Výukový SIEM systém s podporou generativní AI pro analytiky L1

Abstract

The aim of this thesis is to design and implement a training SIEM system that enables L1 analysts to practice on realistic synthetic incidents inspired by real threats and public CTI sources. Realism is achieved by leveraging public databases of vulnerabilities, malware, and other threats, which an AI system uses as input seeds for generating training incident scenarios. The solution also includes an AI-based evaluation module that automatically checks the correctness of the verdict, the completeness of the analytical comment, and provides feedback with recommendations for improving report quality.

Description

Delayed publication

Available after

Subject(s)

SIEM, SOC, L1 analyst, alert triage, incident response, generative AI, Node.js, React, OpenAI API, web application, incident simulation

Citation