it goes on to explain that we're looking for anything benign. We're looking for suspicious or malicious. And explain why it detected that behavior. So, what I'm going to do is go over to my course artifacts and I'm going to grab that circa data IDPS alerts that I created for you and I'm going to execute that prompt. And now you can see that it has recognized some observed behavior. So, you have some inmap activity, you have some suspicious DNS like we found in the previous lesson, some SSH brute force and so on. So, I demonstrated this in the previous lesson, but now we're going to dive deeper into this. So you can see that it found quite a bit. Some threat categorization. There's some analysis being done here. And then here are our recommended response actions. So a lot of great data here.
So now I want to follow up and make this usable. So step three is to format the output for speed and clarity. So I'm going to go to my prompt library and I'm going to ask chatgpt to format the output from your analysis as a table with columns for timestamp, user, host, and more. And each cell should be concise and focused on key triage details. So now I'm going to send that. So here's our table and you can see that it organized everything. You can see again this is our problem host for sure 1010 515. So that's something we definitely want to take a look at. And it organized everything via time stamp. You can see kind of the audit trail of what's going on here. There's no user involved and you can see the observed behavior. So, let me click that off so I can get over here and I'll scroll over. And then it also shows the severity and some recommended actions for each step.
But let's take it one step further. Step four is to customize the prompt for specific alert types. So, what if we want to observe this alert for a CVE? So, I'm going to go over to my prompt library and I'm going to copy this. You're a sock analyst reviewing an alert for CVE 20244567. And now I'm going to review that data against this CVE and see if anything flags. Now, it's asking for the exploit signature and traffic data. So, that means that it just doesn't recognize the file anymore. So, what I'll do is I'll go ahead and drag that file back in and I'll type here is the file for your analysis. And so now it's going to analyze that file and see if
There's any CVE alerts to pay attention to. So, as you can see, it did an analysis, and there's a lot of data here. So, it's asking, does the behavior align with known exploitation patterns? Yes, it does. As you can see up here, I kind of skipped through it. It does have an alert for 2017 0144. That's for Eternal Blue. And then it also says it could target the CVE that's in concern. So, let's look down a little bit more. Some severity. If this is unpatched, then it's exploitable. And so now it gives us a response plan of what to do. So, we want to verify all servers and endpoints for that vulnerability exposure. That means we have to go off research that CVE, and we can go back to previous lessons and do that research and then tie it back to these alerts. Huh. Interesting. Okay.
So, now would you like me to generate a SOC incident report table? Not yet. Let's keep analyzing this a little bit more. So, I'm going to go back to my prompt library. And now what I want to do is I want to review this data for login events. That's what I want to look for now. So, then we'll run that. And so, again, it doesn't recognize the file. So, we'll just drop that file back in and tell it, here is the file. And so, now it'll read it. And in this case, we might want to also provide something from like Microsoft Entra ID, AWS, or Microsoft Azure that might have more login data. But what I want to demonstrate here is that it can even find some login patterns just from your IDPS alerts. It can also find it in various other alerts as well. So, as you can see, it went through it a little bit, and there's really nothing of huge concern that I'm finding. It's just more or less require MFA, investigate things. There's nothing significant in the IDPS alerts that would let us know that we have some login issues or anything like that.
So, now what I want to do is I want to review any traffic between internal IPs because if you recall, that 10.10 address is local. It's internal. So, with that said, we might have some lateral movement coming off of that IP address. So, we want to take a look at that. So, again, I'm going to drop that file in just to avoid any errors. And let's see what it comes up with. So, yes, there's that 10.10 node that we were looking at earlier. That one definitely has some issues. And so, if you go down a little bit, lateral movement indicators right here, we have an SMB exploit. And that points to possible lateral movement. And then you also have RDP activity, which could indicate administrative access attempts as well. And so, if you keep scrolling down, there's a response plan that it created for us and more. So, we get a lot of data just from one single prompt that's analyzing that file. And the possibilities here are endless.
So, now that you found what you're looking for, step five is to chain prompts together to extend this investigation. So, what I'm going to do is I'm going to put this prompt in. "As an expert security analyst continuing this investigation, analyze the prior triage summary, identify which log sources or data types would be most relevant, and so on, and then recommend any specific log queries, time windows or tools to use and explain what indicators or patterns to look for." So, it's going to analyze this entire chat and then tell us what to do next. So, here you go, where the firewall or IDPS logs are something we need to look at. Windows event logs, DNS logs, proxy and web server logs, email logs, EDR logs, and then if we have any pcap data, right, packet captures. So, with that said, we want to go and get these logs and bring them in and then correlate all this information and then we can run these prompts again. And here's some examples of what to look for and so on. And then here's some patterns and indicators to look for where maybe you're looking at reconnaissance, lateral movement, command and control traffic or C2, persistence, and data exfiltration or data xfill. So, these are important things for us to go and take a look at.
So, I'm going to follow up with yet another prompt and keep the chain going. So, in this case, now you're an expert cyber security engineer creating defenses based on prior investigation results. So, now we're going to go ahead and start creating defenses for this. So, we're going to go ahead and run this command. And so, now it wants us to go ahead and start defining some rules. And you can see that it wants us to look at things like source IP, destination IP, destination port, signature, protocol, timestamp, and more in our firewalls. And it wants us to do the same in DNS logs, Windows logs, and everything else. Then it's got some match criteria that it recommends we do, some correlation rule logic, thresholds to reduce false positives, all kinds of things. And then it even gave us a SIEM query that we can drop right into Splunk and start getting results from. That's incredible right there. Some recommended actions and then also your next steps. And then it's asking, do you want me to create three additional correlation rules tailored for outbound DNS, repeated RDP, remote desktop protocol, and then HTTPS POST activity that might indicate data exfiltration? And if you want to go just one step further and make this even easier, 'cause I know there's a lot of information, you can ask a very simple question. "Can you please summarize my next steps in plain language?" And now it'll tell you step by step. Here's what you need to do. Add the new SIEM correlation rule. Set up additional log checks. Whitelist or allow list known safe systems. Run test queries. Create an incident response workflow. And consider adding more rules. That's incredible, right? It just gave you a quick punch list and told you exactly what to do. And there you have it. You've just triaged and investigated SOC alerts using Gen AI, and now you have your next steps.
So, what I hope that you took away from this lesson is to use cleaned and prepped alert data to set Gen AI up for success. Structure prompts using the RACE framework to guide logical analysis. Ask for results in clear, structured formats for speed and ease of use. Adjust prompts based on alert types for more accurate outcomes. And stack prompts to evolve from triage to investigation and prevention. And don't be afraid to ask ad hoc follow-up questions. So, remember, you're not just feeding Gen AI your alerts, you're giving it a mission. When you prompt it clearly, consistently, and with purpose, you turn Gen AI into a powerful security assistant that's right by your side. Now, in the next lesson, I'll show you how to validate AI-generated triage results, filter out false positives, and build trust in your AI workflow without losing your analyst edge. So, let's keep going. You're doing some amazing work here, and I'll see you in the next lesson.
Have you ever been handed an output from Gen AI and felt that pit in your stomach say, "Something's not right here"? That's the feeling that you need to listen to. This is the crossroads that every security professional hits when they start using Gen AI for anything, to include triage. Here's the truth about it. Even the best AI outputs are only as good as your review process. If you don't validate what it says, you're not augmenting your decision-making; you're gambling with it. So, in this lesson, you're going to learn how to turn Gen AI from a high-speed guesser into a trusted triage co-pilot that you can stand behind. And by the end of this lesson, you'll be able to cross-check Gen AI outputs against raw data and contextual knowledge. You'll be able to identify hallucinations or overreach before they cause serious damage. And you'll also be able to use your professional judgment to finalize triage outcomes and translate validated outputs into case notes, playbooks, and updates for stakeholders. Using Gen AI without validation is just automation, and that's dangerous. But using Gen AI with validation is real augmentation, and that's responsible. And in all my experience working with Gen AI, here is something that I see in different types of industries, not just cybersecurity. I see people ask, "Gen AI is pretty smart. Can't I just trust what it says?" And the answer is no. You can't. And here's why. Gen AI is great at recognizing patterns, but it doesn't know your environment. It doesn't understand the difference between a vulnerability scanner and a real attacker. It doesn't know your playbooks, your asset criticality, or your SOC's false positive history. So, it can hallucinate. It can misinterpret logs, and it can miss key signals. And remember, you are responsible for the output from Gen AI. So, picture this. Gen AI says this alert is lateral movement and the severity is high, but the source IP is actually your vulnerability scanner. So, if you act on that, you've misused time, escalated incorrectly, and maybe even shut down a legitimate scan. Do that a few times, and trust in Gen AI will break down. You're burned out all over again and back to square one. So, let's fix that with a repeatable, easy-to-follow validation process.
Now, before we jump into the prompts, let's set one ground rule that we always talk about. Never paste raw logs with sensitive data into a Gen AI tool. That means no real IP addresses, usernames, or asset names. Remember to use those placeholders like user A, internal IP1, and critical asset 2. And make sure that you tell AI that that data has been redacted. So, we can add a line to our prompts to do that. That way, you can still analyze the structure, the logic, and reasoning without leaking any sensitive data. So, now let's walk through the four-step validation framework. So, I'll show you the prompt, but more importantly, I'll explain what to look for, why it matters, and how to interpret Gen AI's output.
So, step one is to cross-check with raw data. Start by verifying that Gen AI's summary actually reflects the underlying logs. Is what it says consistent with what really happened? So, look at things like the redacted IP addresses, timestamps, the commands, redacted usernames, and so on. So, here's how we're going to do this. From the previous lesson, we had a report from the Suricata alerts, if you recall, and it came up with all these different findings and so on. So, I'm going to paste those results in. And then what I'm going to do, I'm going to hold down Shift and Enter to create some space. First, I'm going to grab the summary report that we created from the previous lesson. And I just went to the other chat, copied this out of that, and pasted it in here. So, you can see that the report's there. Then, I'm going to go to my prompt library and copy this prompt. "As a SOC analyst validating AI-generated alert conclusions, your task is to compare the AI summary with the raw logs provided." So, what I need to do is go to my artifacts and upload that Suricata IDPS logs that we used in the previous chat as well. So, now you can see I have my prompt, and you can see right down here I have a note that this may include redacted placeholders such as internal IP1, user A, and so on. Respond using these placeholders if they are found. In our case, they're not going to be in here because this is simulated data. But if you're using real data, they should be, right? And then here is your summary report. Okay. So, now I'm going to go ahead and run this. And as you can see, it's already done its validation. If you scroll down a little bit and you see any mismatch between what Gen AI says and what the logs show, that is your first red flag. So far, everything looks pretty consistent, right? Discrepancies, no mismatches found between timestamps, IPs, or alert signatures.
Now, step two is to bring in what you only know, which is your environment or internal context. So, here's how we're going to do this. I'm going to use the chat that we were on from the previous lesson where we went ahead and summarized everything. We looked at SIEM rules and those kinds of things, if you recall. So, what I'm going to do is use all of this data that it's already given us, and I'm going to follow up with this prompt where we want to act like a SOC analyst validating AI-generated alert conclusions. And so, what we're going to do is compare the AI summary with the raw logs provided. And we're going to focus on confirming the accuracy. So, what I'm going to do is go back and I'm going to grab that Suricata file again, and I'm going to drop this in here so that we have the IDPS alert logs right here. So, now I'm going to run this command, and you can see that it's confirmed some details. Source IPs, timestamps, alert signatures, and more. No usernames are present in the raw logs, but the AI did not fabricate any usernames. That's a good thing. Internal correlation, placeholder fields, and more. This validated what we want to know. If we see a mismatch here, that's when you know there's a red flag.
So, now step two is that we want to bring in what only you know, which is the environment or the internal context. You want to think about, is this a noisy asset? Is this user tied to routine scan activity? Have you seen this alert pattern before? And things like that. So, what we can do is we can go in here and drop a prompt like this. "You are a SOC analyst familiar with our organization's environment. Review the AI-generated alert triage result. Cross-reference it against internal assets and so on." Now, one thing I want you to see here is "cross-reference against internal assets." So, what we need to do is go grab our IT asset inventory artifact and drop that in here. That's going to give Gen AI context to run this command. And also notice again that the data includes placeholders for sensitive information. Okay. So, now I'm going to run this. And now you can see here that the IT asset inventory list has been ingested. And now it's flagging some different assets. So, again, we have that 10.10.5.1.5 node, a 5.2.0, 5.2.1, and 5.2.2. These are issues. So, none of these IP addresses match the asset IP range found in the internal inventory. So, what that means is this suggests that the IPs may belong to a temporary test instance. Woah, that's really insightful. This might be coming from a test string or development environment and may not be part of our critical assets, or it could be a rogue machine that was just added to our network. So, here was our previous AI rating, and now based on internal context, it reduced it to a medium. And this line right here is critical. "Since no confirmed production machines are impacted, this reduces the immediate business risk." This is powerful for us. The goal here was to downgrade or upgrade the severity rating based on what you know that the model can't, which is the internal context of your organization.
Now, we want to look for signs that Gen AI might be overreaching or hallucinating here. So, step three is to check for those hallucinations. Some red flags might be bold claims with no evidence, conclusions that go beyond what the data supports, any vague or generic labels without log references, things like that. So, to do that, we would go over to our prompt library and copy this prompt. "Take on the role of a senior SOC analyst auditing AI reasoning. Review the AI's triage output and identify any conclusions that lack direct log evidence and determine whether AI has made assumptions or extrapolations not supported by raw data and so on." Okay. And then we want a summary stating the assessment at the end. So, we're going to run that. And now you can see real quick, "Below is the breakdown of AI conclusions compared to the raw log files. And this is verified. So, 10.10.5.1.5 is verified. The evidence of SSH brute force is partially verified. Eternal Blue is partially verified. Command and control is verified. HTTP POST is unverified. H okay. And then we have that multiple internal hosts are compromised or scanning simultaneously. That is partially verified. Then we have some assumptions and extrapolations that an act of compromise based on Eternal Blue attempt, which logs only categorize as attempted administrator privilege gain." Okay, extrapolation means to predict or infer or basically kind of guess. So, we're taking a guess that there's an active compromise or we're predicting that there's an active compromise based on this vulnerability. And then "Trustworthiness of AI assessment." Here's some strengths, some weaknesses that AI sometimes escalates suspicion. And then confidence level is now moderate, right? 7.5 to 10. Now, if you see confident claims like "This is malware" or "A user is compromised" without any specific evidence or indicators, that's when we want to stop and investigate further.
So, what we can do is follow up with a prompt like this. "Based on your initial assessment, list the specific log lines or indicators that support each of your major conclusions. If no specific evidence is present, explain what additional data would be needed to confirm or refute your conclusion." So, now we're making AI defend itself. And so, now it's going to give you some support. And see, you can see some support coming straight from the logs. Here's a line in the logs that it's basing its decision on. So, we can go back to the logs and confirm that. Here's another line from a log that supports the SSH conclusion. The Eternal Blue exploit, and there's a line that justifies that the command and control beaconing, HTTP POST, and the lateral movement as well. So, now "user compromise" is there's none provided in the logs, and so we don't have any kind of user compromise at this point. And if we want to go forward with that, we need authentication logs, whether it's from Entra ID, SAML, Okta, OAuth, and so on, or we provide some other authentication logs. So, this prompt encourages AI to justify its claims using traceable data, identifying any gaps, and re-calibrating its confidence levels. And these are all critical skills for real-world SOC validation.
So, finally, in step four, let's push back a little on anything that doesn't seem right. We want to ask AI to explain why it rated an alert a certain way, or ask it what might be missing, or ask for an alternate interpretation. So, here's an example of a prompt that you might ask. "Please analyze the rationale Gen AI provides for classifying this alert as high severity. I'm going to change that to these or any any alerts as high severity. For each conclusion, list the supporting evidence found in the logs and so on." Okay. So, let's run that. So, if there's any high severity logs that we found, we want some justification as why. So, here you go. The C2 beaconing was high. Why? Because communication with no malicious domains strongly suggests active compromise or malware infection. Beaconing activity also indicates command and control. So, that's pretty severe. So, that's why I rated it, and that's why it's telling us that. So, if we want to dig further, we need to go get some additional data like network packet captures or PCAPs and input that as information for AI to go through. Or if we want to add some EDR logs, we can do that, and we have an artifact for that. So, if we want to go further, we can drag that artifact in and test that theory. Okay, but for the sake of this lesson, I'm going to keep moving. So, also the Eternal Blue was high, and it explains why. The SSH was high, and it explains why, and so on. So, if we don't agree with any of these, we can push back even more. And so, now you have a summary of the findings. So, "Strongly supported" is high severity. So, this means that AI believes it has enough data to justify this. And then "Partially supported" are these three. So, one other thing we can follow up with is to follow up with an alternative explanation. So, "Please provide an alternate explanation for the activity and then reassess the severity rating if necessary." So, let's see what it says now. So, now it's going to go back through, and now it has an alternate explanation as what might be going on, and it still doesn't agree. It likes high. So, this is a serious thing that we need to look at. This command and control vulnerability is our top priority. Now, the Eternal Blue, it's medium-high. So, it adjusted it down a little bit. The potential SSH, it adjusted it down based on the context and the alternative explanation. And same with the suspicious HTTP POST, the Nmap scanning activity. All of these got moved down based on an alternate theory that might be going on. So, how amazing is that, right? And then it gave you a little summary table to show you exactly what's going on. So, again, this is definitely our top priority right here. And all in a matter of seconds, you have this information at your fingertips.
Now, once you've validated the AI's assessment, the next step is to operationalize this. So, let's map our results to the MITRE ATT&CK framework and our own internal playbooks. By aligning observed activity with known tactics and techniques, you strengthen the quality of your alerts and your threat intelligence while helping other teams improve in detection coverage. So, a prompt that we can use for that is something like this where we want to use "Validated triage output below or attached. I'll say above in this case because we're not pasting it. Please map observed behavior to relevant MITRE ATT&CK tactics and techniques." And so, we're going to run that. And so, now it's going to come back and it's going to show the exact IDs that we need for MITRE ATT&CK. So, you can see that there's a tactic is Reconnaissance, the technique is Scanning, and the sub-technique is Scanning IP Blocks. And it will go through all of them and give you all of this information. Now, this is incredible right here because this makes our job 10 times easier. And then here's a playbook update that we can add to our incident response playbook or even if we needed to create a new one.
Now, that's amazing. Now, let's translate this into ticketing or case notes. Every triage result that's been validated needs to be logged for continuity and traceability. Whether it's your SIEM or SOAR platform or even just a shared document, a clear, complete ticket helps everyone from analysts picking up the queue to managers doing the incident reviews. Now, these notes should summarize what happened, how it was validated, and what action was taken. So, here is a prompt that will help you do that. "You are writing an incident ticket for SOC case management. Use the confirmed AI triage findings. Generate a structured summary that includes the threat type and so on and ensure that it's concise and suitable for both technical review and managerial audit." So, that covers both bases. Now, we'll run that, and as you can see, it just created an incident ticket for us. Threat type, severity, affected users, current status. Now, right here in "Actions Taken," we would want to confirm that this work has been done or update it to reflect it. So, in this case, maybe these are the steps we want to take, and maybe host containment is done, but network controls is in progress, threat hunting is in progress, and so on. And then our current status is that it's ongoing. So, again, these haven't been done, so there's a little confliction here with what AI is suggesting. So, now we know we have the data, and we can just change it to meet our needs. And if we need to transition this case to the next shift lead in the SOC, here is a prompt that we can do that. "Write a four to five sentence summary of the validated threat activity, including context, what's been done, and what's needed next." And so, again, we would want to update the actions taken to be consistent. So, in that case, we could say right here in the action steps, "Step one and two have been completed," and that's it. And now we know steps one and two are done, but three through the remaining steps are not. So, here you go. "We detected unusual network activity from several internal systems, including scanning behavior, so on and so forth." And there you have it. There's your summary. And you can hand this right off. You can even turn this into a bullet list, a table, whatever you want. You can say, "Please summarize this in a bullet list." And now it'll take that information and make it super simple. Right. "Step one, affected systems have been quarantined. Firewall rules have been updated. No confirmed data loss. Next actions are to review endpoint and DNS logs and provide ongoing updates to management." Like, this is incredible, right?
So, remember that throughout this entire process, you are the decision engine, not Gen AI. Always keep logs of prompts and responses. Redact or sanitize sensitive inputs. Validate all conclusions before actions and ask, "Does this make sense based on what I know?" Blind trust is not security. Disciplined validation is.
So, here's what I want you to take away from this lesson. Remember that Gen AI can hallucinate. Always validate before action. Follow the four-part checklist. Cross-check your raw logs. Apply internal context. Flag vague or unsupported claims. Use follow-up prompts to verify reasoning. And then operationalize your results by mapping to MITRE. Populate case notes and communicate clearly for handoffs and updates. Also, create workflows, save your prompts, and build that habit. Remember, you are the analyst. AI is your assistant. And now that you've learned how to validate and act on Gen AI triage, it's time to go even deeper. In the next lesson, we're going to recap everything you learned in this section. And in the next section, I'm going to show you how to use AI to break down complex threat intelligence and turn it into clear, actionable insight in minutes. Triage is just the beginning, and strategy lives in intelligence. So, I'll see you in the next lesson, and let's keep building.
If you ever felt like alert fatigue is just part of the job, or like you're always reacting and never getting ahead, this section showed you how to reclaim your time, reduce burnout, and still respond faster than ever, all by making Gen AI your smartest teammate. And the lessons all throughout this section proved exactly that. And now we get to tie it all together. In this section recap, we're bringing everything home from our deep dive into using Gen AI to triage alerts. We're going to zoom out a little bit, look at the big picture, and make sure that you walk away with some practical, repeatable processes, and you'll see how all the puzzle pieces fit, from preparing data to prompting to validating AI output like a pro. You'll even get a hands-on challenge to apply what you've learned. And by the end of this, you'll not only understand how, but you'll be ready to do it on the job starting today.
Now, let's go back to the start of this section. Modern SOCs are flooded with alerts, hundreds or even thousands a day, depending on where you work. Most of them false positives, but some of them are potentially devastating. And that's the trap. When everything screams urgent, your brain stops and it starts listening. You start defaulting to dismissal or even worse, burnout. And here's the kicker. Real threats don't yell, they whisper. They blend in with all the noise. And without help, they slip through the cracks. So, how did we fix this? You don't need more hands. You need one brilliant assistant who never gets tired. And that's where Gen AI comes in. But only if you use it right. So, let's walk through the playbook that we've built all throughout this section.
First, you learned the importance of prepping your alert data. Raw logs, no context. That's like handing a map to someone blindfolded. That's not good. You learned how to chunk up the data to ensure that Gen AI gets exactly what it needs. You also learned which alert types play best with Gen AI, like Suricata events, SIEM summaries, and even XDR or EDR logs. And most importantly, you learned how to clean that data, removing sensitive information and replacing it with placeholders.
Next, you learned the magic of good prompting. Not vague, not lazy, not just, "Hey, what's wrong with this?" But real quality prompting. So instead of saying, "Please analyze this alert," you learned prompts like this. You went from generic to expert in one sentence. Then you learned how to customize prompts by alert type. You use prompts like this for brute login. And for lateral movement, you use prompts like to review normal traffic for potential lateral movement, analyze host-to-host communications, and more.
Next, we talked about validation. Because Gen AI isn't infallible. It hallucinates. It makes mistakes, and it assumes at times. That's why we worked on prompts like this where we had AI validate itself to make sure that the alert analysis was correct. You even learned how to operationalize the results and turn them into MITRE mappings, case summaries, and handoff notes. All using the same principles: structured prompts, contextual logic, and human judgment layered on top. And through it all, you weren't just feeding data into Gen AI; you were training it to think like a real analyst.
