21 October 202612:30–14:30 CEST
Online
120 min·Track: Technik
Which concepts, taxonomies, methodologies and frameworks formalise a Cyber Threat Model — and what has to be true before a machine, or an AI agent, can act on the result?
Lerninhalte
- Part 1 · Cyber-domain-specific frameworks, taxonomies and concepts (approx. 30 min)
- 1.1) Detection Maturity Level (DML) model — levels 9 … 1, from goals to atomic indicators
- 1.2) MITRE ATT&CK as a taxonomy; MITRE CAPEC, CWE and CVE as a classification model; CPE naming
- 1.3) STRIDE; the Diamond Model of Intrusion Analysis; environmental effects; Intelligence Preparation of the Cyber Environment
- 1.4) STIX 2.1 — Structured Threat Information Expression: the typed object graph
- 1.5) CBEST and TIBER-EU — where the requirement comes from: deliverables read as data, every TTIR component as an entity, operational depth 0 – 6, the threat intelligence and modelling process
- Part 2 · Problem statement and strategic response (approx. 25 min)
- 2.1) Where large language models stop — the six gaps of generation: no persistent state, no addressable provenance, no per-claim confidence, no schema, no lifecycle, no validation
- 2.2) AI agents, no-code agent builders and the agentic SOC — definitions and challenges
- 2.3) SCIPAB — Situation, Complication, Implication along five threads: representation, AI-generated knowledge, operational reuse, ownership and interoperability, deployment and sovereignty
- 2.4) The Semantic Threat Classification Model; semantics, taxonomies, ontologies — and how they interrelate
- 2.5) SCIPAB — Position, Action, Benefit: a customer-owned Cyber Threat Model on established standards as the shared knowledge layer between CTI and security operations — trust by design, not by vendor assurance
- Part 3 · From theory to a governed model — two real models as data (approx. 30 min)
- 3.1) The adversary (CrowdStrike CSIT-22052, Emotet delivery — used with approval) and the critical function — two STIX 2.1 exports
- 3.2) Representation — the formal apparatus in the data; two ladders populated: TIBER-EU depth 0 – 6 × DML 9 – 1, where the adversary meets the function
- 3.3) AI-generated knowledge — one claim, fully governed: id, evidence, confidence, lifecycle, validation status; the validation gate: validate, supersede, reject, verify
- 3.4) Operational reuse — one graph, four consumers: detection engineering, threat hunting, incident response, threat-led testing
- 3.5) Ownership and interoperability — what in this export does your stack already read; deployment and sovereignty — where a restricted report may be processed
- Part 4 · The governed model in the agentic SOC (approx. 20 min)
- 4.1) Where the governed model sits — the shared knowledge layer of the agentic SOC
- 4.2) How an agent works on it — the loop: read validated, write draft; the gate closed by a person
- 4.3) Five agents, one graph — what each reads, does and writes back
- 4.4) The five complications of the SCIPAB, solved one thread at a time; trust and determinism answered
- 4.5) Value, measured on the two models — coverage, validation backlog, exposure
- 4.6) Recap — what you can now do
- Q&A (approx. 15 min)
- What participants take home
- Participants can place any claim on the two ladders and name its vocabulary, read a governed claim with its evidence, confidence and validation status, spot the six gaps of generation and the field that closes each — and describe how AI agents of any platform consume a governed model without owning it.
Zielgruppe
- Security Consultants
- Security Analysts
- Security Investigators
- Threat Hunters
- Incident Responders
- Detection Engineers
- SOC Architects and SOC Managers preparing for AI agents