Activity
Mon
Wed
Fri
Sun
Nov
Dec
Jan
Feb
Mar
Apr
May
Jun
Jul
Aug
Sep
Oct
What is this?
Less
More
20 contributions to AI Cybersecurity Academy
AI Agent Accidently Edited 🚨
Last month, I gave access to production to one of the AI agent to aspiring AI Engineer | Architect in my team. He was copying part of the code and accidentality remove portion of it. We figure few days later, when we had bigger load of incidents in queue. 🙃 This was my mistake. I gave keys to production to inexperienced person and it had huge impact on our operations. Also...I'm monitoring cost, usage, but...not how many incidents were investigated by each agent. Now I'm in the process of designing complete approach change how to use AI agents in production. The functionalities are great, the customisation brilliant. It's time to take it one step further. In the upcoming weeks I will spend some save guards to identify this kind of problems in the future. It should also cover testing different AI models and ranking them, how they score based on your unique data. My goal is to have AI orchestration agent, who would call the other ones specialized in specific tasks. This orchestration agent would monitor them all. At the same time, you could add new functionalities easily.
1 like • Sep 2
Strong reminder that AI agents need the same controls as human engineers: least privilege, audit logs, testing, and clear production safeguards. The power is impressive, but governance has to grow with it.🔥
🤖 A SOC without L1 and L2 analysts? Anthropic is already moving in that direction.
I came across an interesting post about Anthropic’s “neo-SOC” model. 👀 AI agents are taking over many traditional L1/L2 activities: 🔹 Alert triage 🔹 Enrichment 🔹 False-positive management 🔹 Detection tuning 🔹 Data-source onboarding But the interesting part is that the people weren’t removed, but the queue was. Analysts are moving toward higher-value work such as Detection & Response Engineering, while AI handles much of the repetitive workload. This caught my attention because one of my plans is to create a SOC 2030 roadmap based on a very similar idea. 🗺️ The goal isn't simply to replace analysts with AI. It's to shift people toward: 🔹 Detection Engineering 🔹Incident Response 🔹 Threat Hunting 🔹 Security Automation 🔹 AI Engineering And there is another reason we need to think about this now. ⚔️ Attackers are automating too. If AI increases the speed and scale of attacks, we can't expect defenders to keep up with purely manual processes. The Blue Team needs automation and AI on its side as well. But this creates a very interesting problem: 🎓 If L1 SOC is traditionally where people learn cybersecurity, how do we train the next generation of analysts when much of L1 is automated? I think this will be one of the biggest challenges when designing the SOC of 2030. 🔮
2 likes • Aug 26
A very important point. AI may remove much of the traditional L1 workload, but we still need a clear pathway for new analysts to gain real investigation experience. The SOC of 2030 will need to automate the queue without automating away the learning path.
Upgrading Work Space
This weekend I'll be building bunch of Ikea furniture. Maybe I can finally get rid of the echo in my room, when I'm recording. 😁 Any suggestions, what to have in the background, when I'm recording? 🙂
Upgrading Work Space
1 like • Aug 1
A bookshelf, a plant and some warm lighting would look great in the background. Can’t wait to see the finished setup! 😊
Linux for Cybersecurity
You don't need to know bash! You don't need to learn Python. ⬇️ New video is up for Linux fundamentals in Cybersecurity. My view changed with AI being broadly available. It should be really fundamentals, unless you want to work as system administrator. I have also added some recommended resources and areas to focus on. https://www.skool.com/ai-cybersecurity-academy/classroom/0ebb1453?md=433c43790e184f7a9bcfb6c8940c4531
0 likes • Jul 29
Great perspective. Cybersecurity beginners should focus on Linux fundamentals first—navigation, permissions, processes, networking and logs. AI can support the advanced scripting later.
Ultimate Knowledge Hub
The KQL training in the Ultimate Knowledge Hub is excellent—clear, interactive and practical. The hands-on challenges and instant feedback make KQL much easier to understand and apply to real-world SOC investigations.🔥👍
1-10 of 20
Aanis Jama
2
3 points to level up
@aanis-jama-4023
Aspiring cybersecurity professional with a keen interest in protecting digital systems and learning modern security practices.

Active 15h ago
Joined Jun 24, 2026
Powered by