Now, let's put everything into practice using a real scenario. Let's say it's Monday, and you just started your shift. Your queue lights up with alerts from your SIEM. One has a repeated outbound connection, another failed login attempt at 2:00 in the morning, and you even suspect some beaconing behavior. And so, here's what I want you to do. You're going to start with this prompt. "You are a SOC analyst reviewing potential network threats. Analyze the attached alerts, identify any repeated patterns or indicators of beaconing such as regular intervals, new external IPs, and other things. And then also note that there is some sensitive data and that might have some placeholders like internal IP1." So, I'm going to go over to my artifacts and I'm going to drop that Suricata IDPS log in here so that we can analyze that. And just like that, it's already analyzed that, and you have some alerts. So, here's some observed patterns. There's regular activity from internal IP1, which is what we're going to call 10.10.5.1.5 and so on. There's a potential exploit activity. And notice that it's assigning placeholders to the IP addresses, which is interesting, and that's what AI will do. So, it's making an assumption and giving you a mapping, which really doesn't help because the IP addresses are already there, right? Let's keep moving forward. Suspicious external communication, an outbound. Oh, that looks like mail SMTP that's leaving on port 25, which is unsecure. That's a problem for us, right? And then there's indicators of beaconing. So, this shows rapid outbound connections at intervals of 40 to 60 seconds. That's something to take a look at. And then it gave us severity levels. So, the high severity are the indicators of compromise that's happening on this IP. Eternal Blue, like we talked about in an earlier lesson, and also brute force SSH that we talked about in a previous lesson. There's some medium severity and low severity. And then of course, it gives us some recommended actions, and that's awesome.
So, what we want to do next is I'm going to go into my prompt library and I'm going to grab a prompt so that we can validate that output. "As a SOC analyst verifying an AI-generated summary, cross-check the output with the original logs provided." So, if you remember from a previous lesson, we want to confirm whether AI's conclusions about timing, frequency, and suspicious behavior match the raw data. So, we're going to have AI double-check itself here. So, we run that. And in a matter of seconds, we can see that it's verifying itself. Here's the claim. Here's the log check, and the timestamps are correct. And then we just keep going down. Look at the claim, the check, and the findings. Suspicious behavior assessments are accurate. So far, AI is checking out. So, we'll review this whole output and determine if there's anything we need to pay attention to. And right off the top here, I'm not seeing anything, but I would do a deeper dive just to make sure. But for the sake of this lesson, let's keep moving forward.
Then what I taught you in this section was how to operationalize this. So, to map everything back to the MITRE ATT&CK framework. So, we're going to "Validate alert findings for MITRE ATT&CK." And so, we're going to run that. And as you can see, now we have the mappings. So, we can see clearly what the IDs are for MITRE ATT&CK. So, if we wanted to go over to the MITRE ATT&CK framework, we can look at Command and Control C2 and see what that means for us. Also, there's some other things going on here. And you can see some more for Eternal Blue. Also, SSH brute force, and so on. So, it mapped everything out for us just like that. And if I scroll down a little bit more, there you go. And so, we don't really have a table or anything that makes it clear. So, we can ask ChatGPT to summarize this for us. And there you go. And in just a few seconds, it's going to create a table for us so that we can clearly see what's going on. And just like that, here is our table. And so, now we can see that we have the beaconing attack and some concerns, and that's related to Command and Control. Here's the technique. Here's the detection. And it did that for every single finding here. And we can scroll over a little bit and go back up. So, you can see if you have a playbook, you want to add something new to your incident response playbook. And we can even ask it for Splunk rules, Suricata rules, and so on. That's how powerful all of this is. So, if you do this, you would have walked through the entire Gen AI triage process from confusion to clarity. And you did it without burning out. Look how simple that was.
And once you've validated the Gen AI's output and turned it into a structured summary, we don't want to stop there. We want to drop that analysis into some real-world tools. That could mean pasting it in a Jira ticket for the incident response team, or logging it in The Hive as part of a case file, or adding it directly into Splunk or Sentinel workflows. The point is, Gen AI doesn't just help you analyze; it helps you deliver, discover, document, and deploy. So, think of it like an instant teammate that speaks SOC language and works across your whole stack.
Now, here's a quick recap from this entire section. Gen AI won't save you unless you feed it clean, focused alert data. Make sure that you use the RACE framework: Role, Action, Context, and Expected Output for every prompt. Follow-up prompts are okay. You don't have to follow RACE, but for the initial prompts, you always want to use RACE. And we want to validate like a pro. We want to compare AI summaries with logs, add internal context, and flag any hallucinations that we see. We also want to format everything so that we can take action. We want to turn results into tables, bullet points, or ticket notes, like I showed you all throughout this section. You're not just getting help anymore. You're leveling up your speed, your accuracy, and your impact. And that's the secret behind Gen AI. That's not automation. That's augmentation. So, you're not outsourcing your brain; you're amplifying it. And this is just the start.
In the next section, we're going to take things to the next level. We're going to learn how to break down threat intelligence reports using Gen AI, turning pages of indicators and narratives into immediate insight and action. So, it's time to go from responding to strategizing. So, let's build your next skill set, and I'll see you there.
Imagine this. It's 4:57 p.m. You've got two tabs open: a 17-page threat report from CISA, and your ticketing queue. Your team's waiting on shift turnover. Your manager's pinging you for a summary, and your brain is fried from the day. You don't have time to read the whole report, extract key intelligence, and write it in plain language, and even log it into a ticket before you walk out the door. But what if Gen AI could do 80% of that for you in seconds? It can. In this lesson, I'm going to teach you how Gen AI can be your personal threat report translator. That means it can summarize long technical PDFs into usable, structured briefs. It can create quick-turn summaries for Slack, Jira, or leadership updates. It can tailor the tone and depth depending on the audience. It can safeguard sensitive data before feeding reports into public LLMs and iterate on prompts when the results aren't quite right. This is more than just speeding up your workflow. It's about turning information into intelligence at the speed operations demand.
Now, let's be honest. Threat reports are not written for analysts who are under pressure. They're written for marketing, legal, executives, and sometimes analysts all at once. That means that key intelligence is buried inside bloated paragraphs. MITRE mappings and IoCs are mixed with corporate fluff. There's no consistent structure, and you lose time translating what matters from what doesn't. Now, this slows down incident response briefings. It adds friction to ticketing, and even worse, it creates blind spots in your situational awareness. So, let's train Gen AI to do the heavy lifting for you. But not with just a single copy-paste prompt. I'm going to train you to think and operate like a prompt engineer for cyber intelligence.
So, step one, as with anything, is to sanitize your input. Before you paste anything into ChatGPT or Claude, you want to sanitize the content. Even if you trust your AI platform, you still want to treat it like a public-facing system, unless it's fully private and secured. So, we want to use a redaction tool or even like Notepad++ to replace real host names, to mask any IP addresses, and remove usernames, ticket numbers, credentials, and so on. One other thing to take note of is replacing directory or folder locations as well. After you've done that, your input is now safe to drop into Gen AI. Just be sure to follow your organization's policy on data sharing and data privacy. Okay.
Now, step two is to start with a role-based summary prompt. So, this time I'm going to use Claude to demonstrate this lesson. So, what we're going to do is we're going to go over to our prompt library and we're going to use this first prompt. "You're a cyber security threat analyst, preparing a briefing based on a threat report. Review the report and summarize its findings. Focus on the identified threat actor, targeted sources, and more. And then output in clean markdown, which means headings and clean formatting for easy sharing with the SOC or leadership teams." So, what you're also going to want to do is go over to your artifact pack and grab the threat report. Now, Claude has loaded it, and so now we're ready to execute this. So, it just takes a few seconds here, and Claude is generating this artifact for us. Just like that, you've got MITRE ATT&CK IDs, indicators of compromise. Let me scroll back to the top for you. Here's an executive summary, a threat actor profile, targeted assets and sectors. Looks like they're after a DevOps server right here with Jenkins. Interesting. Now you have all your MITRE ATT&CK framework. You have your IDs, your indicators of compromise, timeline of events, which is definitely helpful. Wow, this is amazing. Containment actions, impact assessment, and so much more. Even recommended next steps, strategic improvements, monitoring. This is an incredible report.
So, let me try ChatGPT with the same thing so we can compare the difference real quick. So, I'll do the same thing. Drag that report in, and I'll execute that. And as you can see, here's a summarized report. And notice how it didn't include an executive summary. It just jumped right into threat actor, targeted sectors, and so on. So, in my opinion, I think Claude did a way better job. That's why sometimes it's good to have multiple tools so you can get the output you want. Now, I would demonstrate this in Perplexity, but you need a paid account in order to upload data. So, I won't test this in Perplexity, but you can see the difference where Claude was clearly light years beyond in terms of the report that it put together. So, let's stick with Claude going forward and let's see what we get. Okay.
So, step three is to adapt the prompt for different outputs. So, we'll use the summary report as our input. So, we can either create a document from the report or just paste it into the prompt. In this case, we're just going to continue the conversation. So, now what I'm going to do is grab this prompt. "You are a cyber security analyst preparing a summary for non-technical leadership. Please review the following threat report and provide a high-level overview. Who's affected? What's the threat? And so on." And so, now we'll run that. And so, now it's drafting the artifact for us. And so, now here's your executive security briefing. What happened? Who was affected? And really, what was affected, right? But still, who was affected, the impact, immediate actions, bottom line. Okay. And boom, just like that, it gives us a quick summary with the exact language that an executive needs to know. But what if we wanted a concise technical output for a SOC case or a ticket update? Well, we can use this prompt from our prompt library. "As a SOC analyst, summarize the threat report in three to five bullets for use in a ticketing system focused on observed IoCs, indicators of compromise, attack behavior, and the required responses and no fluff." So, then we fire that off, and now it's creating that artifact for us. So, here's your summary. Here's your IoCs, and you can see just how the format is so different. Here's your attacker behavior, containment complete, and outstanding actions. Just like that. And now we can review the output and add that to our case or our ticket. Or if we wanted to, we could post a message on Slack, Microsoft Teams, or any other collaborative platform. To do that, let me close that out, and we'll use this prompt. "Please summarize the following threat report for an internal SOC update. Formatted for quick reading in Slack, actor name, impacts, and so on. And use headings or bullet points." So, we're going to do that. And it knows exactly what we want and what we're looking for. And here you go. And it's even got emojis for us and everything. This is perfect for posting. So, if we have a Slack channel for incident response, or we have a Slack channel that's shared amongst our SOC or our engineering team, we can drop this in and start getting to work right away. Just look at the results we got from one single input. We created three very different outputs. And now you're not just copy-pasting, you're controlling the output by design. And that's how you use Gen AI to augment your work. Give each of these a try or change some things around and make them your own.
Now, what if Gen AI goes off the rails on us? Sometimes the output will miss a key indicator of compromise or IOC. It'll hallucinate actors or other details, and it might include vague language like "sophisticated malware" or something like that. What happens then? Well, in that case, we can close that out and we can use this prompt. "Please analyze and revise this summary to remove any vague terms like 'sophisticated.' Only include specific IoCs that are mentioned in the report." And so, if there are any, it'll find something. And then it says, "I can see it's already quite specific and doesn't contain vague terms like 'sophisticated.' The IoCs are all directly from the original report. So, we don't have any vague terminology in here." We can just copy and paste this into our tickets, into our Slack channel, and so on, and we're good. And here's something else that's really neat. Way up at the top when we first started, I don't remember if I asked about MITRE ATT&CK techniques. Do you? I don't think I did, but I might have. But here's the great thing about Gen AI. It knows what you're asking. It knows how to interpret what you're asking. We might say right here that you missed the MITRE ATT&CK techniques, but it knows that's what we're asking for. So, it's going to go ahead and infer this is what you want. I'm going to give that to you. So, now it's just going to list out all of the TTPs, which are tactics, techniques, and procedures from MITRE, and it gives you your MITRE IDs all right here. Wow, this is amazing. Key indicators, all of that stuff, just like that. Or if you don't like that output, you can prompt it to recreate the response with your desired output. You can ask it to restructure the summary using a template or whatever you prefer. The key is to treat Gen AI like a junior analyst that you're training. Don't accept the first draft. Ask for more information. Update what you don't like and repeat this until the output is solid and what you want.
Okay. Now, let's put all of this into action. Let's say that you just received the following threat report in your weekly threat intelligence feed. I'm going to open up a new prompt and I'm going to paste that in here. So, this is the feed that you received. What I'm going to ask Claude to do is save this. "Please save this to memory." And actually, I'm going to add this threat report to memory. Okay. So, it's going to
save that. So, one thing that you do need to know is that it doesn't have persistent memory. It's only going to be temporary.
So, what we're going to do now is we're going to follow up with a prompt. And notice how all of this data here is unstructured. We can't work with this, right? And we don't have time to rewrite it, clean it up, or even turn it into something that we can use in a briefing.
So, what we're going to do is we posted this into Claude and we asked it to save it. So, what I'm going to do now is follow up with a prompt and ask it to do something with it. So, I'm going to say, "You are a cyber security threat analyst preparing a briefing based on a threat report. Please review the report below and I'm going to say above in this case because I got this from my prompt library. So I'll change this the report above and summarize its key findings. You can also say report I asked you to save to memory and summarize its key findings." And so now when I hit send, it's going to go ahead and analyze that threat report and give me exactly what I want, which is an output in clean markdown for easy sharing with SOCK or with my leadership team. And so just like that, you have your briefing. Here's your executive summary, your threat actor profile, your attack chain analysis, which is amazing. Again, I don't see any MITER attack IDs in here. Oh, there they are. Cool. So miter attacks in here with the mapping, the risk assessment, all of it. Look how powerful that is. Now you've got a sock ready copy paste summary for incident ticketing, team Slack briefing, executive summary, and even a threat intelligence wiki if that's what you have. And most importantly, you didn't waste 15 minutes rewriting it. This took seconds. Plus, like we discussed earlier, you can also prompt it to summarize this report for your manager. Rewrite anything if Gen AI includes hallucinated or vague information. We can also drop the outputs into your red team wiki for shared context. That's what Gen AI does best when you prompt it. Right now, you're not just using Gen AI. You're operationalizing it like a pro.
Okay. Now, here's what I want you to walk away with from this lesson. Jinai can summarize threat reports in seconds just like you saw, but only if you prompt it with precision. You want to make sure that you stick to the race framework, role, action, context, and execution. We also want to tailor outputs by audience, executives, sock, wiki, ticketing, case management, and more. We want to redact your input before using public LLMs. That's always important. And also when you find good prompts that work, be sure to save and reuse your best prompts with clipboard tools or your prompt library. And also iterate when results fall short. Train AI like a junior analyst. Meaning ask it more questions. And make this a repeatable part of your threat intelligence workflow. Summarizing threat reports isn't just about speed. It's about clarity when you need it most. You've now got the tools to do that along with the prompts and the mindset. And this will help you turn dense PDFs into clean, actionable briefs. In the next lesson, we're going even deeper. You're going to learn how to extract IoC's and TTPs that are hiding inside those reports and turn them into operational threat hunting fuel. So, I'll see you there.
Here's a situation that you've probably faced. You're handed a long, detailed threat report with dense paragraphs, no structure, and your job is to find every IP address, domain, suspicious URL, and file hash that's buried in the text. And you need to do it fast, and that's tedious. It's errorprone, and it can waste a lot of time during an active incident. So now imagine this instead. You paste your report in Ginai and boom, it pulls out all of the IoC's, your behavioral patterns and organizes them into structured tables and even maps them to MITER attack techniques all in seconds. Now, this isn't the future. This is what you're going to learn in this lesson. We're going hands-on with one of the most valuable ways that Gin AI can augment your cyber security workflow, and that's extracting IoC's and TTPs automatically. And by the end of the lesson, you'll be able to identify the key indicators and behaviors to extract from threat reports. You'll be able to use proven prompt strategies to get clean, structured output from Genai. You'll also be able to format the results for enrichment, hunting, or even sharing. You'll also be able to instantly find indicators from raw paragraphs using Genai. And all of these skills will change how fast and how well you operate in threat intelligence.
Threat reports are usually written in a certain format, right? They're human readable, but they're not machine ready. And here's what that means for you. A report might describe the command and control domain like this. Or it might mention a file hash like this. And none of that is in IOC feed or ready for your SIM. And here's the issue with that. You can't afford to miss any of it. You need every IOC and TTP ready to use right now. And that's where JAI becomes a gamecher. So let's walk through the complete solution from understanding what to extract to formatting the output in usable formats. Now the first step before we prompt anything is to know what we're looking for and that's indicators of compromise or IOC's. These are like digital fingerprints that are left behind by attackers. They're the data points that we can use to recognize malicious activity inside of our environment. whether it's a rogue IP address trying to connect to your server or a file hash that matches a known piece of malware. So things like IP addresses, whether it's version four or six, these can help us pinpoint the source of suspicious traffic. Domains. Attackers often obuscate these to avoid detection. So they use formats like example.com to trick automated filters. URLs. These are full links that often contain a delivery path for malware or fishing payloads. File hashes. Think of these like unique digital signatures for files. If a files hash matches a known malicious sample in a threat intelligence feed, then you can quickly confirm it's malicious without even having to open or execute it. We also need TTPs, tactics, techniques, and procedures, which includes things like behavioral patterns, tools or malware families, and also MITER mappings as well. So, think of IoC's as the what, and TTPs as the how. They're often the first clue that something bad is happening or is about to happen. So by identifying and acting on IoC's, you can isolate affected systems, update detection rules, and prevent any intrusion from escalating into a full-blown breach.
So the next step is to input sanitized or redacted data into Genai. Remember, we want to remove any IP addresses, usernames, or any kind of PII to ensure that we are not compromising any sensitive data in the organization. The next step is to extract the IOC's first. So, I'm going to go to my prompt library and I'm going to paste this prompt. And then I'm going to grab the threat report sample and upload that. And then we'll go ahead and let Claude do its thing. And as you can see, it's already done analyzing. And so now it's got some indicators of compromise. You can see that there's a threat group. It's AP41. threat sector is manufacturing, the region is Southeast Asia and so on. And you can see the initial vector which is supply chain compromise. That's really helpful. You've got a lot of great information here. And there's even some mappings to minor attack. Now, some things to take note of are what's missing, and those are things like there's no IP addresses that are present. There's no domain names, URLs, hashes, or anything. So, we have a little bit of data to go with and then there's some recommendations in terms of what we need to do next.
So, the next step is to extract the TTPs. So, I'm going to grab this prompt and we're going to go ahead and extract the TTPs and map them to MITER attack framework. So, we'll let Claw do its thing here. And as you can see, it's going to go ahead and map all of that out for us. Here's your tactic, your initial access, your technique, which is supply chain compromise, and then you have a description and some evidence in where it found it in the report. So, you can see that we have a pretty good profile already built. And of course, there's some discrepancies that were noted. The report lists MITER ID T1050, which appears to be outdated or incorrect. And then it shows us what it was replaced with. So, what we need to do is cross-check that. Maybe there was an error in the report. So, we'll go ahead and chase that down. Now, these two prompts right here will cover 80% of your use cases. And you want to save these into your prompt library. And that way, you can reference them whenever you need them.
Now, step three is to format the output for real world use. Genai can turn these results into formats that are tailored for your specific need. We can either create structured tables. We can create JSON output. We can also create paste ready blocks that we can use for our incident response tickets, Slack channels, and email. So, for example, let's say you want a markdown table. So, I'm going to go to my prompt library and I'm going to grab this prompt where I want to take the extracted thread intelligence, specifically the IOC's and TTPs, and reformat it for use. And so, we'll go ahead and run that. And then it will go ahead and create this table for us. As you can see, here is the table. So, let me drag this over a little bit. And so, let me scroll up so you can see. And again, it put it into pretty much the same format we had before, but this is more specific. So, now we have our TTPs. We have all of our information right here. We have some malware and infrastructure things to take note of. And then there's also a JSON output if we need it as well. Then if we want to go ahead and use it for a ticket or a chat update, here is the text that we can copy and paste. And then also it created a cool hunting checklist where maybe we want to deploy some detection rules. We want to review the supply chain security controls for sure. And then we can assign it to a sock team lead or whoever we want to assign that to.
And just to drive this point home a little further, let me show you a real world demo of all of these prompts. So I'm going to go to my workbook and I'm going to copy this prompt. And this is just an output from a threat report. Okay. So we have that. So now what we're going to do is I'm going to hold shift. I'm going to hit enter a couple times to create some space. And then I'm going to drop that OC prompt right here. And I wanted to go ahead and review the following threat report and extract all IoC's and classify them by type like domain, URLs, and so on. So I'm going to go ahead and run that and it will give us a table that looks something like this. So as you can see, it started to go ahead and create the campaign overview. It talks about the AP, the attack vector, and then it breaks down the hash. Here's the domains right here. Here's the URL that it found, the IP address, and so on. And here's some IOC summary for enrichment as well. Let me expand this a little bit so you can see it. Some detection signatures, some defanged indicators, hunting recommendations, and so on. Look how powerful that one prompt is. Just when you feed it the data that it needs and prompt it the right way.
Okay, so that was pretty cool. Now, let's go ahead and extract the TTPs. So, now I'm going to drop that TTP prompt in here, and I'm going to ask it to map everything to MITER attack. And then I'm going to run this and we're going to get back something similar to what we did earlier, but this is going to be specific to that particular threat report for a Zebra. And as you can see, it's starting to create it right here. And you can see the mappings. So, initial access, execution, more execution, defense, evasion, command and control or C2. So, there's a lot and then there's some additional context as well right here where it talks about the delivery vector, the payload format and so on. Thread actor sophistication assessment. So, now we can look at the sophistication level here on the right of what the threat actor is capable of doing. So they're actually pretty good at social engineering according to this threat report and everything else is medium, but then command and control is a medium high. So that's something to take note of as well. Then there's some detection and hunting guidance for us, some defensive tactics, and also some attribution indicators and notes for any analytic work.
So as you can see, it did a pretty good job breaking all of this down for us. So this is pretty awesome, right? Do you see how this gives your team an immediate jump start on things? The value here isn't just speed. It's integration into a real workflow. This allows you to enrich IoC's in Virus Total or Threat Fox or any internal threat intel platforms. It also helps confirm if those IoC's have been observed in real attacks. It expands on their context like the geoloccation or the malware family. And it also helps you decide if they're benign, suspicious, or malicious. It can also help you feed TTPs into detection engineering backlogs. That way, you're improving coverage for known attack techniques without waiting for another incident to happen. It can also help you identify exposure points for purple team or even tabletop planning. This is one of the most effective ways to test and tune your defenses using real world threats and also using the MITER mappings to build your threat profile. This allows you to model threat behaviors, identify gaps, and prioritize your activities like EDR tuning or cloud policy updates or what have you.
Now, to do everything that I just explained, we can go to our prompt library and copy this prompt. As a security operations planner, take the following extracted IoC's and TTPs and recommend how they can be operationalized. Suggest specific enrichment steps using public intel platforms. Identify potential detection rule updates and highlight how your findings could inform red team exercises or threat modeling efforts. And then we want to structure our output with enrichment, detection, purple team planning, and threat modeling. So, I'm going to run that and it's going to take all of that data and put it together for us in another artifact. So, I'll scoot this over a little bit. And as you can see, here's some IoC enrichment. And then it's referencing all of the public intelligence platforms that it can find. So, you can see like virus total, passive total, domain tools, lots of things going on here. And I won't go through all of this, but you can see how rich all of this data is that's coming back. Here's your threat actor profile. Here's some detection engineering that we can do with our SIM or even our EDR or XDR. Here's our hostbased detection rules for our IDPS systems or even EDR. There's email security rules, hunting things, all kinds of stuff in here. And here's our purple team planning where it even broke down a red team exercise and designed it for phase one, which is initial access. And then here's your actions. Craft spear fishing emails. deploy macro lace documents. Simulate user interaction. And then here's your blue team focus on this side. And then here's your success criteria or your metric. How long did it take you to detect it? And was the user aware when they got maybe a spear fishing email? Things like that. I mean, how powerful is this? Right? Here's some atomic red team tests that you can do using MITER. Then there's also some purple team scenarios. This is loaded with really, really good advice to give us a great starting point to start looking at how to resolve that threat report. You have a structured categorized report directly usable for team briefings, sock handoffs, or even sprint planning documentation.
