Week 6 moved into AI in security operations, and Monday’s class had two breakout rooms. In the first, Group 1 explored HeyGen, an AI video avatar platform, and I created an avatar using my own voice. In the second, Group 2 focused on AI in cyber threat detection, and I delivered our group’s 60-second briefing. Together, the two activities described both ends of one attack.
In the threat detection lab, we worked with a synthetic dataset of 40 security events and trained a Decision Tree classifier in Google Colab. It reached 90 percent test accuracy. In the red-team round, it classified only one of three new events correctly while reporting 100 percent confidence on all three. It flagged an administrator running a 450 MB backup at 11 PM as malicious. It labeled an attacker using stolen valid credentials as benign: zero failed logins, a normal port, a 10 AM login, and a 90 MB transfer out.
That miss led me to MITRE ATT&CK technique T1078, Valid Accounts. MITRE describes adversaries abusing the credentials of existing accounts to gain access, persist, escalate privileges, or evade defenses, across default, domain, local, and cloud accounts. For detection, it points to anomalous account usage such as unusual logon times, suspicious locations, and service accounts used outside expected patterns (MITRE, 2026).
The HeyGen session supplies the first link in that chain. Joint NSA, FBI, and CISA guidance on deepfakes lists executive impersonation, financial fraud, and the use of synthetic media to gain access to networks among the threats organizations face (National Security Agency et al., 2023). A convincing voice on a help desk call is one route to the credentials. The valid login that follows is exactly what our model missed.
Our tree learned that attacks involve many failed logins or many new processes. An attacker with valid credentials produces neither by design, so the miss was a documented technique working as intended. MITRE’s logon-time signal would not have rescued us either, because our attacker logged in at 10 AM and the legitimate admin worked at 11 PM.
The confidence scores bothered me most. A decision tree reports the share of training examples in the leaf where a new event lands, so a pure leaf produces 100 percent no matter how unfamiliar the event is. In a SOC, that number could easily be mistaken for certainty.
In my Week 6 assignment, I proposed starting Elastic’s anomaly detection with abnormal authentication behavior and warned that an administrator doing maintenance might look anomalous. The red team made that warning concrete. My group concluded the model should not be deployed without more real data, behavior-based features, and human review of every alert.
My takeaway is that AI in security operations should help analysts rank and route alerts, not make final decisions, because the same technology that helps defenders can help an attacker look normal.
References
MITRE. (2026, May 12). Valid accounts (T1078). MITRE ATT&CK. Retrieved October 4, 2026, from https://attack.mitre.org/techniques/T1078/
National Security Agency, Federal Bureau of Investigation, & Cybersecurity and Infrastructure Security Agency. (2023, September). Contextualizing deepfake threats to organizations [Cybersecurity information sheet]. https://media.defense.gov/2023/Sep/12/2003298925/-1/-1/0/CSI-DEEPFAKE-THREATS.PDF
AI use disclosure
Claude (Anthropic) was used at Level 3, AI Collaboration, to assist with source discovery, organization, drafting, and revision. The class activities, lab results, group roles, and assignment connections are based on my own Week 6 work. I reviewed the sources and approved the final entry.
Leave a comment