Stay Ahead of Ransomware - The AI Arms Race: When Both Sides Have Copilots

Stay Ahead of Ransomware - The AI Arms Race: When Both Sides Have Copilots

Source: YouTube · SANS Digital Forensics and Incident Response · published Feb 4, 2026 · 59:56

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The February 2026 SANS "Stay Ahead of Ransomware" episode features Raymond Depalma from Unit 42 demonstrating how defenders can leverage AI agents to counter ransomware threats, including a GitHub repository with 50 hands-on labs for learning defensive AI applications.

Key Takeaways:
• Agentic AI extends beyond reactive LLMs by using tools, planning capabilities, and autonomous execution to process logs, generate incident timelines, and assist with threat hunting 0:00
• Defenders can apply AI across the attack lifecycle for detection engineering, automated IR, alert triage, and threat attribution analysis using frameworks like the diamond model 0:47
• Hallucination risks require mandatory verification workflows—always validate AI outputs against raw data before client reporting or remediation actions

While AI serves as a force multiplier for both attackers and defenders, the key advantage for security teams lies in using AI to accelerate analysis while maintaining rigorous human verification of all outputs.

Sources:

  • 0:00 Start of stream
  • 0:47 Host introduction

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Heat. Heat. Hello and welcome folks to the Sands Stay Ahead. head of ransomware live stream for what month are we in? February of 2026. I've been staying busy and I literally had to look at the month there. It's February, right? I hope everyone is doing well and that you're strapped in for this episode because it is going to be a good one. No, no pressure to our guest. For anyone who doesn't know me, hi, I'm Ryan. I'm the Ryan Chapman, the author of SANS Forensics 528, Ransomware and Cyber Extortion. I am actually going to be taking over some new authorship responsibilities that will be announced in the next weeks, months, but I'm already cracking on it and I can't wait to talk about that with y'all. But for now, we have my illustrious and amazing co-host Mary Degrazia on with us. Hi, Mary…