And here's a bonus tip. If you have multiple reports to process, you can also use document splitting like copy pasting by section or batch prompts with dividers like end of report one to speed up your day. Let me scroll down to the bottom here and I'll go ahead and close this out and I'm going to go to my prompt library and paste this. As a threat intel analyst, you are reviewing multiple threat reports for a security briefing. For each report, extract IOC's and TTPs and summarize the results in separate tables. Use markdown formatting and insert end of report between each section to maintain clarity across the inputs. And so I'm going to run that. And so what it's going to do is it's going to process everything that we've talked about here in this chat. Now, here is something interesting that I want you to see. I understand that you'd like me to analyze multiple threat reports and extract IoC's. However, I only see one threat report in our conversation, which is the AP Zebra report. Now, this is important for AI because this lets you know that it's not remembering what we talked about early on. So, what I'm going to have to do is drag that report back in here and then ask Claude to do this again. So, what I'm going to do is grab that threat report and say attached is the other threat report. And so now it will compare the threat report we just uploaded with AP Zebra and then it will go ahead and execute the prompt. So there you go. So now it's drafting up an artifact again. As you can see, it's churning through a lot. And I'm going to open this up so you can see it. So, as you can see, it started with a zebra and now it's doing its magic, finding IoC's, TTPs, and so on. Some key findings. And then, as you can see, there's the break, and now it has report two, which was the file that we uploaded. And that's a41. And it has the same thing report summary, the IOC's, the TTPs, the key findings, and an end of report. And it even provided a comparative analysis summary for us where we're looking at a Zebra here and a41 here, and it's comparing it. So, we're using this to make our next decision. And here is what Genai is recommending that we take care of AP Zebra IOC's that we do supply chain security review for APT41 and that we enhance email security posture. And if you scroll down a little bit more, here's our risk assessment. And now you can see clearly why I don't agree with the plan of action. Apt zebra is only mediumigh risk and AP41 is a high critical risk. So to me, what I would be focusing on what we can take care of first that's going to give us the biggest impact against these APS to prevent any future incidents.
Now I know we covered a lot and we covered a lot of prompts in this lesson, but here's what I want you to take away. IoC's include things like IP addresses, domains, URLs, and file hashes. And you want them structured and clean so that Gen AI can process them. TTPs describe the adversary behavior and they should map to MITER whenever possible. We also want to use the race formatted prompts for consistent AI output like you saw here. We want to match the format to the task. JSON for automation, markdown for documentation, raw blocks for tickets. We also want to validate before we act. AI is your augment and your accelerator. It is not your decision maker. And we also want to think beyond the extraction. We want to connect these outputs to threat hunting, detection, reporting, and response. Remember that Genai isn't just reading this for you. It's turning unstructured information into threat hunting fuel. The faster you can extract the IoC's and the TTPs, the faster you can defend your environment, and you can also help others do the same.
Now, next up, I'm going to teach you how to assess the relevance of threats to your specific organization so that you know what's noise and what's real. And you're getting sharper by the lesson. So, let's keep building on that. And I'll see you in the next lesson.
Picture this. You get a threat alert. The report says a nation state actor is exploiting a zero day against cloud identity providers. You take a look at it. Your boss looks at it. and you wonder, is this a fire drill or is this just noise or is this the real thing? The difference between reacting to everything and focusing on real threats is relevance. In this lesson, I'll show you how to use Gen AI to assess the relevance of threats to your specific environment and how to do it fast because context is everything. And Gen AI is now your assistant in sorting real threats from noise. In this lesson, you're going to learn how to determine if a threat really applies to you or not. And by the end of this lesson, you'll be able to frame a threat relevance question that Genai can answer effectively. You're going to use race formatted prompts to assess environmental fit. You're going to evaluate Gen AI responses for clarity, risk ratings, and suggested mitigations. You're also going to learn how to leverage both red team and blue team perspectives in your prompt logic. You're going to learn how to perform batch relevance assessments and organize those results into structured formats and also how to integrate Genai relevant insights into triage workflows and threat models.
Now, most threat reports are written for the industry. They are not written for your organization specifically. So, you might read that a threat actor targets cloud infrastructure in North America, but does that mean that you should act upon that? Too often, sock teams either ignore it because it doesn't mention their company name or they panic and escalate because it involves scary terms like zero day or nation state actor. Neither approach is strategic. What you need is a quick evidence-based answer to does this threat affect us? Yes, no, or maybe. That's where JAI can augment your decision-m for you. So let's walk through it step by step and let's learn how to use Genai for threat relevance assessments.
Now step one is to define your context. We want to start by listing your organization's highle attributes. So like what industry you're in like finance, government, healthcare, whatever. Then the tech stack, the cloud providers, your edr tools, your SAS platforms and more. geography, where your company is located, where it does business around the world, and also user behaviors. Are you remote heavy? Do you do a lot of bring your own device or BYOD? And so on. This gives Jen AI something to anchor its analysis to. Now, I've included an artifact for this, or you can input your organization's details if you want to. So, what I'm going to do is I'm going to grab the simulated threat context data, and I'm going to drop that in here. I'm going to go to my prompt library and I'm going to drop this prompt in. I'm also going to upload the threat report sample so that JAI has the threat report and the data to performance analysis and I'm going to ask it to review the following threat summary and evaluate whether it presents a risk to an organization operating in the finance sector that uses octa Google workspace and crowdstrike and consider the past targeting patterns technology compatibility industry alignment and so on. And then I'm going to go ahead and send it. And now chat GPT is going to go ahead and process this for us. And here is the overview. So now it has a41. It's looking at the threat sector which is manufacturing. Here's our risk evaluation right here that AP41 is a China linked threat actor known for espionage and financially motivated operations. So the report highlights manufacturing targets. It has historically targeted finance, healthcare, and technology sectors. Therefore, we could be impacted here. So let's scroll down a little bit more. Technology compatibility, it's looking at Octa, Google Workspace, and Crowd Strike. Some past targeting patterns for us. The risk rating is medium. So it is something to consider. While the current intelligence suggests that manufacturing is the primary focus, AP's history could escalate our risk here. So, we want to take a look at that. Supply chain is also another concern. And here's some mitigations that we asked for with supply chain risk management, advanced threat hunting, cloud security hardening, incident response preparedness, and so on.
Now, that's pretty cool. Now, step three here is that we want to interpret the output. A strong AI response should include things like the risk rating that you saw, the justification, and suggested mitigations. And this is what we're going to use to drive our triage decisionm. And we can also create tags in our threat management system like relevant to act now, possibly relevant, which is something we monitor, or not relevant, which is we log and we move on. So, I'm going to go to my prompt library and copy this prompt. As a cyber threat analyst, evaluate the relevance of the threat analysis above for a healthcare organization using AWS, Microsoft 365, and CrowdStrike. And then provide a table with threat name, tech match, industry relevance, and more plus a final risk rating. And that's what we want to see here. So, we're going to run that. And here's a tailored evaluation where it's breaking everything down. So you can see that there's a high tech match. So you have high under tech match. Industry relevance is high. And then TTP over here is medium. And I'll scroll over so you can see that. And so it lists some minor attack techniques. There's your ID right there. And then here's your risk rating as well. High. So this is definitely a concern for us. Here's some other analysis. Here's some TTP overlap. And then here is your final risk rating. And now it's high. So earlier it was medium, now it's high. So this definitely gives us some cause for concern. But do you see how this turned what used to be some manual grind of going through reports after reports into a minute, 2 minutes of analysis and a review session and now we have something actionable that we can take the next step.
So now step four is that we want to use AI to look at this from a red team blue team perspective or offensive defensive to analyze this from a red team perspective. I'm going to go ahead and drop this prompt in. And this one's a little longer so I'm not going to read the whole thing, but what you're asking for is an advanced threat emulation to conduct red team reconnaissance exercises. And then what we want to do is we want to tie it to TTPs that are in circulation. And we want to look at initial attack vectors and more. And now you can see the step-by-step attack path. Here's your initial access, the likely vectors for that. Then you have the execution and foothold. Here is the methods that are used to do that. Some privilege escalation, lateral movement, xfiltration or impact. And then your attack path example. So here is an end toend simulation of how we would do this. We would start with reconnaissance, get into initial access, focus on persistence, priv escalation, lateral movement, edr evasion, xfill, and then impact. Then here's your estimated difficulty level. So the initial access would be medium, persistence would be medium high, and so on. So, do you see how this prompt produced a realistic attack scenario, outlining how an adversary might infiltrate your environment from initial access all the way to impact? And so, you have a breakdown of the TTPs, plus insights on how difficult each stage is and more. So, we could use this to prioritize our threat emulation, our red team planning, or even just tabletop it for now and then move forward.
Now on the flip side of it, let's look at things from the blue team or the defensive side of things and let's do the same thing. In this case, what we want to do is we want to find some blind spots to known TTPs and we want to identify three to five areas where an attacker might evade our current controls. So now I'm going to go ahead and run this. And here is your threat model assessment for blue teaming. So identify abuse and MFA bypass. A blind spot might be the logs may not be fully integrated into your SIM. So we may not be seeing activity from Octa or Microsoft 365 or Google Workspace. Crowdstrike focuses on endpoint visibility, but cloud identity attacks can bypass the EDR. We have some TTPs that are referenced to MITER and some recommendations. Then there's malicious OOTH applications, cloud control plane misconfigurations, EDR evasion and endpoint blind spots and so on. Data Xfill, then you have top three priority areas. And this is where we would most likely invest our time. So, do you see how this prompt gave us a prioritized list of blind spots in our current defensive setup? We can also add controls in here. We can do a lot of things to really fine-tune this and get some really detailed information. Pretty awesome, right? It really changes the perspective. And these alternate angles can help you uncover gaps that your default triage might miss.
Now, after we've validated and understood the threat actor's relevance to our environment, the fifth and final step is to put that insight into motion. That means tagging the alert, adjusting some playbooks, briefing leadership, or even just updating our threat models. So to streamline this process, of course, we're going to use this prompt to do it. So we're a sock analyst summarizing the operational relevance of a known threat actor based on validated intelligence, give our tech stack, recent alerts, exposure points, and so on, and recommend any immediate next steps to the sock team and what we should prioritize this week. including detection tuning and so on. So this is going to give us a very sophisticated report and tell us exactly what we should be focused on. So it's going to talk about operational relevance and again it's doing the MITER attack mapping. You also have your priorities now for the week. So we want to look at detection tuning. So we want to enhance identity based detections and expand on crowdstrike watch lists. We also might want to tag our highv value cloud assets like AWS admin roles, S3 buckets and so on and also confirm that CrowdStrike is covering our serverless or container workloads and flag any unmonitored assets. Then we want to maybe update some risk documentation. So our threat actor matrix we could document cloud identity risks in a risk management plan in a plan of action and milestones whatever we might need to update it in also playbook updates threat hunt initiatives and so on. And then for the leadership side of things we want to recommend to prioritize identity centric security investments. We want to increase cross team visibility and schedule a tabletop exercise to simulate this AP threat and see how we do. How helpful is this? I mean, this is really awesome.
Right now, here is what I want you to take away from this lesson. Genai can help you answer, does this apply to us? With speed and structure, like you saw here, you always want to provide organizational context in your prompts, whether it's tech, the sector, geography, and more. We want to use race prompts to get risk ratings and actionable justifications. We want to use tabular or batch formats to assess multiple threats fast. Red and blue team lenses will help reveal blind spots or alternate threat angles that we might have missed otherwise. And we want to use relevant scores to drive tagging, action planning, and documentation. Remember, you don't have time to chase every headline or every threat that's out there. With Gen AI, you can triage relevance in minutes, not hours or days. And now you're not just reacting, you're responding with context and with clarity. So start using this approach to analyze your weekly threat feeds, blog posts, and CISA or CISA alerts.
Now, next up, we're going to operationalize all of this intelligence by mapping threats to your controls using MITER attack framework and NIST. So, let's keep sharpening that edge, and I'll see you in the next lesson.
Understanding a threat actor's TTPs is one thing, but turning that knowledge into action, that's an entirely different challenge. How many times have you read a threat report, stared at the MITER technique names, and thought, "Okay, that's cool, but now exactly what do I do with this?" Well, the good news is that you can use Genai to bridge the gap between theory and action or between what the attacker does and what you should be monitoring, blocking or reporting. And with the right prompts, Genai can turn reported threats into framework aligned insights. And they can plug directly into your detection stack, your control mapping, and even your risk register. By the end of this lesson, you'll be able to prompt Genai to map threat behaviors to MITER attack techniques and ideas. You'll be able to translate threat activity into security control mappings like the NIST SP853 or CIS controls. You'll be able to generate actionable insights for detection engineering. Visualize attack paths and kill chains with AI assisted breakdowns. and you'll be able to use all of the above to support security architecture, compliance, or incident response. This is where intelligence meets engineering. So, let's get into it.
Now, here's a typical situation. You've got a threat report that says a threat actor sent fishing emails with macrolaced documents. They used PowerShell to establish persistence. They laterally moved using Wii and they exfiltrated data over HTTPS. Okay, great. That all sounds technical, but how does it translate into MITER technique IDs for your threat matrix or control gaps that you should be reporting? Detection rules that your sock should prioritize and implement. This is the problem that most of us run into. Frameworks are powerful, but only if you connect them to your day-to-day operations, and Genai can be your assistant in that translation layer. So let's break this down end to end so that you can start applying this immediately.
Step one, let's use Genai to map to MITER attack. The MITER attack framework is the global standard for mapping threat behavior. So you're aiming to convert narrative descriptions into structured mappings. To do that, we can go to our prompt library and use a prompt like this. As a cyber threat analyst, analyze the behavior descriptions from the threat report and more. So, what I'm going to do is I'm going to grab the artifact for the threat report and we're going to go over this again, but we're going to look at this from a different angle than we have previously. So, I'm going to send this off and Chat GPT is going to start processing this. And here you go. So, again, like we've talked about in the previous lessons with this report, we have a pretty good breakdown. We know there's a supply chain problem, initial access, compromise of trusted supply chain, and so on. And there's your MITER attack technique ID. And then you can see some of the other things as well. Here's some key notes. This indicates that thread actors are using compromised thirdparty software. That's an issue. We have some ingress tool transfer service installations and so on. Okay. So that just gets us started.
So next what I'm going to do is I'm going to link the TTPs to security controls. So we're going to map these to the Nest 853 controls. the ISO IEC 2702 controls, the CIS controls, or even your own internal policies or custom controls. So, I'm going to go in and I'm going to grab this prompt and I'm going to say, as a cyber security governance analyst tasked with compliance alignment, review the provided MITER attack technique IDs and then map them to the most relevant CIS critical security controls. So, in this case, we're going to look at the CIS controls and then you can change this. You can make it NIST 853. You can make it ISO IEC or whatever other controls that you want. For the purposes here, we're going to map to the CIS critical controls. So, I'm going to run that. And now, you can see it's already done its analysis. And as you can see, this MITER ID maps straight to the CIS control 15.1. It also maps to CIS control 2.1. And then it even tells you what it maps to. There's a secure software supply chain. There's inventory of authorized software and then T105 maps to CIS control 6.2 and it also maps to 13.2 and so on. So you can go down this list and now you have a matrix to trace between the MITER attack framework and your control set. And some key observations that were made are listed right here and so on. Now, if we want to do this for the NIST SP 853 controls, we can just change it and run this prompt. Same exact thing. We just change it to NIST and then we'll see what it says. So, as you can see, now it's creating the matrix. And you can see that T195 for supply chain maps to SA12. It'll map to SA19 and SR1. And so now we can go back into the NIST catalog and start looking at how we can implement these controls and then start tracing down the governance risk and compliance path to implement these and mitigating any threats. Now here is why this matters. This crosswalk supports compliance reporting. It'll support gap analysis and even audit readiness as well. Just remember we always want to validate the AI generated mappings with our internal control owners and our framework documentation.
Okay. Now step three is to support detection engineering using AI. Now that you've identified what the threat is and which controls it might cover, now let's help your sock team. So I'm going to go into my prompt library and I'm going to grab this prompt. You are a detection engineer working to enhance sock visibility. Given the list of MITER attack technique IDs, analyze each one and determine the relevant log sources and corresponding basic detection logic that should be implemented. So now we're looking at implementation that can apply back to the controls that are going to map back to the MITER attack framework. So I'm going to execute that. And as you can see now it's going to create another table for us. And now you can see for T1195 for the supply chain the relevant log sources should be things like EDR logs or XDR if you have XDR software inventory. So our asset inventory application install logs. Then we have the basic detection logic right here. Detect unauthorized or unexpected software installation or updates. Alert on installation of unsigned binaries. compare installed software against approved baselines and so on. So now we can end up working with an architecture team, an engineering team and come up with some implementations to make this possible. Does that make sense? Then there's some key detection enhancements, correlation of events, baseline comparison, dynamic DNS monitoring and so on.
Okay. Now step four is to visualize the attack path. So, what we want to do is explain the attack flow to executives or even during like a tabletop exercise. So, with that, I'm going to run this prompt and keep the chain going. As a security strategist preparing for a briefing for executives, analyze the described threat scenario and outline the attack sequence using Loheed Martin's cyber killchain framework. Your goal is to translate technical TTPs. That's tactics, techniques, and procedures into a narrative that aligns with each phase of the killchain and provide a clear picture of attacker progression for strategic planning or tabletop exercises. Now, this is a powerful prompt here. Now, when I run this, it's going to take everything we've talked about and map it to the kill chain. And so, now you have a breakdown of the scenario. And then you have the kill chain phases where you have reconnaissance, weaponization, delivery, exploitation, installation, command and control or C2, and actions on objectives. So if we start up here, it will literally walk you through the translation of what's happening at each step according to that threat report that we provided earlier on in our chain. So our prompt chain is still going and now we've turned this into even more actionable information. This is incredible. Then you have a strategic takeaway for the executives where supply chain is going to be our biggest focus. There's some visibility gaps between HTTPS and dynamic DNS. Trust me, executives are not going to care about that. But what we want to tell them is there are some technical gaps and here they are and we will take care of them as the technical side of the house. Then there's persistence focus and then there's also proactive measures that we can be taking.
Okay, really awesome stuff here. Now, step five is to connect all of this to your defensive stack. And here is how the whole workflow plays out. We want to identify TTPs from a report, then map them to the MITER attack framework, crosswalk that to CIS or NIST controls, generate detection guidance, then visualize everything with the killchain. This can now feed into detection backlogs, purple team exercises, compliance audits, security architecture reviews, CISO briefings, and more. But remember, we've want to validate AI suggestions when mapping to controls or writing any detection rules. AI is your co-pilot. It is not your compliance officer.
Okay. So, here is what I want you to take away from this lesson. Use Genai to map behaviors to the MITER attack ttps. Prompt Gin AAI to cross reference TTPs to CIS, NIST, or other controls for audit and architecture planning. Get detection logic fast with log source suggestions and sample rules. Use Genai to narrate and visualize attack sequences for stakeholder briefings and validate outputs before implementation, especially when they are tied to compliance or automation. This is how you build defensible, transparent, and prioritized security programs. And now you don't have to do it alone. With Gin AI, you have a co-pilot who can read, map, translate, and even draft rules, leaving you to focus on what really matters, and that's the strategy, leadership, and action. So, start using these workflows in your own environment. Test them, tune them, and make them your own. Use this workflow during incident response, threat modeling, tabletop exercises, or even quarterly security control reviews. The future of cyber security isn't just powered by AI. It's led by professionals who know how to use it wisely. You're one of them now. And I'll see you in the next lesson.
Have you ever read a 20page threat report and thought, "What do I actually need to do with this?" Well, after completing this section of the course, you should know the answer to that now. Most analysts get buried in data and miss the decision. But not you. Not anymore. because now you've got Genai as your assistant. And in this lesson, we're pulling it all together and I'm going to show you how to go from intel overload to operational clarity in just minutes. You've just completed a critical chapter of your Gen AI journey. And in this recap, we're going to stitch together everything you've learned about using Gen AI for threat intelligence analysis. So, we'll cover how to turn dense threat reports into clear briefings, how to extract IoC's and TTPs automatically, how to assess which threats matter to your org and which ones don't, how to map threats to MITER, CIS or even NIST frameworks, and most importantly, how to move from insight to action. And by the end of this recap, you will have a field ready framework for using Genai on real world threat intelligence.
Now, thread intel is powerful, but only if you can process it fast enough to use it. And every day, our inbox fills with reports from CISA, from Mandant, from all these other places. And they're full of acronyms, hashes, TTPs, and vague remediation advice. But you're expected to make decisions in minutes with lives, data, and dollars all on the line. But you don't have an hour to dissect each one. You need speed and you need clarity. You need intelligence that actually makes you smarter. And that's what this entire section was built to solve. So, it all started with learning how to summarize long threat reports in seconds. You learned how to sanitize the data first, replacing sensitive information like real IP addresses, usernames, and other information with placeholders. And then we use prompts like this. You're a cyber security threat analyst preparing a briefing based on an external threat report. Review the report and summarize its key findings focusing on the identified threat actor, targeted sources and so on related to MITER attack techniques and any mitigation recommendations structure your output and markdown for quick sharing with incident response or executive teams. So I'm going to grab our artifact that we used which was our threat report. drag this in here and I'll execute this. And if you recall from the previous lesson, this is going to put everything into a very simple structured document for you that you can use. And boom, you have a clear structured brief that you can drop into Slack, a ticket, or even a daily stand-up meeting.
Next, you tackled the core, which is extracting IoC's and TTPs. So from there, I'm going to go to my prompt library and I'm going to paste this prompt. You are a cyber security analyst tasked with extracting indicators of compromise from a threat report. And then we're going to look for IP addresses, domains, URLs, and so on. And we're going to run that. And so again, this report did not have IP addresses and domains and whatnot if you remember. So this was a very vague report that didn't include any of that information. And so our next step, if you recall, was to
Extract the TTPs. So you are a threat intelligence analyst mapping attacker behaviors from a technical report. Identify the TTPs described and associate them with the MITRE framework. So I'm going to run that and we're going to get this output in a markdown table. So as you can see, here's our markdown table. And again, if you recall from previous lessons, if we don't like how this is laid out, we can always ask Gai to create a new table, a different table, a CSV format, an Excel format, a Google sheet format, however you want this formatted. But the main thing is that you have the information in front of you. And with these two prompts, you turn vague text into machine-ready data for enrichment and detection.
And from there, now you want to answer a question that just about every SOC asks on a daily basis. Does this threat apply to us or not? So, we're going to go and we're going to grab this prompt. You are a cyber risk analyst assessing threat relevance for a financial organization using Octa, CrowdStrike, and Google Workspace. Analyze the described threat and determine its applicability to this environment. Provide a risk rating, justify your assessment, and outline key mitigation recommendations, and structure your output in a concise report format. Now, one thing that we did in the lesson, if you recall, is that we added some context. So, I'm going to grab that simulated context. So, I'm going to input the simulated cybersecurity threat context artifact so that JAI knows the context in which it's going to respond to. So, I'm going to execute that. And so now it's got its report. Here's your threat relevance, your risk rating, which is moderate, justification, key mitigation recommendations, and more. Pretty amazing stuff.
Now again, we didn't stop at just analysis. We learned to operationalize this intelligence. And so we use this prompt to map the TTPs to the MITRE ATT&CK framework. And we executed that. And as you can see, it creates a table for us and maps the technique straight to the MITRE IDs. You can see those right here. All just incredible and powerful stuff that comes out of GenAI. We also mapped the IDs to the NIST controls or the CIS controls or the ISO IEC controls, whichever is your preference. And so in this case, I'm going to map it to the NIST controls. And you can see that the output is going to be yet another table that gives us some really good crosswalk between the MITRE ATT&CK IDs and the controls that may apply to our authorization to operate.
