S SanRa
SAN-101 · Free
  • All courses
  • Overview
  • Main site

Access required

Open your free access link

This course needs a personal access link. Request one on the training portal.

Get free access →

SAN-101

Thinking with AI

  1. 01 · Threat landscape
  2. 02 · Analyst toolkit
  3. 03 · Calibrated trust
  4. 04 · Skill maintenance
  5. 05 · Governance
  6. Knowledge check

0 / 6 complete

Module 01

The AI-Shaped Threat Landscape

Threat reality versus hype — what AI actually changes for analysts.

What you will cover

  • AI-enabled social engineering: deepfake voice and video, spear phishing at machine scale, synthetic pretexting
  • LLM-assisted adversary workflow: reconnaissance, phishing infrastructure, malware iteration and evasion
  • Agentic attack chains and machine-speed recon — what compresses, what doesn’t
  • Separating demonstrated capability from marketing: evidence-based threat perception

Practice prompt

Collect three recent “AI threat” claims from news or vendor blogs. For each, write one sentence of demonstrated evidence and one sentence of speculation. Recalibrate your prior with base rates, not narrative hype.

Human factors lens: threat perception under novelty — how availability bias and narrative hype distort analyst priors, and how to recalibrate with base rates.

Module 02

AI in the Analyst’s Toolkit — Power & Failure Modes

Copilots, triage, and the hallucination problem in live workflow.

What you will cover

  • The AI-augmented SOC stack: copilots, LLM-assisted triage, alert summarisation, detection engineering assistants
  • Prompt-driven investigation: structured querying of logs, pcaps and intel through natural language
  • Failure modes that matter: hallucination, confabulation, sycophancy, silent omission, prompt injection via retrieved content
  • Local vs. cloud models: data handling, evidential integrity and client-confidentiality boundaries

Practice prompt

Ask any copilot to enrich an unfamiliar IOC. Demand sources. Note where it invents a CVE, vendor, or attribution. Write a three-line “trust-but-verify” checklist you will use under deadline pressure.

Human factors lens: the automation conundrum — the better the tool, the worse the operator’s catch rate when it fails.

Module 03

Calibrated Trust: Automation Bias & Vigilance

The core human factors module — matching confidence to demonstrated reliability.

What you will cover

  • Automation bias and complacency: evidence from aviation, medicine and process control — and its arrival in the SOC
  • Algorithmic authority: why AI output feels more credible than a colleague’s, and when that’s rational
  • Alert fatigue 2.0: AI-generated detections, triage queues and vigilance decrement
  • The out-of-the-loop performance problem: losing situational awareness in systems you nominally supervise
  • Structured verification protocols: second-channel confirmation, provenance checks, dissent-by-design in team review

Practice prompt

Design a one-page verification protocol for “AI recommends close”. Include: when to escalate anyway, what second channel to use, and how to record the dissent.

Human factors lens: calibrated trust as a trainable skill — matching confidence to demonstrated reliability, per tool, per task, per context.

Module 04

Skill Maintenance in an AI-First SOC

Keeping tradecraft alive when the model drafts the first pass.

What you will cover

  • Cognitive offloading and skill degradation: what deskilling research says about analysts who never draft the first pass
  • Verification-before-output: reading AI drafts like a hostile reviewer, not a grateful recipient
  • Deliberate practice: manual-first drills and “AI-shadow” exercises (do it yourself, then diff against the model)
  • Where AI must not be used: evidential chains, legal thresholds, novel intrusion sets, client-attributable judgement calls

Practice prompt

Schedule one AI-shadow drill this week: investigate a small log or ticket manually first, then compare to an AI draft. List two things you caught that it missed, and one thing it caught that you missed.

Human factors lens: the “use it or lose it” curve — designing a personal practice regime that fits inside a working week.

Module 05

Governance, Accountability & Capstone Thinking

Auditable AI-assisted work — what lands on an analyst’s desk in practice.

What you will cover

  • Governance frame: ISO/IEC 42001, NIST AI RMF, EU AI Act awareness — practical implications for analysts
  • Accountability when the AI is wrong: logging, provenance and auditability of AI-assisted decisions
  • Writing reports that disclose and defend AI assistance
  • Team-level controls: AI-use policies, peer review, escalation triggers

Capstone prompt (self-paced)

Write a short client-ready summary of a fictional incident in which AI assisted triage. Explicitly record: what the AI produced, what you verified, what you changed, and who owns the conclusion. Then list two injected-error patterns you would hunt for under time pressure.

Human factors lens: debrief what the team delegated, what it verified, what it missed, and what changes on Monday.

Assessment

Knowledge check

Four scenario questions from the SAN-101 item bank. This is a learning check — not a formal certification exam.

Q1. An AI copilot summarises an inbound alert and concludes “no further action required.” Your queue is long. The calibrated response is to:

Silent omission is the highest-consequence, lowest-visibility failure mode of AI triage. Closure recommendations earn the same structured verification as escalations. (Module 3)

Q2. Which failure mode is most likely when an LLM is asked to enrich an unfamiliar indicator of compromise?

Confabulation is the default failure on low-knowledge queries. Provenance checks are mandatory on enrichment output. (Module 2)

Q3. After six months of AI-first drafting, your manual log-analysis speed has measurably dropped. The human factors term and correct countermeasure are:

Deskilling is the predictable cost of never drafting the first pass. Counter with structured practice regimes. (Module 4)

Q4. An AI-assisted incident conclusion is auditable when:

Accountability attaches to people and records, not policies or vendors. (Module 5)

–

Free online edition for individual learning. Not CPD-accredited. Not (ISC)² accredited. Not a substitute for instructor-led delivery.

© 2026 SanRa All courses · Main site