CyBe AI Summit 2026 — NIMHANS Convention Centre, Bengaluru — 4 Sep 2026Learn more
← AI SOC Analyst weekend cohortSession 6 of 6 · Sat 28 Nov 2026 · Arc 4–6 · chapters 30–40

Immersive day and certification exam

The cohort closes with the Cyber War Room — a full day working a live incident against the clock, as a team, with the whole six-session case behind you. The certification exam follows in the same day.

When
Sat 28 Nov 2026 · 10:30–17:30 IST · full day
Where
Bangalore or virtual
Cohort size
25 in person · 40 including virtual
₹3,600₹6,00040% off release price
Book this session →

Sessions can be booked individually, or take the full six-session cohort.

What you leave able to do

  • Work a full incident under time pressure as part of a team
  • Produce the written incident report the exercise is judged on
  • Sit the AI SOC Analyst certification exam

Run of play

  1. 1

    Cyber War Room

    A live incident, a clock, and a team. The whole cohort applied at once.

  2. 2

    The report

    What actually gets handed over when the incident closes.

  3. 3

    Certification exam

    Sat the same day, with the case still fresh.

The case

Where this sits in the story

All six Saturdays run on one continuous breach, so every session picks up where the last one left off.

Silent Phantom returns AI-augmented: phishing written by an LLM that passes every filter, a prompt injection that talks the enterprise assistant into leaking config, a UEBA model poisoned to suppress its own alerts, and a deepfake CFO voicemail authorising a ₹2.3 crore wire. Then the siege — 72 hours, all vectors live at once, and the report the CISO is waiting for.

Who this session suits

Cohort participants completing the arc. The full-day immersive and the certification exam sit here; certification is a ₹10,000 add-on on any session, and free with the full cohort.

Scope

What this session covers

  • Multi-cloud takeover: AWS federated identity into Azure, Key Vault theft
  • Full-chain containment across 33 days and two cloud platforms
  • The AI attack surface: what changed in the last two years
  • AI-generated phishing, where detection shifts from content to infrastructure
  • LLM prompt injection, and reading an audit log for a model that betrayed you
  • UEBA bypass by threshold-splitting, and cumulative detection rules
  • Deepfake vishing and adversarial ML, mapped to MITRE ATLAS
  • Cyber War Room: 72 hours, three live vectors, containment against a clock
  • The final debrief — attribution, disclosure and the CISO report

Hands-on

The labs you work

11 hands-on labs, 725 minutes of lab time. Each runs in a cloud terminal against real evidence — logs, PCAPs, event data — and is graded on what you find, not on a multiple-choice answer. Lab access continues for 3 months, so the work does not stop when the session ends.

  1. 1Silent Phantom: Cloud Infrastructure Takeoversoc-cloud-soar60 min
  2. 2Operation Debrief: Full Chain Containmentsoc-cloud-soar50 min
  3. 3AI-Powered Threats: The New Attack Surfacesoc-ai-era35 min
  4. 4Detecting AI-Generated Phishing at Scalesoc-ai-era50 min
  5. 5Prompt Injection in Enterprise AI Toolssoc-ai-era45 min
  6. 6UEBA Bypass and Anomaly Detectionsoc-ai-era55 min
  7. 7Deepfake, LLM Exfil, and Adversarial MLsoc-ai-era70 min
  8. 8Hour 0: First Contact — All Vectors Livesoc-siege90 min
  9. 9Hour 24: Containment Racesoc-siege90 min
  10. 10Hour 48: The Phantom Resurfacessoc-siege90 min
  11. 11Hour 72: Final Debrief and Attributionsoc-siege90 min

Tools used

  • MITRE ATLAS
  • LLM audit logs
  • UEBA platform
  • Sentinel
  • CloudTrail
  • SOAR

MITRE ATT&CK coverage (50)

  • AML.T0010 ML Model Inference API Access
  • AML.T0015 Evade ML Model
  • AML.T0018 Backdoor ML Model
  • AML.T0043 Craft Adversarial Data
  • AML.T0051 LLM Prompt Injection
  • AML.T0053 Evade ML Model
  • AML.T0053 Use of AI-Generated Content (Deepfake)
  • AML.T0054 LLM Jailbreak / Evasion
  • AML.T0056 LLM Prompt Extraction
  • T1003.001 OS Credential Dumping: LSASS Memory
  • T1003.006 OS Credential Dumping: DCSync
  • T1020 Automated Exfiltration
  • T1021.002 Remote Services: SMB/Windows Admin Shares
  • T1021.007 Remote Services: Cloud Services
  • T1027 Obfuscated Files or Information
  • T1036 Masquerading
  • T1039 Data from Network Shared Drive
  • T1041 Exfiltration Over C2 Channel
  • T1048 Exfiltration Over Alternative Protocol
  • T1055 Process Injection
  • T1056 Input Capture
  • T1059 Command and Scripting Interpreter
  • T1059.001 Command and Scripting Interpreter: PowerShell
  • T1068 Exploitation for Privilege Escalation
  • T1070 Indicator Removal
  • T1071 Application Layer Protocol
  • T1074.001 Data Staged: Local Data Staging
  • T1074.002 Data Staged: Remote Data Staging
  • T1078 Valid Accounts
  • T1078.002 Valid Accounts: Domain Accounts
  • T1078.004 Valid Accounts: Cloud Accounts
  • T1098.001 Account Manipulation: Additional Cloud Credentials
  • T1105 Ingress Tool Transfer
  • T1134 Access Token Manipulation
  • T1190 Exploit Public-Facing Application
  • T1195.001 Supply Chain Compromise: Compromise Software Dependencies
  • T1213 Data from Information Repositories
  • T1485 Data Destruction
  • T1490 Inhibit System Recovery
  • T1530 Data from Cloud Storage Object
  • T1537 Transfer Data to Cloud Account
  • T1550.001 Use Alternate Authentication Material: Application Access Token
  • T1555.006 Credentials from Password Stores: Cloud Secrets Management Stores
  • T1565.001 Data Manipulation: Stored Data Manipulation
  • T1566 Phishing (AI-generated)
  • T1566 Phishing (Deepfake Vishing)
  • T1566.002 Phishing: Spearphishing Link
  • T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
  • T1570 Lateral Tool Transfer
  • T1583.006 Acquire Infrastructure: Web Services
Certification route

Session + Certification (2 exam attempts)

₹10,000

Adds two certification exam attempts within three months. Available on any Saturday for ₹10,000, and included free if you book the full six-session cohort instead.

Choose this tier at checkout →

Both tiers are selectable on the registration page.

Schedule

The full cohort

One continuous case across six Saturdays. Sessions build on each other, and each one can also be booked on its own.

  • Sat 17 Oct 2026Foundations and the first alert10:30–13:30 ISTDetails →
  • Sat 24 Oct 2026AI-era phishing and the initial foothold10:30–13:30 ISTDetails →
  • Sat 31 Oct 2026Endpoint investigation and containment10:30–13:30 ISTDetails →
  • Sat 7 Nov 2026Diwali holiday — no sessionNo session
  • Sat 14 Nov 2026Cloud SOC and lateral movement10:30–13:30 ISTDetails →
  • Sat 21 Nov 2026Detection engineering and automation10:30–13:30 ISTDetails →
  • Sat 28 Nov 2026Immersive day and certification exam10:30–17:30 IST · full dayYou are here

Taking the whole cohort?

The six sessions are one continuous case, and the full course page carries the curriculum, the certification detail and the cohort pricing.