And then from there we helped our detection engineers as well with a prompt like this. You are a detection engineer building coverage for recent threats using the MITRE technique IDs provided. Identify suitable log sources and propose basic detection logic that can be implemented in a SIEM. And then we're going to go ahead and run this. And then you can see the table and what it recommends to do for each individual MITRE ATT&CK ID. Pretty amazing. We even use prompts to create the full cyber kill chain for executive briefings and transform technical jargon into strategic stories as well. So what you saw all throughout this section is the real value of GenAI becomes clear when you embed its output directly into your daily security workflows. Then we take our validated AI-generated summaries, mappings or recommendations and plug them into the systems that our team is already using like Jira for incident tracking, The Hive for case management or your SIEM dashboards for real-time alerting. When GenAI becomes part of your delivery pipeline, it stops being just a research tool and starts becoming a force multiplier.
So here is your playbook from this section. Use GIA to summarize long reports into actionable structured briefs. Extract IoCs and TTPs for use in detection, threat sharing, and hunting. Tailor relevance using your org's tech stack and the sector that you operate in. Map threats to frameworks like MITRE, CIS or CIS and NIST to support compliance and engineering. And lastly, turn insights into operational outputs like playbooks, detections, and executive briefings. So, what's next? You've just unlocked a massive capability. Transforming threat intelligence into action using GenAI, but there's still one piece most organizations overlook, and that is security policies and configurations. That's where attackers hide. That's where misconfigurations live. And this is where risk becomes real. And in the next section, you're going to learn how to use GenAI to audit, review, and even generate policy and configuration insights faster than you ever could before. So, let's turn your policies into protection, and I'll see you in the next lesson.
Have you ever stared at a wall of firewall rules or identity and access management policies and thought, "There has got to be a better way to catch all of these mistakes." I know. I have too, and I know you're not alone in this. Security configuration review is one of the most mind-numbing, high-stakes tasks that we have in cybersecurity. One missed line, one overly permissive rule, and we are looking at a potential data breach. Now, imagine if you had a tireless, always active assistant that could read configs in seconds, point out weak spots, and even suggest stronger settings. Welcome to the world of GenAI, right? And that's why in this lesson, we're going to dive into how to use GenAI as a powerful tool for reviewing security configurations like firewalls, IAM policies, endpoint tools, and more. In this lesson, you'll also learn how to prompt AI to identify risks, rate their severity, and recommend some best practices. We'll also look at how to validate settings like MFA enforcement, log retention, and policy scope. and we'll also save some time on tedious review tasks while maintaining human-level judgment and oversight. And by the end of this lesson, you'll know how to make GenAI your first pass reviewer for complex configs and helping you to catch those red flags faster and easier than ever before.
Now, let's face it, manually reviewing security configurations is time-consuming and it's also error-prone. Firewall rules are often hundreds and hundreds of lines long. IAM policies can be deeply nested within multiple layers of permission scopes and group policies might span dozens of security settings across different domains. It's not just about understanding what each of these settings mean. It's about spotting what's missing, what's too broad, and what could open a door to a potential compromise. And this is where GenAI steps in. Again, it's not to replace you, but it's to help you move faster and spot issues that you might have overlooked after a long day of work. Now, let's look at some common config types that you'll want to review using GenAI. We'll go one by one, and I'll show you what to look for and exactly how to prompt AI to get help. So, let's start with firewall rules. Think Cisco Firepower, firewall D in Linux, Palo Alto, and even AWS security groups. You can task AI to look for things like is the default deny rule in place or are there overly open ports or broad IP ranges that I need to be worried about. Now, because firewall analysis can be quite involved, you're going to need a very good prompt to do this. So, let's hop over to ChatGPT. I'm going to go over to my prompt library and I'm going to copy this prompt. And it's a little long, so I'm not going to read through everything, but basically, you're a network security engineer and you have expertise in perimeter defense and zero trust. And you're going to look at all of the different things in the config. You're going to look for default deny rules, overly broad subnets, the use of non-standard or unnecessary open ports, and so on. So, what I'm going to do is, I'm also going to grab the Palo Alto firewall config artifact that I've provided, and I'm going to run this prompt. And so as you can see, it quickly already looked at the file and now there is no default deny rule. So the issue is the configuration does not include a global deny by default rule. That's a problem. It explains why it's a risk. The recommended remediation, there's some overly broad outbound rules in the config. So we need to look at those. And again, there's a use of broad IP ranges. And yes, these are pretty broad, but they are private IPs, which means they're internal to our network. So we'll want to look at those. Then there's missing segregation for sensitive zones, lack of application and service restrictions, and some next steps. So as you can see, it went through the firewall configuration and gave us some pretty good information about how to start taking a look at things to try to improve and harden this firewall. Pretty awesome, right?
Now, what if you want to review your identity and access management policies like AWS IAM, Azure Entra ID roles, or even Google Cloud permissions? These all govern access and misconfigured ones can lead to privilege escalation or even lateral movement. So, I'm going to go to my prompt library and I'm going to copy this prompt. And this prompt will allow us to analyze an AWS IAM policy that we provided. Now you can say provided below and paste it. But in this case, I'm going to attach the artifact and GenAI will know exactly what you're trying to accomplish and then it will execute. So now here is a review of the policy. You can see that there's some wildcard permissions, why it's a risk, and then it even gives us a severity level, which is great. So it lets us know we really need to pay attention. Then you have some read-only policies that are overly broad. So we need to look at that and why it's a risk. Then there's also some role policies that we need to look at. And this is low to medium. So this is probably a lower priority obviously. Then there's a lack of resource-level restrictions, missing IAM guardrails, and then some next steps. So as you can see this was really helpful. Just a matter of seconds it went through this file and told us exactly what is wrong. That way we get clear actionable advice that helps us strengthen our cloud security and even avoid accidental over-permissioning.
So what if we wanted to analyze our EDR or XDR or even our antivirus settings? So think of this like CrowdStrike, Microsoft Defender, and even SentinelOne. So maybe you want to check our threats set to block, alert, or ignore, are logs retained long enough, or are signature updates enabled. So, here's a prompt that we can use for that. So, I'll go to my library and I'll paste this very simple prompt. And this simple prompt will scan the EDR settings and call out any weak spots like missing threat detections, outdated signature policies, or even unconfigured alert thresholds. So, I'll go and I'll grab the artifact. I'm going to drop this Microsoft Defender config in here and we'll run that prompt. And so, quickly, it reviews it. Here's some general settings. And here are some gaps that it identified. Incomplete attack surface reduction rules. No mention of automatic updates or signatures. That's really scary. Alerting and reporting gaps. And then here's some recommendations. Then there's some other things like device-specific observations, why these are risks, cross-platform and operating system coverage, some gaps there, XDR and automated response, and so on. So you can see that this output is very detailed and gives us very specific directions on where we need to focus our attention. Imagine how much time you could save with a prompt like this.
Right now, what if you wanted to review your Group Policy Objects or GPO configurations in your Microsoft Windows environment? Maybe you want to look for password complexity settings, account lockout thresholds, or even RDP restrictions. Well, in that case, you can use a prompt like this where you want to assume the role of a Windows security auditor and review the GPO. And I'm going to go to my artifacts and I'm going to drop the GPO configuration file in there and I'm going to run this. And so now you can see it quickly reviewed the file and ChatGPT quickly processed this. And now here is our feedback. Here's the current config. The assessment: it is in alignment with NIST SP 863, which is good. Some recommendations: keep the minimum length 12. Evaluate removing a forced 90-day rotation. Enable password history. Here's your account lockout thresholds. Some recommendations. So you want to implement that lockout duration and consider using Windows Defender Smart Lockout or even Azure AD Active Directory (which is now called Entra ID) to lockout protections. Then there's our RDP restrictions, some recommendations, and some additional security recommendations as well. So this is really powerful. In just a matter of seconds, we clearly understand what's going on in our GPO configuration. This is pretty awesome stuff.
Right now, let's look at one last configuration check. Let's analyze a YAML or JSON configuration file. These files are human-readable and they're used to define structured data. You'll see these in Kubernetes, Terraform, and other infrastructure-as-code tools for cloud deployments. They're often nested and they're very easy to misconfigure. So, we have a prompt for that. So, what we'll do is we'll go to our prompt library and we'll paste this prompt where we're going to act like a DevSecOps engineer. We're going to review the provided Kubernetes YAML configuration file and identify any kind of security issues in this file. So, let me go over to my artifacts. I will drag this over and here is our file. And so, we'll go ahead and run that. And here is the result. So, the containers are running without security context. That's an issue. Here's the risk, which is really great. And then it even gives you a recommended update to the YAML file. So we could just copy and paste this in if we agree with this, right? We need to review this and make sure this is good for our environment before we just accept AI's output. There's a lack of resource limits and requests, use of latest image tags, missing readiness and liveness probes, no network policies, no pod security standards, and so on. And again, just in a matter of seconds, we have all of this information at our fingertips that we can use to start hardening this file. So, as you can see, GenAI can digest all of these formats just like a human would, but faster and with less fatigue. And with the right prompt, it gives you not just the answers, but structured, actionable feedback. Each of the examples that I showed you here quickly surfaced the risks and best practice improvements and it saved us minutes if not hours of research to do.
Now, we can't forget about the limitations and guardrails when we're using GenAI for this kind of work. Remember, GenAI is your assistant. It's not your replacement. It's not a substitute for security baselines like CIS benchmarks, NIST, ISO IEC, or other standards. Always validate any outputs manually. GenAI can make suggestions, but you are accountable for the accuracy. So, always be sure to remove sensitive or regulated data before you prompt. Be specific with your context as well. If AI doesn't know what platform a config belongs to, it may guess, which leads to hallucinations. Okay, now I know this lesson was jam-packed with prompts and results. Here's what you should take away from this lesson. GenAI can review IAM policies, firewall configs, GPOs, EDR and XDR settings, and even YAML files, and it can do it quickly and clearly. Every prompt has to follow that RACE framework to get meaningful results. Remember to use role-based prompts to extract targeted and expert-level feedback. Always treat GenAI as your first pass review. Always validate it before you implement it. And lastly, sanitize inputs and guide outputs with your expertise. Security config reviews don't have to be a soul-crushing experience anymore. With GAI, we can turn hours of manual work into minutes of intelligent review, making us faster, more effective, and less error-prone. Now, the next time you're staring at a 200-line firewall rule set, or you're confused by an AWS policy, let AI take the first crack at it. And then with a clear head and sharper focus, you can step in and do what you do best, which is making the final secure decision. I'll see you in the next lesson.
Have you ever tried to line up a 7-page internal policy next to a standard like NIST SP 853 and try to play match the control? It's like finding needles in a haystack while the haystack keeps growing. Manual audits against frameworks are super time-consuming. They're error-prone and they're often inconsistent depending on who's actually doing the audit. So different reviewers may interpret the same control differently. Some may miss controls altogether. And let's be real, nobody enjoys reading the same policy for the fifth time just trying to make sure it checks all the boxes. Now imagine this. You paste your internal policy into an AI prompt and seconds later it tells you which NIST SP 853 control it meets and which one it doesn't, where it's weak or completely missing. And it even suggests language to fix the gaps. Welcome to the new way of auditing. In this lesson, we're going to walk through how to use GenAI to audit your internal security policies against industry standards like NIST, CIS Controls, ISO IEC, and PCI DSS. You'll learn how to feed internal policy documents into GenAI and ask for gap analysis against specific standards. We're also going to interpret and use AI-generated results like gap lists, rewrite suggestions, and even optional compliance scores. And we're going to learn how to work faster and smarter while still making final human judgment the call that matters. And I'll also show you how to build prompts that drive high-quality results. And we'll also chain prompts to guide GenAI through multi-step audits. And by the end of the lesson, you'll never approach a compliance audit the same way again.
Now, let's say that you're handed a new password policy from your Human Resources department and your manager asks, "Does this meet NIST SP863B requirements?" And like most professionals, we would end up going to NIST's website and we would look for the NIST SP800-63b standard. Then we would line that up against our policy, try to interpret each control, and make a judgment call on alignment. And then we document gaps, make suggestions, and then maybe even debate the interpretations with our team. Now, that's hours and hours of work. And if you miss one key detail, like failing to discourage password hints or require a minimum password length, then you're going to be out of compliance. GenAI can take the heavy lifting off your plate and become your second set of eyes. Now to make GenAI work for audits, you need to know what kinds of documents and frameworks work best. Policy types like acceptable use policies, password policies, incident response plans, BYOD policies, and access control policies are all perfect. Frameworks like NIST 853, NIST 863, the CIS Critical Security Controls, ISO 27002 controls, and also PCI DSS are also perfect. You don't need to paste in the entire standard. GenAI already knows these public frameworks, so all we need to do is reference the specific section that we're auditing against. Now, here's where most people go wrong. Vague prompts lead to vague answers. So, if you want useful results, you have to be specific. That's why we use the RACE framework. Role, Action, Context, and Expected Output. So, let me walk you through a few examples and I'll break down what each one of them does so that you can clearly understand what's going on. First, let's look at a CIS control gap analysis. Let me go to my prompt library and I'll paste this prompt. You are a cyber policy analyst. Review the attached group policy object and compare it against the Critical Security Controls five and six. Notice that we're being very specific about what we're looking at. Identify any missing requirements, configuration gaps, or areas for improvement. So, I'm going to go over to the artifacts and I'm going to drag the group policy object over and Claude is going to do its work. So, as you can see, it's already finished. And so, now you can see it analyzed the GPO. Here's our password policy, account lockout, audit logging, firewall, and then here is our gap analysis. So now against CIS Control 5, account management deficiencies, there's no automated account provisioning, there's a lack of account inventory, there's no dormant account identification, and there's missing service account management controls. Ooh, and then what about 5.2 access control weaknesses? Here's some gaps. There's no privileged account management controls and so on. And so, as you can see, it clearly breaks down the control and tells us exactly what's wrong. Now, it doesn't mean that this is incorrect. The GPO may not have all of the controls implemented. So, we might have to use another policy. We might have to use another document or something else to verify it. But, this gives us a lot to go chase down to see if our GPO is compliant or not. And then there's Control 6 for access control management. And so we don't have any good RBAC defined. We don't have regular access reviews is missing. So again, because it's a technical file, it may not catch it all. So let's go back to ChatGPT. I'm going to run this same exact prompt and drop this in so we can see if ChatGPT might give us better results. So I'm going to run that. And here is our review. And so here's the strengths. Here's a gap. Again, no mention of password history enforcement. That's a problem. The maximum password age. And here's some recommendations for Control 5. Add your password history, enforce MFA, implement lockout, add automatic disabling, and so on. Now, notice how Claude was very specific about things outside of the file. So this gives us a much deeper analysis in terms of outside factors that can influence the configuration of the file. So we want to keep working with Claude because we're getting better results.
Now what if you want to perform a NIST password policy audit? Well, here's a prompt to do that. And so I will drag the GPO back in here and I will run this same prompt against that GPO. So now instead of looking at it from CIS, we're looking at it from a NIST perspective. So again, it's going to break it down. I'll open this up a little. And you can see that it clearly broke down the policy and it's saying here's what's compliant. Here's what's non-compliant. So now we need to take a look at password complexity rules. Ooh, that's an issue. And we keep going down. Here's some missing critical requirements. We don't have a blacklist or dictionary checking. Password strength verification is an issue. Secure password storage might be an issue and more. So you can see that it gave us a pretty detailed analysis. And then here is a recommended update to the policy itself. So if we want to just copy this, put this into a text editor or something like that, we could clearly review this, update this, and then push this through the configuration management or change management process to implement this. Okay, pretty awesome stuff here. And then there's some implementation guidelines. So we got really specific for us. Wow, this is incredible. Just going to keep scrolling so you can see exactly what this is. Amazing. And just a matter of seconds, we got all of this information right at our fingertips so that we can start securing that GPO file.
Now, let's look at performing an ISO IEC 27001 alignment audit. So, I'm going to go to my prompt library. I'm going to open a new chat and I'm going to paste this prompt. As an information security compliance specialist, review the acceptable use policy below or in this case, it'll be attached. Compare it against the ISO IA 27001 Annex A, specifically these requirements, and identify any gaps or misalignments. So, I'm going to grab the acceptable use policy, and I'll drag this in, and I'll send this off. And in just a matter of seconds, we've got our feedback. So, here we go. So, it's doing an analysis, which is great. There's an executive summary. It has significant gaps when measured against these specific controls. So that is something we need to look at. So handling of assets, this is what could be missing in the policy. We don't have asset handling procedures. We don't have information classification in there. There's a vague asset return process and insufficient media handling. So these are our gaps. And then on this other control here, the use of privilege management rights, these are our gaps as well. There's no privileged access allocation, missing privileged account monitoring, absent regular privilege review, and no segregation of duties. So these are issues for sure. And then it gave us a recommended enhancement, which is awesome. So now we can go through and we can review this and if it's good enough, we can use this and send this off to our executives and try to get this approved and implemented across the organization. This is amazing. So, I'm going to scroll down a little bit more. Here's more detail from Claude. Man, more enhancements. Wow, this is powerful. And so on. So, you can see clearly how powerful that prompt was and the artifact combined to give us the results we just saw.
What if we wanted to perform a multi-control review against the CIS Controls? So, what I'm going to do now is I'm going to close this document and I'm going to go to my prompt library and paste this prompt. So, you are a GRC professional conducting a compliance gap analysis and we're specifically going to look at these controls one and four against that acceptable use policy. So, I'll drag the artifact back in here. I'll execute this and Claude will do its magic. And just like that, it's reviewed it against those controls. And now it's going to give us that similar feedback that we saw earlier. So CIS Control 1 is inventory and control of enterprise. There's some existing elements in the policy, but here are our gaps. So asset discovery and inventory is not addressed. Unauthorized asset detection is not addressed. Mobile device inventory, asset disposal, software asset inventory, these are not addressed in this policy. Now, this very well could be addressed in another policy in the organization. So, that's on us, the human, to go and chase this down, right? So, I'm going to scroll down a little bit more. Software configuration of enterprise assets. And here's Control 4, the secure configuration of enterprise assets and software. So, we have secure configuration standards, which is kind of referenced. Then there's configuration baselines, which aren't mentioned. So nothing is really covered for this control in the acceptable use policy. So in that case, we go and we update the acceptable use policy or we reference another policy we have in the organization to ensure coverage and compliance.
So now once we have AI's feedback, we don't want to just stop there. This is where we start to prompt chain. So in my experience, GenAI works best when you use it like a junior analyst. You give it one task at a time and then build upon that. So let's stick with CIS compliance and let's follow up with this prompt. Let me close this out. Go to my prompt library and I will paste this prompt. As a cybersecurity auditor reviewing policy documentation, assess the acceptable use policy provided below for alignment with CIS Controls. Identify any compliance gaps and suggest specific policy statements that can address those gaps. So why am I doing this? What if controls one and four were not really appropriate for the acceptable use policy? Maybe I got the numbers wrong. Maybe I misunderstood. Right now, I'm going to go a little bit higher and I'm going to review the entire control set and see what Claude finds for me. So, I'm going to run this. And now it performed its review. And it's giving us a full audit report of that policy against the CIS Controls. Now, this is incredible right here. Let me open this up a little bit. Here's a detailed analysis. It went through Control 1 and it told us the current compliance level is 20%. Then it went through Control 2. We're 15% compliant, Control 3 40% compliant, and so on. And it gives you all of the gaps and the findings. And then it even tells you the risk level as well of non-compliance. So here's four, which was one of the controls we looked at earlier. Here's five for account management. It's only 30% compliant. Control six, eight, 17. So what another thing I want you to see is how it's jumping around controls. AI is smart enough to know the document you gave, it knows exactly what you're looking for. So, it's not going to give you controls that don't apply to this particular document or this artifact. It's going to give you exactly what you're asking for. And again, that's why we use that RACE framework. So, let's go down here. And now, it's given us some recommendations for our updates, which is awesome. This is crazy how powerful this is. So you can see it's addressing every single control. You can see right here that it's addressing every control and giving you what you need to update to this policy to become compliant. So what we could do is update the policy, re-upload the document and run this check again and then it will give us another score and we can keep refining until we are compliant. Pretty amazing, right? Plus you can always request a different format of the output as well. We have a report here. But what if we want all of this in a table or we want this in a gap list or we want to rewrite something in there or we just want a compliance score report? AI can do all of that. So I can just go over here and I can say output the response as a markdown table and hit enter. And now we'll go through and it will update this artifact and give us a table instead of text, which is really incredible. And this is helpful too because then we can upload this to Google Sheets or create an Excel document or upload this to any tool that we might be using as well. This is awesome, right? You get to choose how the results are packaged because the better the format, the easier it is for us to take action on the feedback, right?
Now, remember, AI can hallucinate. It can make stuff up and it can misinterpret vague content. So, your expertise and oversight is still required here. So remember to always review AI output manually. Don't treat it as certified compliance. Sanitize those inputs. Remove internal names, systems, and sensitive information. Check AI's control references. Confirm that they match your framework version as well. And always treat AI as your powerful research assistant and you are still the final reviewer of everything. Okay. So here's what I want you to walk away with from this lesson. GenAI can audit internal policies against frameworks like NIST, CIS, and ISO IEC and save you hours and hours of comparison work. Remember to use the RACE formatted prompts to ensure structured, relevant, and actionable feedback. You can chain prompts. First, identify gaps, then ask AI to rewrite things to give you the output you want. Request outputs in structured formats like tables, bullet lists, or even redline-ready language and always apply your expertise. AI gives you a draft, but you certify the result. Okay? Policy audits don't need to be slow anymore. GenAI can now help you bridge the gap between policy intent and standard alignment. It can give you clarity, speed, and confidence. In a world where compliance and security frameworks are growing faster than ever, this is your new secret weapon. Now, in the next lesson, we're going to talk about GenAI for peer reviews and compliance quality assurance to help us catch blind spots before our team members do. So, I'll see you in the next lesson.
Have you ever proofread a document five different times and still missed something totally obvious? I have, and I know plenty of my team members did as well. We've all been there. You put in the hours writing or updating a policy only to have a peer spot a typo or a conflicting section or some confusing language, and that opens the door to compliance gaps. And that's if you're lucky enough to have a peer that's available with time to review it all. Now, imagine this. You finish your draft, you paste it into a prompt, and GenAI comes back in seconds with flagged inconsistencies, suggestions for clearer enforcement wording, and even tone improvements for audit readiness. That's not science fiction. That is AI-assisted policy quality assurance. And it's available right now using GenAI. In this lesson, I'm going to show you how to use GenAI as your always-available peer reviewer for security documentation. So whether you're working on a new access control policy, an onboarding checklist, or updating your incident response plan before an audit, AI can act like a second set of eyes for you. In this lesson, you're going to learn how to simulate different reviewer roles using GenAI, like a GRC peer, an auditor, and more. You'll learn how to use properly formatted prompts to check clarity, coverage, tone, and consistency. And you'll learn how to apply GenAI during the pre-publication QA phase so that you can tighten up documents before they go live. And by the end of this lesson, you'll have a new documentation workflow, one that never sleeps, never gets tired, and helps you spot the little things that make the big difference.
