
AI-Powered Ransomware: How Threat Actors Weaponize AI Across the Attack Lifecycle
Source: YouTube · SANS Digital Forensics and Incident Response · published Jan 7, 2026 · 59:24
This is the premiere episode of the 2026 SANS "Stay Ahead of Ransomware" live stream, hosted by two seasoned DFIR professionals 0:48.
Key Takeaways:
• Host Ryan Chapman is the author and instructor for SANS Forensics 528: Ransomware and Cyber Extortion 1:01
• Co-host Mary Degrazia also teaches FOR528 and FOR4500 (Windows Forensic Analysis), and recently authored a new course (4563) on using local LLMs for DFIR 1:13
• Mary's day job is as a director at IDX, where she performs hands-on DFIR consulting work 1:35
The transcript cuts off shortly after the host introductions, so no substantive ransomware topics were covered in the provided segment.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[snorts] [music] Heat. Heat. [music] >> [music] [music] >> Hello and welcome everyone to the first episode of the SANS stay ahead of ransomware live stream here in 2026. Oo, new year. All right. My name is Ryan Chapman and I am the author/instructor for SANS Forensics 528, Ransomware and Cyber Extortion, and I am here with my awesome co-host, Mary Degrazia, who is also an instructor for 528. Mary, what else are you up to in the SNS realm? >> Yeah, thanks Ryan. I am also well 528 like you said and I teach forensics 4500 which is the Windows forensic analysis and I've just authored the 4563 basically using local LLMs to do DFIR. So uh my day job as we call it here at SANS is I'm a director at IDX where I do consulting work doing uh DFIR stuff all day long. >> Very cool. For anyone who has no…