The Learning Lab experience is supported by both asynchronous and synchronous components. Each part includes a set of resources, an asynchronous discussion, and an interactive live session, all of which culminate in the development of a project to apply learning to local and specific contexts in support of the learning objectives.
Schedule
Part 1: AI as Your Security Analysis Superpower: Mastering ChatGPT for Incident Response
December 1, 2025 | 3:00–4:30 p.m.ET
Get ready to revolutionize how you approach security analysis! In this session, you'll discover how AI tools like ChatGPT can transform complex security tasks into manageable workflows — even for beginners. We'll start with practical, hands-on exercises where you'll use ChatGPT to analyze network traffic, decode suspicious logs and identify potential threats. You'll learn prompt engineering specifically for cybersecurity tasks, turning AI into your personal security analyst. By the end, you'll start building a toolkit of AI prompts and techniques that will accelerate every aspect of incident response.
Learning Objectives:
- Configure ChatGPT and AI tools optimally for security analysis tasks.
- Craft effective prompts for log analysis, network traffic investigation, and threat identification.
- Use AI to decode complex security alerts and translate them into actionable intelligence.
- Build a personal library of reusable AI prompts for common security scenarios.
Part 2: AI-Enhanced Traffic Analysis and Threat Hunting
December 4, 2025 | 3:00–4:30 p.m.ET
Time to put your AI skills into overdrive! Building on your ChatGPT foundation, we'll dive deep into network analysis using AI as your investigation partner. You'll learn to feed packet captures to AI for instant analysis, identify malicious patterns in network traffic and use AI to correlate events across multiple data sources. We'll explore how AI can help you understand attack techniques, decode obfuscated commands and spot anomalies that manual analysis might miss. This session transforms overwhelming data into clear, actionable intelligence.
Learning Objectives:
- Leverage AI to analyze Wireshark captures and identify malicious traffic patterns.
- Use ChatGPT to decode suspicious network protocols and encrypted communications.
- Apply AI-powered correlation to connect disparate security events.
- Create automated workflows combining traditional tools with AI analysis.
Part 3: Code Red! Live Ransomware Investigation Begins
December 9, 2025 | 3:00–4:30 p.m.ET
The call every IT professional dreads just came in: ransomware has hit your university network! It’s time to step into the shoes of an incident responder facing a sophisticated ransomware attack. Using the AI skills, you'll begin your investigation by establishing baselines, hunting through network traffic for patient zero, and detecting the initial signs of compromise. This isn't a drill — you'll work with real ransomware indicators, analyze actual attack patterns, and use AI to accelerate your investigation. By session's end, you'll have started documenting the attack timeline and identifying the threat actor's techniques. Get ready for an adrenaline-pumping deep dive into active incident response!
Learning Objectives:
- Establish system baselines and identify deviations indicating ransomware activity.
- Analyze network traffic using AI-enhanced tools to detect command-and-control communications.
- Detect initial anomalies using OSQuery and AI to identify unusual system behaviors.
- Begin developing custom signatures and detection rules for the specific ransomware variant.
Part 4: Containing Chaos and Recovering Strong: Your Ransomware Victory Lap
December 16, 2025 | 3:00–4:30 p.m.ET
Time to turn the tables on the attackers! In this climactic session, we'll escalate from detection to decisive action. You'll deploy the detection rules you've crafted, investigate triggered alerts and make critical containment decisions to stop the ransomware's spread. Using AI as your co-pilot, you'll navigate the complex process of eradication — ensuring no remnants remain — and plan a secure recovery strategy. We'll conduct forensic analysis to understand the ransomware's behavior, hunt for any lingering threats, and compile a comprehensive post-incident report. You'll leave with a complete incident response portfolio: your AI-enhanced playbook, tested detection rules, forensic findings and lessons learned that will make you a formidable defender against future attacks.
Learning Objectives:
- Deploy and tune detection rules while investigating and escalating security alerts.
- Execute ransomware containment strategies to prevent further spread across the network.
- Plan and implement secure eradication and recovery procedures using AI-assisted workflows.
- Conduct post-incident analysis and create actionable improvements for future defense.
Lab Project/Assignments
Your capstone project is completing the Advanced Ransomware Case, where you'll respond to a realistic ransomware attack against a university network. This comprehensive exercise takes you through the entire incident response life cycle: from detecting the first signs of compromise to conducting post-incident analysis. You'll establish baselines, hunt through network traffic, develop custom detection rules, contain the ransomware spread, and execute recovery procedures—all while using AI tools to accelerate your analysis and decision-making. Your final deliverable is a complete incident response portfolio containing: AI-enhanced detection rules and signatures, forensic analysis reports with IOC documentation, containment and eradication procedures tailored to higher education environments, a post-incident report with timeline and lessons learned, and an updated AI-powered playbook based on your experience. This real-world simulation prepares you to confidently lead ransomware response efforts at your institution, armed with both technical skills and AI superpowers!