Now, let's talk about what happens when documentation goes out with mistakes. Because errors create risk. Typos can make your team look careless, irresponsible, and vague enforcement language can leave policies open to interpretation and debate. Inconsistent terms across multiple documents can create confusion or even a contradiction during an audit. For example, you say "system owner" in one paragraph and then "data steward" in another, but they mean the same thing. You say "should enforce MFA" instead of "MFA must be enforced," creating ambiguity, or you forget to include account deprovisioning in your onboarding checklist. Something that a compliance auditor will absolutely find. Manual QA takes time, it takes effort, and it takes multiple human reviewers. But GenAI can give you a faster way to clean up the mess before it happens. And here's the cool part. You can instruct GenAI to take on different viewpoints to give you varied feedback. So let's say you want feedback from a peer who really knows security governance. You can try this prompt. I'll go to my prompt library and I'll paste this. Act as a cybersecurity GRC analyst. Review this draft incident response policy and suggest improvements related to containment steps, reporting timelines, and so on. So, what I'm going to do is I'm going to go over to the course artifacts and I'm going to get an incident response policy. I'm going to drop this in here and I'm going to let Claude review this for me. And so now it's doing its job and here you go. Here's your executive summary. Some critical improvement areas, containment steps, there's some vague language right here. There's no decision matrix. It's missing automated containment triggers. Some recommended improvements right here. So, level one network isolation, level two system isolation, service shutdown, and so on. And then there's some asset-specific containment procedures. There's a decision matrix right here. Then there's reporting timelines. So, Claude did a complete review and is recommending all kinds of updates to this policy. I'm thinking I didn't do a very good job with the draft, but Claude does a very good job in catching all of this for us. And it even provides some recommended frameworks as well. And you can go right through here and see exactly what it's recommending. And it did this in seconds, which is awesome. It even gives us some performance metrics and KPIs. Like this is amazing. So you can see how valuable this feedback is to create the best possible policy. This is perfect when you need input from someone who speaks the language of controls and frameworks, but you don't have to wait on a real colleague for their time to free up.
Now, what if you wanted to see your document through an auditor's eyes? Well, then I'm going to go to my prompt library and copy this prompt. You're a security compliance auditor preparing for an internal review. Analyze this access control policy. Identify any areas that could trigger audit findings or require clarification. So, I'm going to go to my artifacts and I'm going to grab the access control policy that I created for you. And then we'll send that off and it will update the document. So, as you can see, here we go. Here's your executive summary. Here's your audit findings. It's going to be looking at things from an ISO 27001 perspective. But let's say I want this done according to the CIS Critical Security Controls. So, let me close this. Let me go and edit this. And right here where it says analyze this access control policy, I'm going to say against the CIS Critical Security Controls and then I'm going to hit save. And so now it's going to rerun this and give us feedback based on these CIS Controls. So now it went ahead and created a new summary for us. And now it's going down the list of all the different controls. There's a major finding here. There's a major finding here, minor finding. So, this is not looking good for us. We've got a lot of work to do. But you can see how quickly it gives you the feedback and also gives you very specific details about what it's finding and what we need to go pay attention to. So, you can scroll down. Hey, we got something that's compliant. That's awesome. So, then we keep going. Now, it has a critical risk finding section here. And now we know the critical findings. There's the high findings, the medium findings, and then some recommended improvements. So, Claude is excellent when it comes to document review. So, if you're ever using documents or you're reviewing documents or creating policies, definitely Claude is the one to use in my opinion.
Now, when we're in security, we don't just write policies for security people and auditors. They also need to make sense to regular employees so that they can comply as well. So let's assume a different role so we can create something for non-technical team members or stakeholders. So I'll close this out and I will go down here and I will paste this prompt. Assume the role of a non-technical HR manager. Read this acceptable use policy and highlight any confusing language. So what I'm going to do is go over to my artifacts. I'm going to grab that acceptable use policy that I created for you and we will go ahead and execute this. And now you can see it's already done the review and here comes all of the findings. So there's a high concern that this policy contains language that can create a barrier between employees understanding and complying with it. So that's an obvious issue we want to resolve. There's some problematic sections that it's identified right here and HR concerns. So now it's approaching things from a human resources perspective and telling you exactly what it's finding and the impact of that finding. And so this is very insightful for us to create the best possible policies. This is how you get clarity feedback from someone or in this case from something that isn't engaged in cybersecurity buzzwords and lingo and it helps ensure that your policies land with everyone.
Each of these prompts that I've showed you gives JAI a different lens to review your content. Just like having three different reviewers at the table, each of them will have their own priorities and they'll find different blind spots. Now, let's take it up a notch. Let's say you want to tighten up your policy language for clarity. Since that HR manager prompt found a lot of mistakes, let's clean up our language. And so, what I'll do is, I'll close this out and I'll paste this prompt. You are a technical editor specializing in cybersecurity policies. Review this policy document for vague terms, passive voice or enforcement ambiguity, and suggest some plain language alternatives. So, what I'll do is I will upload that acceptable use policy since that's the one we're working with, and I will go ahead and send this off. And so, you can see it gave us some really good feedback. Another option is if we don't like the tone, maybe tone is an issue, maybe we feel like the draft is a little too casual or it's uncertain, we can definitely use this prompt to clean up the tone in the actual document. So I'll grab that acceptable use policy. I'll upload that again and I will run that through Claude. And so now it's going to draft the artifact for us. So now as you can see it's got purpose and objectives, scope and applicability, policy requirements. So it basically rewrote this entire policy for us and used a professional and audit-ready tone. So we keep going down. You can see network and remote access right here. Data protection and privacy requirements, enforcement and discipline, monitoring and compliance right there. Policy administration, acknowledgement and agreement, and then there's signature blocks and everything. So you can see it did a really wonderful job for us.
What if we want to make sure that our document actually covers what it's supposed to? In that case, we can go to your prompt library and we can grab this prompt. Assume the role of a security documentation reviewer. Evaluate this onboarding checklist for coverage of access provisioning, approval tracking, access validation, and account deactivation and identify any missing items and suggest what should be added. So, I'm going to go to my artifacts and I'm going to grab the onboarding checklist that I created and I'm going to send this off to Claude. So, you can see that it's completed its review and analysis and here are the gaps that it found. So, this is something that's of high importance. The onboarding checklist contains significant security gaps that could lead to unauthorized access, compliance violations, and audit findings. Uh-oh. So, we need to go through and take a look. So, now you can see some security gaps that it found. There's no access request form. There's no role-based access matrix that defines who gets what. There's no least privilege. No documentation of business justification for access. And then here are the recommended actions. And then there's some risk assessment integrations. Some recommended actions there. And then this section here, approval tracking failures. This has to do with the actual workflow of the checklist. And so there's critical gaps here, here, and here. Then it gives you some recommendations, access validations. I mean, there is all kinds of great stuff here. Let me open this up a little. Access deactivation planning, account lifecycle management, and so on. This is incredible, and this is incredibly powerful for us to take and apply back to this policy and start shaping it to be compliant.
Now, let me go ahead and close this out and open up a new chat. I want to talk about contradictions across multiple documents. If you want to look at multiple documents, have JAI review these for you, analyze and compare them, you can use this prompt. So, I'll go to my prompt library and I'll paste this prompt. You are performing QA quality assurance across multiple policy documents. Review the following set of policies on remote work, access control, and acceptable use. Identify contradictory statements, repeated terms, or inconsistent formatting. Suggest how to consolidate or resolve these conflicts. So, what I'm going to do is grab these three artifacts. I'm going to grab the remote work policy. I'm going to grab the access control policy. And then I'm going to grab the acceptable use policy. And so now, Claude has all three of these to work with. And then I'm going to run this. So, it's going to compare all three documents and tell you what's wrong with all three of them. And all three of these documents should be in sync with terminology and other things. So, as it went through, it looks at some of the key contradictions: password change requirements, data access and storage rules. And so, you can see how it breaks it down. The remote work policy says this, but the access control policy says this. And the conflict is here. Then there's repetitive content. So, there's duplicated system asset lists. There's overlapping security requirements, redundant scope statements, and then there's formatting inconsistencies as well. And then there's policy gaps and enforcement issues, conflicting ownership. Look at all of the awesome stuff that this just found for us. Because you know as well as I do, I might work on one policy while my teammate's working on one and my manager's working on another. and we never really get them synced together to understand what's conflicting, what's overlapping, and then what we might have missed, right? And this solves that problem for you. And just like that, you've streamlined three policies into one cohesive, readable document.
Now, I want to walk through one last prompt. So, I'm going to switch over to ChatGPT because Claude can start limiting us when we're using too many prompts and we're asking for too much information. So, I want to do this as a comparison, but also I want to make sure that it executes for you. So, let's say that you have three separate policies, an acceptable use, a remote work, and a mobile device policy, and you want to unify them. What we'll do is, we'll go over to our prompt library, and we'll copy this prompt. Act as a senior policy analyst. Review these acceptable use, remote work, and mobile device policies. Identify overlapping content, contradictions, or formatting inconsistencies. Recommend how to merge and harmonize them into a unified policy structure. So, what I'm going to do is, I'm going to grab the acceptable use policy, going to grab the remote work policy, and I'm going to grab a mobile device policy. All of which I've created for you. So, now that it's ready, I'm going to go ahead and send this off. And ChatGPT, just like that, has gone through everything and it's found overlapping content, common themes across all policies, scope, all three policies cover employees, contractors, and third-party vendors, security requirements, each policy includes.
references prohibited activities and so on. So these are all the good things. Now, here's the contradictions or gaps. Device use: The acceptable use policy broadly permits IT asset usage under authorization, while the Remote Work Policy explicitly restricts remote access from personal devices unless approved. So you can see that we really need to dig a little deeper on these to make sure that everything is symbiotic, that it's in sync, and all of the policies are singing the same song. Does that make sense?
So this prompt will help you do that. And you can see that it found some formatting inconsistencies, some recommendations for a unified policy structure, and then it gives you a breakdown: purpose, scope, policy guidelines, roles and responsibilities, compliance and enforcement, acknowledgment, and version control. And just like that, you have streamlined these three policies into one cohesive, readable document. All you need to do is tell ChatGPT to do it for you, and you will have that.
Now, remember, we want to make sure to sanitize and redact any content before we feed it into GenAI. We want to pair our prompts with our organization's style guide, whether it's formatting, language, and so on. And we want to treat GenAI as a drafting assistant, not a decision-maker. We don't ever want to accept a suggestion without our own judgment. We don't want to use AI behind closed doors either. We want to document its use in our quality assurance process, and we never want to assume that GenAI knows our organization's unique policy nuances. So we need to tailor and finalize the language so that it understands.
So here's what I want you to take away from this lesson. GenAI can simulate GRC peers, internal auditors, and end-users to catch different types of issues. Use RACE-formatted prompts for clarity, tone, coverage, and conflict review. And let GenAI help during the pre-submission QA. Then, that way, you'll publish cleaner, clearer, and more compliant documents. And always apply your expertise before finalizing any changes. In cybersecurity, your policies and procedures are not checkboxes. They're your story. During an audit, an investigation, or an incident, and like any good story, they need clarity, consistency, and credibility. With GenAI as your reviewer, you don't have to fly solo anymore. You can catch mistakes early, simplify communications, and even ensure that the documentation will stand up to scrutiny.
Now, coming up next, I'm going to show you how to generate and update policies using GenAI, where I'll show you how to go from a blank page to a draft policy in just minutes. And I'll see you there.
Be honest. How many times have you stared at a blank screen trying to start a security policy from scratch? I know it's painful, it's slow, and most of the time it feels like guesswork. Updating policies isn't any easier. Adding a few lines about cloud storage and suddenly your enforcement section contradicts your scope. Now the whole document becomes a mess. But here's a better way. You ask GenAI to write a policy for you. Say, a security awareness policy for a healthcare company with under 500 employees. In seconds, it delivers a complete draft: sections, structure, tone, and all. Your job: refine and finalize. That is the new way to write policies. And in this lesson, I'm going to show you exactly how to do that.
In this lesson, you're going to learn how to use GenAI to generate and update security policies using structured prompts that follow the RACE framework. You'll see how to create detailed draft policies from a single prompt, how to update legacy documents to reflect new technologies like cloud and GenAI, to provide your GenAI tools with the context it needs for better results. And you'll learn how to use a post-generation checklist to review and finalize your content. We'll even walk through a hands-on exercise to draft an AI usage policy together. And by the end, you won't just write policies faster, you'll be able to write them better.
Creating cybersecurity policy content often feels like assembling furniture without instructions. You know what you want it to do, but figuring out how to build it is a whole another story. Now, here are the big pain points when it comes to writing policies. First, starting from scratch. You have to define the format, research compliance requirements, and even write clearly for different stakeholders, and make sure that it aligns to frameworks like NIST, CIS, PCIDSS, and more. Second, updating old policies. Let's say you want to include new cloud guidance in your data retention policy. You patch in a few lines, but now your enforcement section makes no sense, and your role definitions are off, too. No wonder why organizations delay policy reviews. But GenAI changes that entirely.
So, let's start with generation. The secret here is using paragraph-style prompts that follow the RACE framework: Role, Action, Context, and Expected Output. So, I'm going to go to my prompt library and I'm going to paste this prompt: "Act as a cybersecurity policy writer responsible for drafting internal documentation. Please create a comprehensive security awareness policy tailored for a healthcare organization with fewer than 500 employees. This policy should align with HIPAA compliance expectations and include structured sections for purpose, scope, responsibilities, and more. And the tone should be formal and audit-ready. And the language should be accessible to both technical and non-technical staff."
So I'll send that off, and in seconds, ChatGPT is going to generate this policy for us. Security Awareness Policy. You can see clearly there's a purpose, there's a scope, responsibilities, workforce members. It identifies security officer, management, and then there's training requirements, enforcement, review and maintenance, and then related policies and references. Like, this is a pretty good start, right? This is a really good start. So again, we want to review this. We want to refine this and add the human touch to it to make sure that it's compliant in our organization.
Now, what if we wanted to create a policy with a framework like ISO 27001? So, I'll go to my prompt library and paste this prompt: "Act as a security compliance author tasked with creating policy content aligned with ISO 27001. Draft a professional acceptable use policy for a financial services organization. Notice how specific this is, and this is what's going to give you a much better policy. Ensure that it reflects a formal, audit-ready tone and includes structured sections and so on."
So we'll send that off, and in seconds, ChatGPT created this policy for us. So you can see there's a purpose, here's our scope, user responsibilities, acceptable use criteria, prohibited actions, enforcement measures, review and maintenance, and more. This is incredible. Notice how this one raises the bar a little bit. It clearly tells GenAI to stay framework-aligned and maintain a formal tone. And this is perfect for audits.
So, what about tone and audience? Let's say we want to create a device usage policy and we want to change the tone a little bit. So in this case, "Create a plain-language device use policy for a remote-first technology company with under 1,000 employees. And you're doing this as a cybersecurity policy consultant. And then you're going to cover topics like device enrollment, secure configurations, acceptable use, and also user responsibilities."
So I'll send that off. And again, in seconds, we have our policy draft. Now, because we've been creating multiple policies in this chat, you can see that ChatGPT is getting lazy. It's starting to create less and less content. So this is good. It's a good start. Let me keep scrolling down. Acceptable use. Yeah, it's very light and it's very weak in my opinion. So what do we do? We follow up and ask it to do more. And you can say something as simple as this: "This seems a little light for a security policy. Please expand on each section and provide more detail." Boom. And so now it will refine this for us.
Now, as you can see, now it's much more detailed in the purpose section, much more detailed in scope and device enrollment, secure configurations. This is what we were looking for. So, you see, sometimes AI will get lazy on you, and you need to keep it in order. So, you just prompt it and ask it to expand or give you more details, and it will.
Now, this is awesome, right? Now, this is creating policies from scratch. So you would copy this over to Google Docs or Microsoft Word or another software and start shaping this policy to be aligned with your organization. You can also use GenAI to revise outdated policies, and you can give it very specific guidance to do that. So let's look at how we can update a remote work policy with cloud guidance.
So I'll go into my prompt library and I'll copy this: "Act as a cloud security analyst reviewing a legacy remote work policy. Update the policy to include guidance on cloud storage and SaaS-based backups. Keep the tone formal and ensure alignment with NIST SP 800-171. Emphasize lifecycle management, encryption at rest, and regular backup testing."
So what we'll do is we'll grab that artifact and we'll put it in here. And then we'll let ChatGPT make recommendations on how to update it. So we send it off. In just a matter of seconds, it's already recommending an updated policy. So here's the purpose, the scope, policy guidelines, device and asset usage, network security, data protection and cloud storage, SaaS-based backups, monitor and logging. And you can see that it's starting to get lazy again. The sections are starting to get light. You can see that it's just two sentences. So we want to expand on this. So I can say, "Please expand on each section and provide more detail."
Now send that off. And now it will go ahead and start expanding on those sections again. There you go. Purpose is now well-defined. Much better than before. The policy is much more well-defined. Device and asset usage looks better. Network security looks about the same. Data protection is certainly better. SaaS-based backups is good. Monitoring is better. So you can see how now it expanded, and we have a better policy overall. And we can continue to do this. And we can even say, "Please expand on section 10," and it will give you a much more defined section 10. And there you go. Employee acknowledgment requirements, key user commitments. It broke it down in real detail. 10.3 says compliance tracking and records. 10.4 says consequences of non-acknowledgment. Like, that's incredible. Versus this just two sentences, right? And that's all just by prompting AI to do exactly what you want it to do.
Now, what if we want to update our acceptable use policy? In that case, I'll go to my prompt library and I'll copy a prompt like this: "You are a cybersecurity GRC specialist revising an outdated acceptable use policy. Expand the scope to include employee-owned smartphones and tablets that store corporate data. Include clear language around device registration and so on."
So now I'm going to go ahead and grab that artifact. I'll put it in here. And you can see that it's done. We'll send this off. And then ChatGPT has now updated this policy. And so now you can see it's got a purpose, a scope, device registration and management, acceptable use of mobile devices. So it added exactly what we asked: prohibited activities, enforcement and compliance, acknowledgment, and so on. And if we want to get even more precise, we can ask GenAI to identify missing cloud-related controls in this policy or to rewrite the data storage section to address those gaps and align it with the CIS controls. That's how you use GenAI, not just as a writer, but as a policy analyst.
Now, let's talk about inputs. Better prompts mean better outputs. Make sure that you include these elements: like industry. Are you in healthcare, government, finance, education, training, and so on? Risk tolerance. Is your organization conservative, or is it flexible? Frameworks. Are you aligning to NIST, ISO, IEC, CIS, HIPAA, and more? Control objectives. Spell out specific controls, behaviors, or requirements. And then tone. Is the policy formal? Is it friendly? Is it instructional? And all of these inputs will ensure that you get the best possible output that meets the needs of your organization.
For example, I'll go to my prompt library and I'll grab this prompt. And this is really specific about what we want from a policy. We want to "Act as a security policy author tasked in developing a Bring Your Own Device (BYOD) policy for a mid-sized financial institution. Align the policy with CIS Control 4 and NIST SP 800-124. The tone should be formal and risk-aware. Include structured sections for device enrollment, acceptable devices, secure configuration, monitoring, and remote data wiping."
And then when I run this, it will create the exact policy that we're asking for. Now, I won't walk through it. I just wanted to demonstrate how specific the prompt needs to be. So, as you can see, it clearly outlines that there's your scope, device enrollment, acceptable devices, secure configuration, and more. And again, if we want it to expand, then we ask it to expand, but we tell it exactly what we want it to expand about. Does that make sense?
Now, once GenAI gives you a draft, your job is to refine it. So, here is a checklist to guide you through your review. First, framework alignment. Double-check the draft and make sure that it actually meets decided control requirements. Two, defined roles. Assign responsibilities to job titles like IT Admin or Human Resources, not vague groups. Three, enforcement actions. Clarify what happens when someone violates the policy. Four, strong language. Use terms like "must," "will," "not may," "should," or "can." Okay. Number five, consistency check. Ensure the tone, the terminology, and the structure match across all sections of the document. And then six, review cycle. Specify how often the policy is reviewed and updated and who owns that process. This checklist is your finishing pass. GenAI will get you close, but you are the one who makes it bulletproof.
So, here is what I want you to take away from this lesson. Use the RACE framework to create clear, effective prompts. Include industry, risk tolerance, tone, frameworks, and controls in your inputs. Layer prompts to revise or refine policy content. Review GenAI drafts using a proven checklist for quality and alignment. GenAI is your speed boost, but you are still the expert. So, you want to bring your strategic lens and review GenAI drafts using a proven checklist for quality and alignment. You're no longer stuck starting policies from scratch. GenAI handles the heavy lifting for you so that you can focus on what really matters, and that's aligning policy to your people, processes, and risk posture.
So, next up, we'll go through our recap and I will walk you through a hands-on exercise applying everything you learned in this section. So, I'll see you in the next lesson.
Have you ever handed off your policy gap analysis or config review to a stakeholder and immediately thought to yourself, "I hope they actually get what I'm trying to say here"? This is pretty common. Translating technical findings into something that your CISO, your compliance officer, or your non-technical business partner can act on is one of the hardest parts of this job. You've done the reviews. You've prompted GenAI and you found the gaps, inconsistencies, and misconfigurations. Now comes the part where you need to communicate it in a way that gets decisions made and policies changed. And guess what? GenAI can help you here, too.
In this final lesson of the section, we're going to tie everything all together. You'll see how you take everything you've learned in this section—reviewing configs, auditing policies, running QA, and drafting updates—and how we can turn those insights into clear, actionable, professional communications. In this lesson, you'll learn how to write clear summaries of GenAI findings, structure executive briefings and stakeholder emails, create audit-ready tables and markdown summaries, use prompts to translate findings for different audiences, and finally, you'll get a chance to test your skills with a real-world hands-on challenge. So, let's jump into this.
First, let's talk about the problem. We spend hours reviewing firewall configs or updating BYOD policies, but when it's time to report it, we fall into one of two traps. We either copy-paste raw AI output into a document and hope that it makes sense, or we rewrite everything manually and lose the time-saving benefit that GenAI gave us in the first place. And neither of these are ideal. The reality is the value of your review work is only as strong as your ability to communicate it. If a stakeholder can't understand the risk or if a reviewer misinterprets your findings, your analysis might as well not even exist.
So, here's the solution. Use GenAI not as your reviewer, but as your communications assistant. Let's walk through how you would do that. Let's say that you need to review an AWS Identity and Access Management policy. So instead of reviewing it manually, we would sanitize and redact any sensitive data. Open up our favorite GenAI tool like ChatGPT and use the following prompt: "You are a cybersecurity analyst with deep expertise in AWS cloud environments and Identity and Access Management. And we wanted to review the policy that we provide below. Your goal is to identify any overly permissive elements like wildcards, overly broad resources, and more. And then we'll ask it to rate the severity, propose safer alternatives that align with least privilege and other things."
So then I'm going to grab my artifact and I'm going to drop it in here, and then we will send this off. And so now you can see the ChatGPT has done its analysis and it's going to give us some findings. So we have an admin policy issue that's granting unrestricted access. That's pretty severe. So we want to take a look at this. And we have a read-only policy with wildcards. We have role policies that has a wildcard. We have a lot of issues with this particular policy. So here's our recommendations: to audit all roles and users, to implement AWS IAM Access Analyzer, to introduce some restrictions, and use some SCPs. So that's what we found with this file.
Now comes the time that we need to brief a cloud architect or a compliance lead or someone like that. So in that case, we can use this prompt to change this language into something that's a little bit more reasonable for that audience. So we're going to say, "Summarize this policy for a mixed technical and compliance audience. Include the key risks, severity, a recommended action plan, and a one-sentence impact summary for executives." And then we're going to go ahead and format it. So I'll go ahead and send that off. And here we go.
So now you have exactly what we asked for. We have the key risks, and it shows exactly what it is: overly permissive admin policy, excessive use of wildcards, role policies, unrestricted log group creation. Here's the severity ratings. And now we're looking at the admin policy is the most important one we should be looking at. Then we have the mediums, lows, and our recommended action plan. And then down at the bottom, we have our executive impact summary. Unrestricted administrative access could allow total account takeover. Broad read-only permissions may leak sensitive metadata from EC2 or S3. Oh, that's bad. And then refining policies and enforcing least privilege will reduce both insider and external attack surfaces.
So in seconds, GenAI gives you a concise, cleanly formatted summary with plain language and technical depth. You can copy this into an email or even a presentation, and then your meeting gets cut in half because everyone already understands the context.
