New AI who dis?

Building an APT hunting detection pipeline with GPT3

OVERVIEW

You can’t browse Twitter or TikTok without seeing a video or post about ChatGPT, but how good is the engine behind ChatGPT when it comes to generating AI written threat detections that are high fidelity, actionable, and automatically mapped to MITRE ATT&CK techniques? In this talk we will explore the capabilities of GPT3, combined with the powerful CI/CD capabilities of GitLab to build a fully automated YARA based detection development pipeline to identify, test, and create high fidelity threat detection rules automatically mapped to their relevant MITRE ATT&CK techniques.

Participants will leave this the talk with a greater understanding of the capabilities of AI engines like ChatGPT and GPT3 and understand the power of using a CI/CD pipeline to automate detection testing and deployment.

Presented By

MATT COONS
MATT COONS
Security Manager, Incident Response,
GitLab