AI Integration for Security Workflow Automation (LFWS303)

This one-day course shows security teams how to use AI and automation to cope with alert overload and scale their security operations.

Suggested prerequisites: comfort with the Linux terminal, familiarity with fundamental cybersecurity concepts (IOCs, MITRE ATT&CK basics, log analysis) and REST APIs (webhooks, JSON), and basic programming experience in JavaScript or Python.

Audience: security analysts, SOC and blue team professionals and security engineers, as well as LLMOps practitioners applying AI in security.

Security teams face a steady stream of alerts and evolving threats with limited resources. This course is for people who want to build the automation skills to keep up and to move into higher-impact roles. You will learn why automating security makes sense, how to design low-code SOC workflows, and how to integrate data from multiple sources, including threat intelligence.

You will also learn to apply large language models with retrieval-augmented generation (RAG) for investigation and triage, and to put guardrails in place, including a look at the OWASP Top 10 for LLMs. The labs build on each other: you start with a threat intelligence enrichment workflow, add AI-powered threat analysis with RAG and guardrails, and finish by building an end-to-end SOC pipeline with a live SIEM. A team challenge, a race to detect and respond, and short team presentations round off the day.

You will need a laptop with at least 8GB of RAM, a reliable internet connection and a modern web browser such as Chrome or Firefox. The course prepares you for roles such as Senior SOC Analyst, Security Automation Engineer or Detection Engineer, by helping you reduce alert noise, speed up investigations and build scalable detection and response pipelines.

← All Linux Foundation courses