Now, let's look at another scenario. Let's say you provided this to the executive level, and your CISO wants to know if we're compliant or not, and they want to know quickly. Well, here's a prompt you can use to do that. So, I'll go to my prompt library and I'll paste this prompt: "Act as a GRC reporting analyst. Please convert your analysis above into an audit-friendly table against ISO 27001. In the table, please include..." and then we give it what we want in the table. So then I'm going to send this off, and just a matter of seconds, we're going to know where we stand according to ISO 27001 and the findings from that AM policy.
So, access control policy is not met, privilege management is not met, least privilege and need to know are not met. Access to source code and system data is partially met. Monitoring activities partially met, and so on. And you can also see that GenAI only gave us the controls that apply specifically to the policy. It didn't lay out every single control or requirement from 27001. It just told us exactly what we need to know so that we can report back to our CISO and tell them where we stand. Pretty awesome, right?
Now, what if we want to step this up a notch and maybe we want to change the language or how the table feels? So what we could do is go to our prompt library and paste this prompt: "Based on the above table, generate a one-paragraph summary explaining overall compliance, alignment, key deficiencies, and next steps for remediation. Target the tone for an executive audience."
So now what we're going to do is take that table and put it into a single paragraph that our CISO can clearly understand based on all of our results. So we'll send that off. And just like that, we've got it back. And so now here is our paragraph. And just like that, you've got a full communication package: a table for your auditor and a paragraph summary for your executive. Or if you even want to bulletize this, you can do that using GenAI. This is where GenAI really shines. Not identifying problems, but helping you report them and shape them for the different audiences that we have to work with.
Now, let's turn this into a hands-on challenge so that you can practice everything you've learned in this section. So, here's the exercise. Imagine you're working in a mid-sized healthcare organization, and you've just reviewed a BYOD policy against CIS Control 4, and you've done this using GenAI. And the AI output gave you this: You have three gaps. Gap number one is no enforcement of MDM or remote wipe capabilities. Gap two is no mention of security patching requirements. And gap three is devices not required to use encryption. It also gave you some recommendations. So your task in this challenge is to create a short executive summary and a policy remediation plan that can be handed off to the compliance and IT teams.
To do that, we'll go over to our prompt library and we will copy this prompt: "Act as a cybersecurity GRC lead. Using the findings below, draft a one-paragraph executive summary followed by a structured action plan for remediation. Tailor the summary to an executive audience and the action plan to a technical implementation team." And then what I did is I included the control gaps that we just talked about. So what I'll do is I'll send that off, and ChatGPT will quickly give us our summary, and then it will create our action plan for remediation. So you can see right here that we want to implement MDM with remote wipe. We want to enforce device encryption and governance and continuous monitoring. And there's our action steps: the owner, the timeline, and so on.
Now, what if we wanted to create a summary slide for the board of directors and have three bullets, some plain language, and focus the output on business impact? We can go to our prompt library and use a prompt like this. Now, "Rephrase the above for a board of directors summary slide. No more than three bullets, plain language, business impact focus." Boom. We'll fire that off, and it'll take everything and put it into three bullets for us. Unmanaged devices and data risk. As you can see right here, patch delays equals higher threat exposure and business impact. And this is what the board is really going to care about, the business impact. And that's why this language is so important. So, in just a matter of seconds, we got all of this information right at our fingertips. And now we can brief our executive level in the company and let them know exactly what's going on. You want to practice this over and over because the more that you use GenAI this way, the more influence and clarity that you can bring to your work.
Now, here are your key takeaways for this section. GenAI can help you translate complex findings into clear, actionable reports. You want to tailor your prompts to the audience, whether it's technical, compliance, or executive. You want to use output formats like summaries, tables, action plans, and slide-ready bullets. Prompt chaining helps you layer outputs for different stakeholders. And practice turning raw AI findings into professional communications. This is what separates good analysts from great ones. Not just finding the issues, but making sure the right people understand them, can act on them, and remember them. And now you're ready to do just that.
Now, next up, we'll take everything we've learned and focus more on creating reports and communications using GenAI. This will really help you make an impact in your organization and make you the go-to person on your team. So, head over to that next lesson, and I'll see you there.
Have you ever sent a security email that no one responded to, or worse, that got ignored until it was too late? We send critical messages every day: alerts, patch requests, phishing updates. But here's the problem: most of them go unread. It's not always about the content, it's how it's written. Now, imagine this: You jot down a few notes after a stand-up meeting. You feed them into GenAI, and in seconds, you have a clear, action-focused email that cuts through the noise and gets results. In this lesson, I'll show you how to make that your new normal.
Security teams live and die by communication. Whether you're chasing down patch compliance or warning about a new phishing campaign, your message needs to be clear, understood, and acted on. In this lesson, we'll walk through how to use GenAI to draft emails quickly and clearly, how to customize tone and language for different audiences, how to turn rough notes into professional, readable messages, and how to apply structured prompts for different security use cases. And by the end, you'll be writing emails that are short, powerful, and impossible to ignore, even by the most overloaded team members.
Now, let's play out a familiar scene. You find a critical vulnerability. You fire off a quick email to the DevOps team asking them to patch something. A week goes by, and it's still unpatched. Why? Because the subject line wasn't clear, the tone wasn't urgent, it lacked a clear deadline, or it was buried in 200 other emails. And when timing matters, that kind of delay can mean serious risk. But who has the time to write the perfect email when you're juggling different incident response calls, compliance reports, or even awareness campaigns? That is where GenAI becomes your new writing assistant.
So, let's break this down into a practical system that you can start using today. First, you need to identify the different email types where GenAI can give you back most of your time. Whether it's incident alerts, vulnerability disclosures, policy or awareness updates, audit or evidence requests, and more, every one of these needs to be clear, direct, and easy to act upon.
Now, let's look at how to craft a prompt that will give GenAI exactly what it needs. Let's start with a common use case: let's say a patching request. So, here's a prompt we can use: "Act as a security analyst responsible for communicating urgent vulnerabilities. Draft an email to the DevOps team explaining that CVE 2025870 requires patching within 48 hours. The audience is technical engineers, so use a direct and urgent tone. Include affected systems, remediation steps, and a firm deadline. The email should be concise, professional, and focused on driving immediate action."
And for some added value, we can go to our artifacts and we can drop in our IT asset inventory. GenAI is smart enough to look at that inventory and go and look at this CVE to see if there are any affected systems and the remediation steps for it. So let's go ahead and send this off. And then there's your asset inventory list. Okay.
Now, just like that, here are the affected systems for this particular CVE. So we have a storage node, an application node, a firewall, and so on. Now, there are some interesting findings. For example, firewall and CentOS 7. I hardly think that CentOS is our firewall, but we need to double-check that. So, we can go through and take a look. Okay, so we have some systems and we have everything that we asked for. And then here is an email that we can send right to the DevOps team and ask them to patch all of these. And what will most likely happen is they'll come back and say, "Hey, firewall 3 is not affected," or "The finance database is not affected," and so on. But we want to leave that to them because they are the technical subject matter experts. So we would send this off and wait for some feedback. And then here's some patch recommendations for Debian and CentOS. And there is a deadline.
Now let's say you need to take this and turn this into an executive brief instead. So what I'll do is I'll go to my prompt library and I'll paste this prompt: "Act as a security program manager preparing an executive update based on the CVE findings above. Write an email for the CISO summarizing any vulnerabilities affecting critical systems. Focus on business risk, impact, and the estimated remediation timeline. Avoid jargon, and the tone should be calm but serious."
So, we'll send that off. And then, ChatGPT is going to take everything that it's found and put this into an email that we can send to an executive. "We've identified that CVE [High Severity Vulnerability] affecting several critical systems, including our finance database server and key infrastructure assets. The finance database is at risk. The firewalls and application servers are at risk, and the data center and cloud assets are at risk. And then we have a remediation plan that we're including and the timeline." So they clearly know what we're doing, and full remediation is expected in 48 hours. That's important because that's what the CISO needs to know. For the next 48 hours, you can expect to be at risk. After that, everything will be remediated. And then you even include some next steps. "I will provide a final status. No service downtime is expected." That's another important detail. And we are monitoring for any IOCs, indicators of compromise, and we'll escalate immediately if there's any signs. So, this is a very powerful email that you can send to an executive. The shift in tone and focus ensures that your message lands with the right level of urgency and clarity, even for non-technical audiences.
Now I'm going to open up a new chat and let's shift gears here. Let's say we want to send a soft reminder for policy training. Here's a prompt we can use to create an email for that. So what we're going to do is we're going to say, "Act as a cybersecurity awareness lead. Write a friendly email reminding employees to complete their annual security training by Friday. Use a light tone, include the link to the training, and explain why it matters. Make it easy to read and upbeat in tone." And now, if you want to, you can include the link, but sometimes ChatGPT will just give you a placeholder, and then you can add the link later. So, we'll go ahead and send this.
And here is a friendly email that we can send. "Hey, don't forget, complete your security training by Friday. Hey team, just a quick reminder." So on and so forth. And again, here's your placeholder for the link. "Let's finish strong. Keep our workplace safe and secure." And so on. So, this is a fantastic email to send out to bring awareness towards training.
Now, what if maybe that subject line is not urgent enough? Maybe it's not strong enough. And so, we can go and we can type in a prompt like this: "Improve the subject line to reflect urgency and clarity." So, now it will go ahead and update that subject line for us. In fact, it gave us three different ones to choose. So, we can say, "Action Needed: Complete Your Security Training by Friday," or "Don't Miss It." I don't think that would be as strong. I think this would definitely be powerful. And "A Final Reminder" would be powerful too if this is the last email you're sending out. And if you don't like these three, ChatGPT is even offering to create more.
So now that we like the headline, what if we want to create a TL;DR in the email? So we want to create a "Too Long; Didn't Read" summary at the top for a busy technical audience. So in that case, we can just ask for that. And there you go. "Too Long; Didn't Read: Your annual security training is due by Friday. It only takes 30 minutes. Complete it here." That's really awesome because that will show up in the previews. It'll show up on mobile devices and so on. And it gives your audience exactly what they need to see, whether it's your security team, your IT team, or the company in general. They'll know exactly what this email pertains to without even having to open it.
And what if you want to tighten things and make it even more urgent with what we call a call to action? So, what I would do is I would paste this prompt: "Rewrite the call to action to include a specific action and deadline." So, now it'll do that. And then here's your TL;DR. And then down at the bottom, this would be a very strong call to action. You need to do something, and you need to complete it by a certain date. And then you're reminding them it only takes about 30 minutes. Okay, that's how you go from okay emails to actionable emails in just a few edits.
Now, let's walk through a real example. Let's say you're in a meeting and you jot this down on your notepad after a team call, and it's something to do with DevOps needing to fix the Log4Shell vulnerability in production apps. It needs to be done by this week. It's being actively exploited. We have a policy breach risk if it's not patched. The last time this happened, we got flagged in an audit, and so on. So, what we can do is go over to ChatGPT and we can paste this prompt: "Act as a security engineer. Turn the following notes into a clear and urgent email to the DevOps team. Highlight the risk, required action, and deadline. Use a direct tone." And as you can see, here are the notes that I took. So, I'll go ahead and send this off.
And just a matter of seconds, here is the email that we can send with our notes converted into action items, deadlines, and more. So, that was amazing right there. This is clean, it's urgent, and it's clear. And you didn't start from scratch. You focused on what mattered here.
Now, as a bonus, what if you were to anticipate some executive questions ahead of time? So, before we send this out to a CISO or a leadership team, we can ask AI this. We can say, "What follow-up questions might an executive have about this issue?" And as you can see, it's going to generate several different questions. It's going to say, "From a risk and impact perspective, an executive might ask, 'How critical is this vulnerability to our business operations? What's the worst-case scenario? Are we exposed to any kind of data breach for sensitive data? Have we seen any suspicious activity or indicators of compromise?' From a current status, 'Which applications or services are impacted? Have we already applied a temporary mitigation?'" And so on.
So what I would follow up with is, "What would be the top five questions an executive might ask?" So now it'll go through all those questions and tell us what the top five is. And so now, "What is the actual risk to the business if it isn't fixed? Are we already exposed or compromised? Which systems, applications, or services are affected? What is the timeline for full remediation? And how are we preventing this from happening again?" So what I would do is follow up with, "Generate brief answers to each question suitable for an executive audience." And this is going to give us answers to those questions.
And here are the top five answers. So now, "If unpatched, attackers could exploit this vulnerability. Are we already exposed? There's no evidence of exploitation found so far." We would definitely want to go confirm 100% if that's true. "The vulnerability is present in all of the production apps. What's the timeline? Full patching and validation will be completed by Friday, end of day, right? And then how are we preventing this from happening again? We're tightening our patch management processes and so on and so forth." So, we would go through these answers and make sure that they are speaking to exactly what we're doing. And if you want to add those questions to your email, you can use a prompt like this: "Please update the email and include the top five questions and answers as a TL;DR at the beginning of the email."
So as you can see, the subject line: "Urgent: We have a vulnerability, immediate remediation required." And then we show the TL;DR. "What is the risk if not fixed? Are we already exposed or compromised? Which systems are affected? What's the remediation timeline? And how will we prevent this in the future?" And here's your action required deadlines and so on. And then we say, "This is a critical and time-sensitive priority." Look how effective that email is right there. And just like that, you have created an actionable email that can go out to your team and explains exactly what they all need to know.
Now, here's what I want you to take away from this lesson. GenAI, as you saw, can turn rough notes into clear, professional emails fast. We want to use the RACE framework to define the role, action, context, and expected output. And then we want to fine-tune tone, call to action, subject lines, and summaries with follow-up prompts. You can use GenAI to tailor the content instantly for executives, GRC teams, or even engineers. And as you saw, GenAI can help you anticipate and prepare for stakeholder questions in just seconds. Unread emails lead to unresolved risks. But with GenAI, you no longer have to choose between speed and clarity. Now you can communicate clearly, confidently, and quickly, even during high-pressure moments.
Now, coming up, we'll explore how GenAI can help you write technical security reports that stand up to scrutiny without drowning your reader in a bunch of jargon. You're doing great. Let's keep going, and I'll see you in the next lesson.
Have you ever stared at a blank page after an incident and thought, "Where do I even start with this?" Writing technical reports can feel like the most thankless task in cybersecurity. You've just wrapped up a 10-hour incident response sprint, and now you have to document every step, every timeline, and every artifact. It's tedious, but it's critical. Now, here's the good news. GenAI can help you get 80% of the way there in just minutes. All you need is the right approach.
Reports are where your security work gets visibility, support, and impact. But let's face it, writing those reports often gets pushed to the end of your to-do list. GenAI can help you turn your raw findings into clear, structured, and professional documentation. Whether you're writing incident response reports, threat hunting summaries, vulnerability assessments, even penetration testing debriefs. And in this lesson, I'm going to show you how to turn raw notes into structured reports using the RACE framework prompts. You'll learn how to refine language and format for different stakeholders, how to use safe practices to redact sensitive data in AI prompts, and how to leverage GenAI as your report drafting assistant, not your replacement.
Now, let's be honest. Writing reports is slow and it's painful. Think about this. You just responded to a lateral movement incident. You investigated, you contained, and you eradicated. And now leadership wants a full write-up. But here's what typically happens. You open a doc, you freeze at the title, and you start writing, deleting, writing, and deleting. Why? Because documenting is hard when you want to get it right, but you're mentally drained and exhausted. And that's even harder when you need to write the report for multiple audiences. That's why GenAI can be your game-changer here.
So, let's walk through how to make GenAI your report co-pilot. So, before prompting anything, you need to start with the right format. Are you writing an incident response report, a vulnerability assessment, a threat hunting summary, or a pentest debrief? Each of these has different needs, different readers, and more. So, we want to keep that in mind as we're crafting our prompts.
Now, let's generate a first draft. Let's say you have some notes that say: "User J. Smith compromised. Attacker brute-forced login. Accessed SharePoint through SSO. Lateral movement to finance server. Found by anomaly alert 3 days later. No MFA. No confirmed X-fill." Okay, so that's pretty broken. So we'll open up our favorite GenAI tool. In this case, I'm going to use ChatGPT. And we will paste this prompt: "Act as a cybersecurity incident response analyst. Draft a structured incident report based on the following summary. Organize it into executive summary, detection timeline, and so on. The audience is mixed: technical staff and security leadership. The report should be professional, factual, and easy to follow. And use placeholders like username and hostname where needed." And then I have a section that says, "Here are my notes." So those are the notes that we took in our meeting. And now we want GenAI to create an incident report for us. So I'm going to send this off.
And in a matter of seconds, here comes our report. Incident Report: Unauthorized Access to Corporate Systems. So you can see that we have a date placeholder. We have a username placeholder, but we also have the username, and that's not a big deal. Was compromised through brute-force login attack due to absence of MFA. The attacker gained unauthorized access to SharePoint, carrying on via SSO, and laterally moved to the finance server. And in this case, we have a redacted hostname. Now, we have that in our inventory list. So, we could use that if we wanted to. An anomaly detection alert identified suspicious activity after 3 days. And at this time, there's no confirmed data exfiltration, but the potential is there. Okay, here's our detection timeline. There's our zero day, day three, day three plus, and so on. Affected systems. So we have some placeholders, and we can update those if we want, or we can leave them redacted. And then here's our root cause and some recommendations. So this is pretty incredible. Just in a matter of seconds, we got this information.
Okay. Now, what if the executive summary up here, what if this is too long? It's too much information. What we can do is we can add a prompt like this: "Please simplify the executive summary paragraph while maintaining accuracy." And now it'll rewrite this for us and just make it a little shorter, a little bit more concise and direct, because that's what executives want to hear anyway. They want to know where the real impact is. They don't want to read the entire document, right? So we just made this, we made it that much easier. We can even break this down into a table, bullet points. We can format this however we want to.
Now, what if we don't like the tone of this new paragraph? So, what we could do is we could rewrite this section to use an active voice and improve the clarity for the executive-level audience. So, I can run that, and now it updated it once again. And what if we want to make use of this entire report right away? What we could do is we can ask it to format this report with markdown headings and bullet points for each section. Make it copy-paste ready for internal documentation. So now what we can do is run that, and now it's going to give us a well-formatted document where you have a header, and you have bullets, making it easy to read. Detection headline, easy to read. Everything is very simplified now that we can drop this into a case management tool or we can paste this into any other internal documentation.
Now let's say that you need to turn this same report into something that a CISO can present to the board. What I would do is I would use a prompt like this: "Rewrite this technical report for a CISO audience. Focus on risk, timeline, and business impact. Limit technical terms and explain any acronyms." So, we'll fire that off. And now here is a fully updated report. The business risk was included in the summary. So, now, "This incident exposed sensitive finance-related systems to unauthorized access. While no confirmed data loss has been identified, the delay in detection increased the risk of potential misuse of financial or confidential business data." Then there's some timeline. There's the business impact, which is going to be very, very important to the board, the root cause of it, and the recommendations we have going forward.
Okay. Now, what if we want to send the original report to an internal auditor? What I would do is I would use this prompt right here: "Rewrite the initial report above for an internal audit team. Include control references for a NIST Cybersecurity Framework, affected assets, and remediation status, and keep the tone formal." And one other thing that I would do is I would add the IT inventory to this prompt. That way, ChatGPT or your GenAI tool can reference that list as it's creating the report. So I'll send that off.
And as you can see, here is the report. And now you can see here's an executive summary. Here are the key risks, the timeline again, the affected assets, and now this time it filled in a hostname because we gave it the inventory list. It even
Put the IP in here for us. And the user account is still redacted. And we could replace this easy enough. And here are our control references. Notice again that the controls only apply to the issue. You're not getting the full controls list, but just the controls that apply to the issue at hand. Here's your root cause, your immediate status, some recommendations. This is outstanding. And now you have two new versions that are customized for specific audiences. No rewriting anything from scratch. So, think of it as building your own cyber security report generator. This is awesome, right?
As we've discussed many times throughout this course, we never want to feed Gen AI sensitive data directly. We always want to use redacted placeholders like username, host name, IP address, company name, and so on. Here's why that matters so much. It protects your data, but it also makes your prompt reusable. You can save this prompt, update the placeholders, and generate a new report instantly the next time you need to.
Okay. Now, before we wrap up, let's work through a hands-on exercise real quick. I'm going to open a new chat and I want you to imagine that you are a threat hunter and you've just wrapped up an investigation. You jotted down some quick notes. Beaconing from application 2 and application 6 to known C2 domain endpoint isolated reverse shell blocked. No persistence. Fishing email was initial vector script ran when attachment clicked. Now, instead of sweating through an empty word doc, you hand this off to Jinai with a clear race formatted prompt. So, we can use a prompt like this. Act as a threat hunter, writing a post engagement summary based on the following notes. Draft a professional report with sections for executive summary and so on. Write clearly for a mixed audience of security leadership and analyst. Keep any placeholder tags for sensitive information. Reference the attached inventory list as needed. And then here are the notes. Beaconing from application 2, six, and so on. So, let me grab the asset inventory. I'll put that here. And then we'll send it off.
And as you can see, it's already starting to generate the report. Here's your executive summary. Malicious beaconing activity was detected originating for application 2 and six, which are both part of our application server environment. And it knows that because of the inventory list. The activity is linked to known command and control or C2. A fishing email containing a malicious attachment was confirmed as the initial attack vector and so on. And then here are the details. One thing to take note of is that chat GPT realized there's application O2 but application 6 seems a little fishy. We want to verify that host name and asset ID. So what if that was a temporary node that was stood up as part of the initial attack? Hm. We'd have to do some investigation, right? So there's some indicators of compromise here, the initial vector detection method, and more. And then here are our response actions. Here's the root cause, our lessons learned, so user awareness, patch management, and so on. So this is incredible. In just one prompt, we created all of this from our notes. This is how you turn half-scribbled field notes into a polished report in just seconds. See how each of them is clearly structured? It's easy to read, easy to scan, and it avoids drowning the reader in technical jargon. That's the kind of clarity that drives decision-making, not confusion. And remember, all it took was one solid prompt to get going.
Okay. Now, here's what I want you to take away from this lesson. Format your reports using markdown, bullets, and clear headings. Always redact real data with placeholders to protect sensitive information and also to build reusable prompt templates. Tailor your reports for executives, engineers, or auditors with follow-up prompts. Gen AI can get you 80% there, but your job is to add the final 20% that reflects your expertise and the factual information. You weren't hired to spend your day formatting timelines or rephrasing passive voice. You were hired to detect, respond, and protect. So, let Gen AI handle the first draft so that you can focus on what matters.
In our next lesson, we're going to look at how to write complex content for different audiences from analysts to boardrooms. You're doing great. Let's keep building your skill set and I'll see you in the next lesson.
Have you ever written a security update that left someone more confused than informed? Or maybe you provided a vulnerability report to leadership and got nothing but blank stairs in return. It happens more often than you think. Because here's the reality. One-size-fits-all communication in cyber security doesn't work well. Different audiences have different needs. They have different language preferences and they have different goals. And that's exactly where Gen AI can help you shine. As cyber security professionals, we don't just need to understand technical details. We need to explain them clearly and effectively. That means turning a finding into a boardroom update, rewriting a misconfiguration report for engineers, or even translating incident response notes into audit documentation. Each audience cares about different things. So, in this lesson, you're going to learn how to identify what your audience actually wants to know. You're going to use Gen AI to reshape technical content for executives, engineers, and compliance teams. And we'll walk through real examples from start to finish. So, let's dive in.
Now, picture this. You discover that an AWS S3 bucket is misconfigured. You write it up and you send the same report to your CISO, a DevOps team, and an internal auditor. Here's what happens. The CISO asks about business risk. DevOps wants to know which settings to fix, and audit wants to map it to SOC 2 controls. The same finding, but three completely different answers. If your message doesn't speak their language, you'll waste time explaining it three more times. That's where Gen AI becomes your communication sidekick. So, let's take the same finding and walk through how to tailor it for three different audiences using Gen AI. Here's the original summary. We discovered an S3 bucket named data-public-prod with full anonymous read access. The bucket contained internal company documents and was indexed by public search engines. Over 400 anonymous requests were logged. The bucket has now been secured.
