Overview
Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore how artificial intelligence revolutionizes digital forensic investigation through this Black Hat USA 2025 conference presentation. Learn about the first AI-powered agent capable of autonomously performing digital forensic analysis on massive log volumes from real-world security incidents. Discover how this innovative approach addresses the traditional challenges of timeline analysis, which typically requires highly skilled professionals to spend weeks sifting through hundreds of millions of log records from diverse and unfamiliar log types. Understand the agent's advanced threat hunting capabilities that can identify and explain evidence of system compromise without requiring predefined attack signatures. Examine the technical implementation combining sophisticated prompting techniques with reinforcement learning that enables high recall and precision in finding and contextualizing individual log records within complex attack chains. Review evaluation results from a dataset of 100 diverse, real-world compromised systems that demonstrate the agent's effectiveness. Gain insights into how this technology integrates with existing log-normalization and collaborative analysis tools like Plaso and Timesketch to significantly reduce the time and expertise required for incident response. Access comprehensive presentation materials and learn from Google's security engineering team about the future of automated digital forensic analysis and its practical applications in cybersecurity investigations.
Syllabus
Black Hat USA 2025 | Autonomous Timeline Analysis and Threat Hunting: An AI Agent for Timesketch
Taught by
Black Hat