Now, let's break this down and reshape it for each key audience. First, let's focus on executive leadership. They care about risk, exposure, and timeline. They don't care about configs or any technical jargon. So, here is a prompt that we can use. Act as a cyber security communicator preparing an executive summary. Rewrite the following cloud storage misconfiguration summary into a two-paragraph summary for the CISO. Emphasize business risk, potential data exposure, and the remediation timeline. Use plain language to avoid technical jargon. And then down below is the summary. So I'm going to go ahead and send that off. And here we go. So here is your two-paragraph summary. We identified a serious security issue involving a cloud storage bucket that was publicly accessible and so on and so on. And again, we can format this paragraph to be whatever we want it to be. From the previous lesson, I showed you how to break this down into bullets, markdown formatting, and more. So, we can work with this format as we see fit. If I were to deliver this to a CISO, this is way too wordy. I would break this down a little bit more. So, what I might do is use a prompt like this. Please break this down into easy-to-read paragraphs and include a five-bullet summary at the top. So now it'll reshape this for us. Key points. Cloud storage bucket containing internal documents was publicly accessible. Over 400 requests were logged. The bucket was indexed by search engines. Immediate action was taken and so on. And then here is the summary again. Okay, so this broke it down pretty easy. This I would deliver to a CISO because it gives exactly what they need right up front. Sometimes we call this bottom line up front and then you have the executive summary right here. Okay. Now this is a lot better because it shifts focus from configuration details to the bigger picture which is business risk and resolution.
Now let's focus on the team that's actually fixing the issue. This could be engineering, DevOps, or even a site reliability engineer, an SRE, and more. These are the folks that need specifics, not summaries. So here's a prompt we can use to do that. So what I'll do is I'll paste this. Act as a cloud security engineer documenting a storage misconfiguration for DevOps. Rewrite the finding using specific configuration details and recommended actions. Use technical language and keep it concise. So here we are. And now you can see we have our finding and we have our recommended actions right here. So this covers everything that a DevOps team would need to know about fixing this S3 bucket. Notice how this version removes any fluff and delivers straight up actionable steps. That's exactly what DevOps engineers would need in this situation.
And finally, let's turn this into something for the compliance audience. In that case, we can use this prompt. Act as a GRC analyst documenting a cloud misconfiguration for audit readiness. Rewrite the finding to include compliance impact for SOC 2 or even ISO, affected asset, timeline of exposure, and so on. In this case, what I'm going to do is I'm going to narrow this down to just SOC 2 so you can see exactly what it creates. So we'll run that. And now here you go. And then here is your finding, the affected asset, the timeline of exposure, and the compliance impact right here. This misconfiguration represents a potential violation of SOC 2 and ISO 27,0001. So even though we took it out of there, it still added it back because Gen AI knows how to predict what you're probably looking for. Then it goes on to say, "The incident also highlights a gap in the company's cloud configuration monitoring process and more." This is not good for us, right? Then there's also evidence handling as well. All relevant cloud trail and S3 server access logs have been preserved in a secured write-once S3 bucket for audit and forensic analysis. Of course, we would want to collect any other logs that might pertain to this as well and include those for analysis as well. So this version here checks every compliance box, control reference, exposure window, and documentation, and we can expand on this more as needed. So as you can see, we have the same technical issue with three different outputs. One for the CISO, one for the DevOps team, and another for the compliance or audit team. This is why Gen AI is so powerful. You don't need to rewrite everything from scratch. You just change your prompt. Pretty cool, right?
Now, let's do one more hands-on demo. Here's the raw input. A critical vulnerability in OpenSSH allows unauthenticated remote code execution. Our production servers are running version 8.3. Exploits have been observed in the wild. Now, let's start with how to explain this to a CISO. So, I'm going to open a new chat and I'm going to drop this prompt in. And as you can see, I have the finding down below. Act as a security manager writing a risk summary for the CISO. Rewrite the following vulnerability finding to emphasize business risk, operational impact, and the remediation timeline. Use clear executive-level language. And here is the finding right here. Okay. So, what I'm going to do is send this off. And in seconds, Chat GPT is already creating this summary for us. Critical vulnerability has been identified in OpenSSH and so on and so forth. It is a confirmed vulnerability. So that is something to be concerned with. The business risk is it could grant attackers full control over the affected server. That's not good. Operational impact, loss of system integrity and availability, unauthorized access to sensitive data, and extended downtime for remediation. The remediation timeline is that it should be done in 48 hours. Cut and dry. And this is very clear. This version simplifies the message while still conveying the urgency related to this. It's focused on decisions that the CISO will need to make.
Now, let's create the DevOps or engineering version. So, I'll go to my prompt library and I'll paste this. Act as a security engineer writing patch instructions for DevOps. Rewrite the finding to include affected versions, recommended mitigations, and specific host actions. And again, like we've done before, we can use our course artifacts and drop our asset inventory into this prompt to give Chat GPT some more information to work with. So, as you can see, here's the affected versions and the recommended mitigations, immediate restriction of access, patch upgrade, service hardening. Here's the host-level actions, and even some commands to run. And then here's how you do your updates right here. Then you can do some verifications, monitor and logging. And then here is the timeline. So this is pretty good for DevOps. This is exactly what they would need to see. If we want to expand more and we want to identify hosts and whatnot, we can follow up with more prompts. So this is short, technical, and full of actionable steps.
Now, finally, let's look at the audit version. Here's what we would send to our compliance team. Act as a compliance analyst preparing audit documentation. Rewrite the finding with affected assets, control references, patch status, and evidence handling. So, we'll send that off. And here comes back that summary. So we have that summary, the affected assets, we have relevant controls, the NIST Cybersecurity Framework, we have the CIS Controls, PCI DSS if that applies to us, patch status is the interim mitigation, then we have a plan, patching, evidence handling, evidence that's been collected, evidence that's in storage with a chain of custody, and so on. So this again is exactly what an auditor or even a compliance analyst would need to see. Do you see the difference in these different outputs? You've got reporting clarity across the board. And you can always ask follow-up questions that a CISO might ask, a DevOps engineer might ask, or even a compliance analyst or auditor might ask as well, such as has any data been exposed? What's the worst-case scenario here? How long was this in our environment? Are other systems vulnerable? And how are we preventing this in the future? Then we can follow it up with creating a short executive-level answer or a DevOps answer or a compliance answer to each of those questions. And by doing that, you're not just answering, you're anticipating. So just plug in your role and context and you're good to go.
Now, here's what I want you to take away from this lesson. Gen AI helps you adapt one message into multiple tailored outputs. Always use RACE-style prompts that define the role, action, context, and expected output to get the best results. Tailor your message to the audience. Risk for executives, action for engineers, and documentation for auditors and compliance. Ask Gen AI to help anticipate and answer stakeholder questions. And if you want to, you can build reusable templates with these prompts to help you save time and boost your clarity. You don't need to be a master communicator to sound like one. With Gen AI, you can translate complex findings into language that each stakeholder understands. And when your message lands, people will take action.
Now, coming up next, I'm going to show you how to take these audience-tuned messages and turn them into powerful presentations and briefings that drive real decisions. So, let's keep going and we'll see you in the next lesson.
How many times have you opened PowerPoint to build a security briefing only to spend hours just staring at the first slide? I mean, you have the data, you know the story, but turning it into something coherent, executive-ready, and visually engaging, that's the tough part. Here's the shift. Gen AI can help you storyboard, script, and structure your briefings in minutes. That way, you focus on your insights and not the formatting. At some point, presenting is a part of your job in cyber security, whether it's after an incident, during an audit, or while making a case for some new tools. But security professionals often lose hours building decks from scratch. The good news, Gen AI can help you draft full presentation outlines. It can help you generate clear speaker notes and summaries, recommend visuals and diagrams, and tailor your message for any audience. And by the end of this lesson, you'll be able to turn technical content into polished, professional presentations without wasting hours upon hours on slides. For example, let's say that you just finished an incident response and your manager wants a five-slide executive briefing by tomorrow. Instead of focusing on the message, you get stuck wondering, "What should each slide cover? How do I explain the technical content clearly? And what visuals do I need?" That's the trap. The content is in your head, but formatting and structure is what gets in your way. That's where Gen AI can help you.
So, let's start with a solid outline. So, let's say that you need to brief leadership on a threat report. Rather than starting cold, here's a really good prompt that you can use. Act as a cyber security communicator preparing an executive briefing. Create a five-slide outline to present the threat from the attached threat report and include the required mitigation steps to be taken. The audience is the executive leadership team. Focus on high-level risk, impact, response, and forward-looking recommendations. Each slide title should be clear and geared for non-technical stakeholders. So, what I'll do is I'll go to my course artifacts and I'll drag in that threat report sample. And now Gen AI will create a presentation for us. So here is our outline. Slide one is the targeted cyber threat. Here's what you need to know. Then slide two is what's at risk, the potential business impact, which is what really matters for executives. Slide three, how the attack works. Here's a simplified view of it. And then slide four, the immediate response actions that are needed. And slide five, the long-term recommendations. So, just like that, we have a slide presentation ready to go and we can expand on this if we want to. This outline gives you the structure instantly and we didn't waste any time staring at blank slides.
Now, let's fill in the content and add some speaker notes for each of the slides. Here's a prompt you can use. Act as a cyber security presenter. Create three bullet points and write speaker notes for each of the slides that explain the technical and procedural mitigations needed to address the threat in the report. The tone should be professional and concise. So, we'll send that off. And just like that, Chat GPT is going to create the slides for us. And if you notice, it started with slide 4 because that's where our mitigations are going to be. So, here's our three bullet points for our mitigations. Here are the speaker notes that we can touch on each one of the bullets. And then it also updated slide five as well with three bullets, speaker notes, and it even recommended a slide six as an option for executive actions needed. So if we need a decision to be made or we need authority to take action, this might be a slide to add to our presentation so that we get the required direction from the executives. Okay. Now to complete the presentation, let's fill out the remaining slides with this prompt. Please create three bullet points and speaker notes for the remaining slides. When you are done, please create a final presentation that is boardroom-ready. Use the exact language from all of the slides when creating the final presentation. So I'll send this off. And now AI will create this presentation for us. And as you can see, slide one now has bullet points and speaker notes. Slide two has bullet points and speaker notes. Slide three. And then here is the final presentation that we asked for. So here's slide one, two, three. Here's slide four. Here's slide five. And that's it. Now, if we want to create the slide six, we can. But at this point, we'll just keep moving forward. Look how clean and clear this content speaks with authority about that threat report.
Now, let's talk about visuals. You've got your outline, content, and speaker notes. But what if you want to diagram something that shows the threat? Here's a great prompt that you can use to do that. Act as a cyber security content strategist. Describe a visual to explain the attack flow of the threat from the report. Include any recommended diagram elements, images, and layout. And so we'll see what AI thinks we should use as a visual. So, as you can see, here's a diagram that it's recommending, and it's actually making it for you. And you can see that it has a complete step-by-step explanation of what to include in a diagram. And I'll scroll over so you can see the rest. And you can see that it's very MITRE ATT&CK-centric here. Then we'll scroll down and there's some detailed explanations of each stage. So for compromised vendor and supplier, it recommends an icon of a factory or office labeled "Trusted Vendor." And then for malicious software update, there is another icon that it's recommending. And then there's more icons that it recommends throughout each phase of this. Then there's some optional enhancements like color coding, impact callouts, overlays, and so on. So that's your visual blueprint. You can sketch it. You can use stock photos or images or icons. Or you can hand this off to a designer. You can even ask ChatGPT to create the image for you or create the diagram for you. There are also other AI tools out there like Midjourney and many others that can do this for you as well. If you want even more inspiration, you can use a prompt like this. Suggest three diagram types to visualize this threat in a technical presentation. So we'll send that off and AI will recommend three effective diagram types starting with the kill chain diagram. So again, when we are looking at the diagram, it felt very MITRE ATT&CK-friendly and even cyber kill chain-friendly, and now you have it. This is exactly why it's recommending that you can also use a network-based attack flow diagram and you can use a layered defense or a defense-in-depth diagram as well. So these are three options we can choose from and then we can ask AI to keep going further or we can design our own diagram. These options will help you think visually and avoid slides that look like walls and walls of text.
So now you have your content, you have your visuals, and you have your storyline. Now it's time to format everything into a final draft. So what we can do is combine everything together with this prompt. Update and format the final presentation above into a presentation-ready structure with slide titles, three bullets per slide, and complete speaker notes. Use the exact language you used above. The audience is for technical leadership. So now AI will combine everything we've worked on to this point into a final presentation. So here is your presentation title, the executive threat brief for AP41, which is a supply chain attack. Here's slide one with all the bullet points, the speaker notes, and then here's slide two with bullet points and speaker notes. Slide three with bullet points and speaker notes. Slide four and slide five. However, what's missing? A graphical diagram. I didn't see a diagram. So, we can always tell AI, "You forgot to include this. You did not include the visuals in the final presentation," and we'll send it off. And so now it will go and it will re-update this and then show you what visual should be included. There's the bullet points again, the speaker notes, and so on. And then let's scroll down. Here's slide two. Now you have a visual there. What it recommends, the bullet points, the speaker notes, the visual, everything is included now in this. So all we need to do is copy and paste this into PowerPoint or even ask AI to create the PowerPoint presentation for us and then we can download it. So this is pretty awesome. Your slides are almost ready for delivery and you didn't spend all day working on this.
Now the last step here is preparing for any questions you will definitely get in any presentation. So we can use this prompt and ask it to act as a security leader. What questions might executives ask after this presentation about the threat report, mitigations, or remediations? So now it's going to tell us what questions would be predicted from this presentation. The first question, "How do we know that we're not already compromised by this AP campaign?" The second question, "What makes this threat group more dangerous than others that we've tracked?" "Are there any current suppliers or vendors known to be part of this attack vector?" These are great questions. Then there's some questions about mitigations. "Do we currently have the capability to detect and block this malware?" "How effective is our vendor onboarding process?" And then there's some more questions. "What's the plan if we detect this?" "Have we tested our ability to respond to this?" And "How fast can we shut down vendor access if we are compromised?" And then there's some other ones that are related to investment and risk. "What do we need to do to close these gaps?" "Where does this threat sit in our overall cyber risk register?" And then also, "Are we over-relying on vendors that pose an outsized risk?" This is really great. Then there's some more questions. "Who owns the remediation?" "How are we tracking the effectiveness of mitigations?" And "What is our forward-looking strategy to stay ahead?"
Now, 15 questions is a lot to prepare for. So, what we'll do is we'll ask AI to narrow it down for us. From the questions above, select the top five questions you think would be asked and generate short, executive-ready answers to each of these questions. So, we're asking AI to pick the top five, and it's going to go ahead and show us what those are. "How do we know that we're not already compromised?" And then here is an answer. So, we can put this into our slide package as well. "Are there any of our current suppliers or vendors known to be part of this attack vector?" And then here's our answer. "Do we currently have the capability to detect and block the ShadowPad or similar malware?" And the answer is yes. And then we explain our tools. And then question four is "What's the plan if we detect it?" And then how we respond to it. And then five, "What do we need from the board or budget to close these gaps?" And then here's our answer. So, we can put these in another slide, like an FAQ slide, or we can just have them in our notes to be prepared. In doing this, you're not just delivering a great presentation. You're walking in fully prepared for anything that comes at you.
Now, do you want to open your talk with confidence? Maybe you can try this prompt. Using the final presentation above, write a one-minute verbal summary to introduce this briefing to the board. And we'll fire that off. And here is our boardroom introduction. And so we could put that in our slide notes or we can put that in just another script and read that as we start our presentation. And just like that, you have a complete presentation ready to go with your intro, your content, your storyline, your mitigations, and you even have everything formatted with visuals and so on.
Now, here's what I want you to take away from this lesson. Use Gen AI to generate slide outlines instantly. Add speaker notes and bullets with prompts like "explain this section." Ask for visual ideas, diagrams, images, or flowcharts that support storytelling as part of your presentation. Format everything with clear slide titles and audience-tuned bullets. And prepare for Q&A ahead of time using anticipated executive actions. Now you've got the knowledge, you've got the framework to turn it into clear, compelling presentations without wasted time. With Gen AI, your message becomes clearer, your slides become sharper, and your time goes towards the work that really matters. Now, in the next lesson, we're going to recap everything we learned in this section. So, head over there now, and I'll see you there.
Let me ask you a quick question. Have you ever done all the hard work, investigated the incident, analyzed the vulnerability, reviewed the misconfiguration, and then completely stalled when it came time to communicate it to someone else? Maybe you had a blank Word document staring back at you, or you had a draft email that didn't sound quite right, or you had to turn your findings into a board slide, and all you could think was, "How do I say this in plain language?" If that sounds familiar, then congratulations. You're human. And you're exactly why we built this section. In this final lesson, we're going to tie together everything from the "Creating Reports and Communications with Gen AI" section. You've learned how to write better emails. You've learned how to craft structured reports, tailor technical content for different audiences, and build presentations that actually get attention. Now, we're going to bring everything home. We'll recap the key lessons and then we'll go through a hands-on exercise to test your skills and a preview of what's coming next, which is your final project.
So, we started this section with emails because let's face it, emails are your frontline communication tool. They're also the most ignored. That's why you learned how to use Gen AI to go from messy notes to clear, urgent, action-focused emails in just seconds. Why did this work? Because you defined the role, the context, the audience, and the outcome. And that's the RACE framework in action. And when you wanted to tweak an email, you used follow-up prompts to rewrite the call to action and to add a TL;DR section for busy technical teams. With just a few extra inputs, you turned a decent draft into a message that gets read, understood, and acted upon.
Then we moved into technical reports. You learned how to turn your incident notes into structured summaries with sections like detection, root cause, and recommendations. You took raw findings and turned them into polished, professional documents without spending hours and hours of word-smithing.
After that, we zoomed in on one of the most important communication skills in cyber security, adapting content for different audiences. Same finding, different people, totally different messages. So you learned how to take a misconfigured S3 bucket and explain it three different ways: to the CISO, which is risk-focused, non-technical, short, and strategic; to the DevOps team, which is config-specific, action-oriented, and direct; and to the audit team, formal, controlled, referenced, and timeline-documented.
And then we wrapped up this section by building presentations and briefings. You learned how to prompt Gen AI for slide outlines, speaker notes, visual details, executive intros, and anticipated questions and answers.
Now, it's time to test it all. So, here's your hands-on exercise. Imagine this real-world situation. You're part of a security team at a mid-sized healthcare company. You just discovered a misconfigured firewall rule that exposed internal administrative interfaces to the internet. The issue was identified by your vulnerability scanner and confirmed through manual inspection. There's no evidence of compromise, but the rule has been in place for 3 weeks now. So, you need to do three things. You need to write an email to the DevOps team to fix this rule immediately. You need to write an executive summary for the CISO. And you need to write a briefing slide for an upcoming board presentation.
So, let's start with this prompt for the DevOps email. Act as a network security engineer. Draft an urgent email to the DevOps team about a misconfigured firewall rule exposing admin ports to the internet. Include IP ranges, urgency, and required fix. Use a direct and technical tone. So, you can see that I included the firewall host name and also the IP range that may be affected. So, we're going to send this off. And just like that, here is our email to the DevOps team. We've identified a critical misconfiguration in firewall 3 that requires immediate remediation. Here's the issue summary. And so here is the IP range that's allowed, which is all zeros, and that's really bad. And then our required action, which is immediate. We want to restrict access. Verify no other broad access rules exist and so on. So, what we want to do is we want to go back through this email and make sure that these IP ranges are exactly what we want them to be and that the firewall host name is correct as well. So, now we have our email ready to go.
Now, let's use this prompt to create our executive summary. Act as a cyber security communicator writing for a CISO. Summarize the firewall exposure issue, its business risk, and the resolution plan. Use non-technical language and a calm but serious tone. So now AI will create this executive summary. Here's what happened. Here's why it matters. Here's what we're doing about it. And we'll keep you updated if anything new arises. So this clearly gives your CISO exactly what they need to know. We have a problem. Here's where it's at. Here's why it matters to you. And here's what we're doing about it. Okay.
And finally, let's create the board slide. Act as a cyber security presenter. Create a board-facing slide titled "Recent Firewall Misconfiguration." Include three plain-language bullets explaining what happened, what was done, and what's changing to prevent recurrence. So, just like that, AI is going to create our slide for us. Here's what happened, here's what we did, and here's what's changing. And now we can use these bullets in our presentation to brief the board as necessary. And just like that, you have an email for action, a summary for strategy, and a slide for story. And don't forget, we can chain prompts to polish each of these versions. For example, we can add a TL;DR to the email, or we can make the CISO summary more concise. We can also suggest a diagram to show exposure timelines as well. And this exercise is a perfect test drive of everything you learned throughout this entire section.
Okay. Now, here are your key takeaways from this section. Gen AI can help you write clear emails, reports, summaries, and slides all from raw notes. Always use the RACE framework, role, action, context, and expected output, to get the best results. Tailor messages to your audience. Risk for executives, action for engineers and analysts, and structure for audits. Chain prompts to refine the tone, format, and clarity of the output. And think in terms of layers. One version doesn't just fit all, but AI helps you remix everything quickly. Every cyber security professional knows the tech, but the great ones know how to explain it, and now you do, too.
So, up next is where everything comes together. In the next section, you'll step into a real-world scenario and put your Gen AI skills to the test. There will be full workflows, multiple outputs, and all with one mission to prove to yourself that you can do this. And I'll see you there.
Welcome to the walkthrough of the final project for the AI Prompt Engineering for Cyber Security Pros course. Now, let me stop you real quick. If you haven't already completed the project or at least attempted it, I recommend you pause here. This walkthrough is not meant to give you the answers. It's meant to be your backup plan or something to lean on if you're stuck or want to compare your work after you finish the project. This project is your opportunity to show yourself and potential employers that you can handle real-world security operations using Gen AI as your co-pilot. You'll be working through a simulated security incident at a fictional company called Red Shadow Tech. And you'll also be operating across three different roles: security analyst, security engineer, and security manager. And each task builds on the last. And each deliverable matters. Now, you're not just writing prompts. You're solving a real incident. So, take your time, think like a pro, and treat this like your job. Also, all of the prompts you need for this project are in the playbooks. I'm going to use my own prompts for this walkthrough, which you're welcome to copy. However, there will be no download for these as this project is about you and your knowledge, not copying me. Okay.
So, with that said, let's dive into an active security incident. And let's start with task number one, which is to conduct alert triage. It's 7:15 a.m. and your incident queue is blowing up with alerts from Splunk, Cortex XDR, and Palo Alto Next-Gen firewalls. Your CISO pings you and asks, "Can someone figure out what's going on?" And that someone is you. Your job is to look through these alerts, identify what matters, and figure out where to dig deeper. So, you collect the following artifacts to help your investigation. You collect the Splunk raw alerts, Palo Alto Cortex raw alerts, Palo Alto Cortex malware alerts, and the Palo Alto Next-Gen firewall raw alerts. You also grab your threat report. Now, here is where Gen AI really helps. It will cut through the noise in all of these artifacts, identify indicators of compromise, summarize threats, and spot signs of lateral movement all in seconds. So, what we want to do first is we want to copy this prompt. From your prompt library, I'm going to use this prompt where you're a security analyst reviewing alerts from multiple sources. Analyze the Splunk, Cortex, and Next-Gen firewall logs provided. Clean the data, eliminate the noise, and identify up to five high-priority alerts that warrant immediate investigation. Group by severity, explain the context, and flag anything requiring escalation. So, I'm going to go over and grab the Palo Alto alerts. I'll drag those in and I will grab the Splunk alerts and drag those in. And then I'll run the prompt. And just like that, here we go. Now we have our high-priority alerts. And then it says, "Based on the analysis of Splunk, Cortex, and the logs I've isolated. Here's your top priorities. Splunk, you have an external command and control or C2 communication attempt. We have an XDR raw. We have a suspicious PowerShell execution. We have malicious scripts that have been detected. We have an outbound DNS issue. And we have an anomalous user agent from server issue." So those are the top five.
The next step is we need to ask Gen AI to compare any extracted IoCs to a known threat intel report that we've received. We also want to tell it to flag any matches and summarize any potential pivot points, such as systems that were touched by the same IP. So, what I'll do is go to my prompt library and I'll use a prompt like this. Using all of the information above, thinking like a security analyst, correlate the high-severity alerts against the IoCs listed in this threat intel report. Highlight any matches. Then identify any potential signs of lateral movement or suspicious pivoting between systems. Now you can add the threat report again, but it should already be in memory. So I'm just going to go ahead and run this. And here you go. So now it's correlated everything. And now you can see our table that shows an indicator of compromise match. Shows where the log source is. And then it shows lateral movement and pivot analysis, the suspected lateral movement chain. And it also gives us an hypothesis of the attacker's path. And then here's some red flags for immediate review, which is awesome. And then some recommendations for our tactical response to this.
Now, this is a lot of data. So, what we want to do now is ask for a short narrative summary that outlines what happened and which alerts need escalation. So, I'll go to my prompt library. I will copy a prompt like this. Acting as a security analyst, create a short triage summary. Include two high-priority alerts, any matching IoCs, signs of lateral movement, and any outlier anomalies that require further investigation. Format clearly and professionally, like an initial SOC handoff report. So now what I'll do is send that prompt off. And here we go. Now we have a summary report with everything that we need to know. Now, why do I want the two high-priority alerts? Because we can only handle so much at one time. These are the two that we really need to take a look at before we consider the other findings. Does that make sense? So now we have this summary. Now, hopefully, you got an output similar to this. And what I want you to do at this point is take a step back and ask yourself, "Would this summary help another analyst hit the ground running?" If the answer is yes, then you have everything you need for task one. If you're not happy with the output, challenge AI and keep asking it for more information until you're happy with it. Then copy the summary of the identified high-priority alerts, the correlated IoCs, pivot points, those kinds of things, and copy that into a document called the "Task One Triage Summary" and save that off to your project folder. Now, remember, this task sets the stage for everything else. So make sure that you have everything saved in the document. The prompts, AI model, and other factors don't matter. What matters is the output.
Okay, so that takes us to task two, and that's to conduct vulnerability analysis. So now we know something happened, but how? Where did the attacker get in? And how do we figure out which doors were left open? Maybe there's an unpatched system in production. Maybe a dev server has weak authentication. This is where we dive into the vulnerability analysis phase and find out. So you're still wearing your security analyst hat here. Now, this time you're going to use the following input artifacts to perform a vulnerability analysis. We're going to use the Nessus scan results, the Red Shadow asset inventory list, and the task one triage summary. Now, to look for vulnerabilities that could have been used in the attack within these files, you can use a prompt like this. As a security analyst, analyze the attached Nessus scan results. Summarize all critical high CVEs by CVSS score and identify affected systems from the asset inventory. Prioritize them based on business impact, external exposure, and potential for exploitation. Highlight anything that overlaps with known IoCs from task one. So, what I'm going to do is drag the task one triage summary over. I'm going to grab the asset inventory and I'm going to grab the Nessus scan results. And then I'm going to send this prompt off. Now this might take a minute, but now here you go. Here is our output. And as we scroll down, we can see the CVEs that were found, the CVSS scores right here, the exploit is available, the risk is critical, and then how many systems are affected by this. And you can see the host names affected, their IP addresses, the CVEs, the scores, everything's been correlated for you. Here's the IoC correlation from task one. And the web server looks to be an issue. So we need to take a look at that. Here's some key observations that were made as well, and also some recommendations. So this is fantastic.
Now from here, we want to follow up and ask AI to provide additional research on top of the CVE risks, including whether they are actively being exploited in the wild, if there are known exploits, and what the suggested mitigation steps are. And we also want to ask for links to the MITRE CVE database. So I'm going to go to my prompt library and I'm going to copy this. I'm saying, "Still act as a security analyst. We're looking for high-risk CVEs. Provide detailed summaries including the descriptions, CVSS scores, exploitation in the wild, current patches or workarounds, and links to MITRE CVE database." The reason I'm using this prompt is because sometimes AI will not give you all of the details. We've got a really good output up here, but you can run the same prompt, the same way, with the same model, and get a completely different response. So, I'm trying to train AI to think the way I'm thinking. So, what I'm going to do is send this off. And here is our output. And it gave us a couple different CVEs to take a look at. Here are links, patches to Microsoft, which is fantastic. More CVE links, which is good. And then here is our summary. So now if we look at CVEs with the high-risk, are they exploitable? Yes. Is there direct IoC overlap? Yes, on this web server. And then with the other ones like the remote command injection for the firewall, there's not a direct overlap, but there is a perimeter risk. So this is kind of an Easter egg. We're finding more and more vulnerabilities within our system just as we're chasing down this one threat report. Also, we have a router access and traffic control issue, and there is a lateral pivot risk there. It's not directly related to our IoCs, but it could be something that could be leveraged, and this gives us something to dig deeper on. So our immediate security actions are already laid out for us where with high urgency we need to look at the domain controllers. We need to look at the Palo Alto firewalls. We need to look at the Cisco routers, and we also need to look at the web server.
Okay. Now, finally, we need to look for any patterns. For example, do any of the vulnerabilities relate to indicators from task one? Are they the same CVEs that keep showing up in both environments? Whether it's development, production, or what have you, these are clear red flags for us. These could indicate a wider misconfiguration that deserves deeper attention. So to dig a little deeper, we could use a prompt like this. Still acting as a security analyst, look for patterns across the environment. Are the same vulnerabilities present in production and test? Flag any systemic misconfigurations or old software that might increase lateral movement risk. So I'll send that off. And here we go. Here's our summary and here are all of our CVEs and they're across the production host, the test and dev host, whether they have known exploits and the criticality. Scroll down a little bit more. Here's some systemic misconfigurations or outdated platforms and you have a dev workstation that's running CentOS 7 and it has some older CVE. So, obviously, it hasn't been updated. That's probably something for us to take a look at later, but not
right now. Here's some other observations and some recommendations going forward.
So, this is fantastic. So, what we want to do is copy this output and put it into a document called the task 2 vulnerability analysis report. And then we want to save that off to our project folder. Also, think about which vulnerabilities would be prioritized in this organization and why. Is AI correct here? Is this how you would approach it? And also think about what systems or teams would be impacted by this and how does Ginai help you balance the risk versus the reality here. Okay, this is where you really discover the power of using Ginai as your sidekick.
Okay, now that brings us to task three. This is where we're going to perform threat intelligence correlation. Now we've seen the alerts, we've identified the holes, but we need to ask who's behind this? What tactics are they using? and is this part of a known campaign? And at this point, we're still in the security analyst role, but now you're putting on your threat hunter glasses.
So to start this task, we need to extract indicators of compromise, things like IPs, file hashes, domains, and any other useful data from the provided threat report. So we need the task one triage summary, the task two vulnerability analysis report, and the threat report from earlier. So, I'll go to my outputs and I'll drag in both of those documents. And then I'll go over and get the threat report as well. And then I'm going to go to my prompt library and I'm going to copy this prompt.
As a security analyst, review the attached files and extract the IoC's from the attached threat report. Identify any known threat actor campaigns or AP groups linked to those IoC's or TTPs and then summarize your findings. So, I'm going to go ahead and run that. And then here is our report. So now we have a summary. And so now we have basically a command and control beacon infrastructure issue. And so that's part of the OC. Then we also have our domains. There's our file hashes. Man, there's a lot of great data here. Here's our TTPs for a MITER attack. And then if we keep scrolling down, here are the known threat actors. So here are the threat groups. There's AP29, FIN 7, Muddy Water, and so on. So these are active techniques being used in the wild. And then here's our summary for alert correlation. So that's great.
Now, the next thing that we need to do is ask AI to correlate these IoC's and TTPs with the ones found in task one and two. We want to ask it if any CVE identified earlier is known to be targeted by these actors or a campaign. So, I'm going to copy this prompt and I'm going to switch gears and look at things from a threat point of view.
So, as a threat analyst this time, correlate the extracted IoC's and TTPs against the alerts summarized in the task one triage summary and the vulnerabilities outlined in the task two vulnerability analysis report. Then it's going to highlight anything for me and it's going to call out any patterns or links that we need to pay attention to. So I'm going to send that off. And just like that, here is our correlation report. And you can see clearly that there are matches. So you have an IP address that came from Splunk and it is flagged as a command and control from one of our storage nodes and it matches an IoC threat report. So that is a big concern for us. We also have our hashes. These are known for PowerShell script attacks as well. And there's a few others that we can go through. Then there's our TTP mapping that maps directly to the technique, the observed evidence that's in our files, the host that's affected, and the correlation. So this is powerful right here. Then we have our CVE exploitation risk. And we also have the chain of activity and attack progression. And then when we go down here, you'll see the key risk patterns and takeaways. And that's really what I want to know. Attackers are moving through staging to production via shared systems. Wow, that right there is incredibly insightful. You now know the attack vector, how they're getting into the node. That's awesome. Now go down here to the analyst recommendations. We need to isolate those immediately because that's the attack vector. Then we need to take care of this web server and so on. This is incredible right here. I didn't expect to see this much data.
Now what we need to do next is map those TTPs to the MITER attack matrix, the cyber killchain phases, and the CIS controls. And we want to ask it to flag where any current defenses might be falling short. So I'm going to go to my prompt library and I'm going to use this prompt.
Still acting as a threat analyst. Map each tactic you discovered above to the MITER attack framework and align them to the cyber killchain phases. Also identify any relevant CIS or CIS controls that should mitigate these behaviors. So now we'll go ahead and run that. And look how fast that comes back. And so now we have our behavior mapping. So here is the kill chain reconnaissance weaponization delivery and so on. Here's the MITER tactic. Here's the technique. And I'm not seeing CIS controls. So it might be right here. Here we go. Here's the minor attack technique. Here's the CIS control. And then here's the description. So you'll see all the controls that apply here. And then here's our gaps and weaknesses. So we have a staging zone monitoring issue. We have a PowerShell auditing issue, patch management, egress control, and more. So then when we go down and we look at the summary and we look at the killchain phases here, the threat actor success defenses that are triggered and then are the controls weak and you can see that pretty much across the board we have weak controls. So we have weak defenses in place. So here is the analyst recommendation to bring us up to compliance pretty much and then we're going to go ahead and chase this a little further.
Now, by the end of this, you should have the complete picture of how the attacker operates, how they may have compromised red shadow tech. Do you see how correlating alerts and vulnerabilities with intelligence adds context, reveals intent, and strengthens detection and response strategies? It turns noise into narrative, and helps justify decisions to leadership. And that's exactly what we want here. Now, what we want to do is copy this output from this prompt and paste it in a document called the task 3 threat intel correlation report. And then we want to save that off to our project folder.
Now, that brings us to task four, reviewing configurations and policies. We're going to change roles and act like a security engineer. Your job in this task is to close the doors that were left open. In this task, you will use many different input artifacts like the task three threat intel correlation report, the PaloAlto configs, Azure security group configs, Palo Alto cortex configs, and then our organizational policies as well. And your job here is to make sure what's running in production and the other environments actually matches what your policies say you're doing. So we want to start by telling Genai you're reviewing system configs for PaloAlto nextG firewalls, Cortex XDR and Azure. Then we want to ask it to analyze the configs for common misconfigurations and compare them to industry best practices or CIS benchmarks.
So I'll go to my prompt library and I'll paste this prompt.
Act as a security engineer. Carefully review all of the provided configuration files based on the threats identified in task three threat intel correlation report. Identify any misconfigurations, missing rules, and so on. And then cross-check those against relevant CIS controls and then also document any critical issues or areas that do not align with the recommended CIS benchmarks. So I'll drag all of the configuration files, the one from PaloAlto Cortex, the NextG firewalls, and also the Azure security group. So we'll go ahead and run that.
Now here's our summary. You can see we have some findings. There is a suspicious domain. There is the staging outbound command and control. And there's no EDR detection rule for this CVE. So those are problems. We have some critical misconfigurations. Wow, the Azure network security group is overly permissive outbound. That's not good. There's some missing XDR policy. So, we have a lot to go through here. And then here are some suggested remediations and hardening. So, the NextG firewall needs some help. The Cortex XDR needs some help. The Azure network security groups need help. And then here is our control alignment. So, we're partially meeting these controls. And then here are our key takeaways.
Now that we have that, we need to compare the actual configurations to the organization's policy documents and ask AI to highlight any misalignments or recommended specific actionable fixes for each one. So I'll go to my prompt library and I'll paste this prompt.
As a security engineer, compare the attached system configurations to the organizational policies. for each policy area, identify where the implementation in live configs deviates from the stated guidance in the policy. So, we're going to compare the configs against the policy and see what is non-compliant. And we're going to do that against the CIS controls and then we're going to ask for a table that shows the policy and what's missing. Okay. So, what I'm going to do is I'm going to go grab the policies and then I'll also drag in the configuration files and then I'll send this off.
And just like that, it's already done its analysis. And now you can see that there is a TLS decryption policy. That's non-compliant. We have an RDP access control issue to take a look at, an outbound traffic filtering issue to take a look at. Also we have an application aware control issue. We have a staging exposure which we already knew. And then we have some change control and rule hygiene endpoint policy enforcement. And then here is our summary. And it also shows us our controls and everything we need to make a sound decision going forward.
Now we want to take this output and put it into a document called task 4 recommended updates. Now, how confident are you that your configurations match your policies right now? This task closes the gap between intention and execution. It helps your team uncover blind spots and prevent attacks caused by configuration drift or outdated assumptions before auditors or attackers find them. And this will feed directly into your remediation plan, which is the next step.
And that brings us to task five, where we're going to create a remediation plan. Now it's time to bring it all together. You're still in the security engineer role, but now you're building a plan that leadership and tech teams will follow. In this task, you're going to need outputs for task two, which is your vulnerability analysis report, the task three threat intelligence correlation report, the task four recommended updates, and you'll need the asset inventory list. What we want to do here is merge all findings from the vulnerability report, threat intel, and config review and create a complete remediation plan.
To do that, I'll go over to my prompt library and I'll use a prompt like this.
As a security engineer, create a remediation plan that combines all previously identified vulnerabilities, threat intel findings, and configuration gaps. Group them. Give me a priority level based on risk and exploitability. Use the asset inventory to link each issue to the specific systems and then for each group suggest a realistic timeline for resolution. So I'm going to grab the three outputs from the previous tasks. I'll drag those in. Then I will grab the asset inventory and we will execute this prompt.
And so now you can see chat GPT has already done the work. Here is the critical which need to be resolved in the next 3 to 5 days. So you can see these CVEes of course it's on the web server that we've already seen a few times and then you have some highs that need to be resolved in the next 7 to 10 days and then some mediums that need to be resolved within the next 2 to 3 weeks and then some lows which can wait for 30 to 45 days. Okay. And then here's your summary of prioritized fixes and the suggested timelines by tier.
Now this is awesome. The next thing we want to do is add some technical guidance. And we can do that with a prompt like this.
For every remediation action in your plan, provide detailed technical guidance. Include implementation steps, any prerequisites or dependencies, and call out quick wins that can reduce risk fast. Also mention any operational risks or impacts associated with each action. Okay, so it already knows we're a security engineer, so we don't need to prompt that again, we can just run this and it will go right through the remediation plan and tell us exactly what needs to happen.
Now, here is our detailed technical remediation plan. So again, we have our critical issues and then we have the implementation steps that it included for us. So that we identify the domain controllers, we apply the patches, we enable domain controller enforcement mode via GPO which is group policy object and then we monitor the event and it will tell us what to do for every single one of these findings which is outstanding. So as you see here's the PaloAlto where we want to upgrade the version. We want to revalidate the config and then conduct a config diff to detect any persistence and then here's the high issues and so on. Now you can see that as we go through that chat GPT is getting a little lazy in terms of the steps. So what we can do is we can follow up and ask it to give us more or we can just go forward. Okay. And I'm going to scroll down to the bottom and here you go. Now we have a complete remediation plan for the ones that we really care about. And we also have the technical guidance for each finding. We have prioritization, clarity, and context. And this task helps our organization move from analysis to action. It also ensures that fixes are achievable, aligned with business priorities, and communicated clearly across teams. And that's it for task 5. So what we want to do is copy this output, paste it into a document called task 5, unified remediation plan, and then move on to task six.
Now in this task, we're going to generate our reports. We're going to take on the role of a security manager. Now, and your job here is to translate all that technical work into formats for different teams and different stakeholders so they can act upon them. So you'll need the outputs from task 2 through 5, the network and edr policy and the CM policy as well. In this step, we need Ginai to start by drafting a detailed technical report based on tasks 2 through 5. Also, we want the target audience to be the engineering team. So the tone can be technical and direct.
So what I'll do is I'll go to my prompt library and I'll use a prompt like this.
You're acting as a security manager, preparing a technical report for engineering teams. Use the findings from tasks 2 through 5 to write a detailed document that includes affected systems, vulnerabilities, threat mapping, and more. And then keep the format professional, direct, and focused on actionable technical content. And then include any references to any policies that were evaluated, and so on. So, what I'll do is I'll grab all of the outputs from tasks 2, three, four, and five and send this off.
And now here are the technical security findings and the remediation report. And as you can see, it's even calling out task two, calling out task three. So, what it's doing is it's letting you know where it got this information, and that's really helpful. So, now we know that it's not hallucinating. It's not making anything up. It's referencing our documents and giving us what we need. So, this is perfect. Here's our remediation plan summary. And here are the reference policies that have been evaluated. And as you can see, it still has these policies from memory, which is great. And then here's any final notes for the engineering team. So, what we want to do now is save this output as the task six technical security report.
Next, we need an executive briefing. So, we want to tell AI to summarize the incident, impact, and the next steps in language appropriate for leadership, and we want to keep it concise and focused on business risk. So, I'll go to my prompt library, and I'll use a prompt like this to do that.
Act as a security manager. Summarize the incident and investigation output for an executive audience and focus on what happened, business impact, the top three risks, and what actions are being taken to resolve them. Okay? And then use plain business language and so on. So what I'm going to do is go ahead and send this off.
And so now here is our executive level summary. Here's what happened. Here's our business impact. And here are the top three risks identified. Also, here are the actions that are underway where we're doing emergency patching. We've already blocked outbound access. We're reviewing any firewall or network ACL rules. We're restructuring endpoint protection and so on. Now, what's really important to take away from this step right here is in the real world, we want to make sure that status is accurate. AI can hallucinate and make it up. We want to make sure this is exactly what's been achieved, what's in progress, or what is planned. Okay? That way, we're communicating accuracy back to the executive leadership. And here's some immediate leadership considerations. So, support emergency patch windows and so on and so forth.
So, now what we want to do is we want to save this off as the executive briefing presentation. So, this is the task six executive briefing presentation. So all you'll do here is you'll just highlight each one of these sections and paste these into PowerPoint slides or Google Slides or whatever you prefer and then we can use this artifact later on. Okay.
Now next because some of the configuration changes will be needed. We need to ask for a change control board request that outlines what changes will be made to which systems and why. So here is a prompt we can use for that.
Based on the remediation plan, create a formal change request for the CCB. Include affected systems, timelines, risk assessments, and required approvals. Then generate a short teamspecific summary for network, DevOps, and IT teams. Okay, so we'll send that off.
And here is our change request. So you can see there's a description, the affected systems, the risk assessment, the required approvals, the summary of changes that are going to be made, and the team specific summaries as well. So you can see that it gave us exactly what we asked for. And now we want to save this final artifact off as the task six team action summaries. And there you go. You have all of the reports and presentations ready to go. This ensures that everyone understands what needs to happen, why, and by when.
Now, it's time to log everything into your ticketing system. That brings us to task seven, which is to update case management tickets. Even worldclass incident response falls flat without good documentation. So, we need Genai to create concise, professional ticket updates for each phase of the investigation.
So, with our security manager hat still on, we can use a prompt like this to do that.
As a security manager, updating case management records, summarize the key findings and actions from each phase of the investigation. For each task, create a concise ticket that documents what was done, what was found, and what happens next. Then, make sure the language is professional and understandable for both technical and non-technical stakeholders. And then include any links or file names, things like that. Okay. So, we'll send that off.
And now here are our updates. You can see that it's still referencing task two. So, it's going back to a known document and it's tying it back to that, getting its data from there, which is great. Here's the key findings, the next steps, and so on. And then here's a ticket for threat correlation, a ticket for configuration policy evaluation, and so on. So, we can drop this straight into any tool like Jura. We can drop it into service now and so on. And I'm going to keep scrolling down. So you can see here's a summary.
And now what we want to do is take this output and create a document called task 7 case management updates and save that off into your project folder. Good ticketing provides traceability. It meets compliance standards and it helps others learn from past incidents. This task builds trust and ensures that your team's work stands up to audits, retrospectives, and real world scrutiny.
Okay, now that brings us to the last task, which is task eight, to provide team communications. Now that we have all of our artifacts created, it's finally time to communicate. For this task, you're going to need a few artifacts as your input. Task five, task six, and task seven artifacts. Then we'll ask Genai to create three separate messages. One for the technical teams that includes step-by-step instructions, one for leadership with a status update and an estimated timeline, and one for non-technical stakeholders explaining any impacts.
So, instead of using three different prompts, I'm going to use one single prompt to do that.
As a security manager, reference the attached documents and create three types of communications. First, write a detailed message to the tech teams. Second, write a highlevel progress update for executive leadership. And finally, draft a short communication for affected business stakeholders. So, what I'm going to do is grab all of the artifacts from five, six, and seven. Place those in here. And now it's ready to go. So, I'll send this off.
And boom. Just like that, we have three messages ready to edit and send. And then there's even some reference links. There's a clear message here. Here are the tasks for the network team. As you can see, there was a little error in chat GPT. So again, that's why we edit and we make sure everything's correct. Here's the DevOps team. Here's some more missing documents. It's kind of weird. Looks like the link had an issue when it was running the code, but you can see that pretty much everything's here. So this is exactly what we want. Here's the executive briefing. That's pretty much the same as the presentation we created earlier. So, we can always ask it to rewrite this and make it an email or we can ask it to do something different. And then lastly, here is the business stakeholder notice where we're going to go ahead and send this out. Let them know what to expect. Here's the timing, any questions, call our sock or call customer support and so on. So, we'll take this, we'll save this output to a document called task 8 communications and then place that in your project folder.
And that's it. You've just completed a full cycle security operations incident using Genai as your co-pilot. From triage to threat intelligence to exec reporting, this is what real pros do every day. Imagine how long this would have taken if you had to do this manually. This would have taken hours, if not days, maybe even weeks. Instead, you did this in about 30 minutes. And that's with me talking over everything. And all of the artifacts that you created in this project aren't just a portfolio piece. It's proof that you can work across roles, communicate across audiences, and move fast with the help of Genai.
Now, once you've completed the entire project, here's the final step. Upload all of the artifacts you created and paste this prompt into your Genai tool.
I've just completed a simulated real world incident response project for Red Shadow Tech. Attached are the project instructions. Act like an AI prompt engineering for cyber security pros instructor and review my output documents from each task. Triage, vulnerability, threat intel, config review, and so on. And compare my output documents to each task requirement in the project instructions. Create a scorecard that ranks my performance on a scale of 1 to five. One being poor, five being excellent. The scorecard must provide a final score. And then for any task requirements that score between one and three, identify any inconsistencies, gaps, or areas for improvement. At the end of the scorecard, provide detailed feedback and suggest improvements for professionalism, accuracy, or clarity that will help me be a more effective AI user in real world security roles. So, this will score your project. And once you run this self-grading prompt, I have to ask, how'd you do? I'm sure you did awesome. And you're always welcome to complete this project again. Go back, fine-tune your prompts, polish your documents, and be proud of the work that you're doing here. Because the next time you walk into an interview, you won't just talk about your Genai skills, you'll show them. I hope you enjoyed this final project and I hope to see you again in another Dion training course.