After the course, you will no longer be fighting against the flood of alerts, but working with a system: You know which model takes on which task, have over 50 ready-to-use prompts for analysis, documentation, and detection – and you evaluate each result in such a way that you can stand by it.
The course trailer: Marco summarizes in under a minute what it's about – hundreds of alerts, endless logs, reports without end, and the question of how you are supposed to handle it all. The answer: You don’t have to manage it all on your own anymore. Log analyses in seconds, incident reports at the push of a button, working detection rules, along with plenty of lessons and over 50 prompts for immediate use.
Before you touch any tool, you clarify the most important question: Where does generative AI bring real benefits in daily security – and where is it simply the wrong tool? Marco contrasts log interpretation, summaries, documentation, and script generation with the hard limits: real detection in SIEM, automatic incident decisions without human involvement, access to internal systems. In Windows Event 4625, you will see live how several minutes of Google searching become just a few seconds.
This is about the question that security professionals should ask first: Where do my data actually end up? You will get the comparison of ChatGPT, Claude, Gemini, local models via Ollama, and the enterprise variants – each with a focus on training, retention period, and compliance. Marco goes through the ChatGPT data control step by step and shows you where to turn off training with your content.
80% of result quality depends on the prompt and not on the model – and this lesson painfully demonstrates that to you. You start with the classic beginner prompt "Help me with a security problem" and see why the AI only responds with further questions. Then you transform it into a precise instruction using four components – role, context, task, format – which provides truly actionable answers.
Thousands of events per day, and you’re supposed to find that one brute force attempt – manually a hopeless endeavor. Marco goes through the event IDs that you should know in your sleep (4624, 4625, 4688, 4720, etc.), filters for failed logins, and exports them as CSV or via PowerShell. He then hands over the data to ChatGPT and gets the analysis that would normally take you hours in seconds.
Event logs show you what is happening on the endpoint – firewall and proxy logs show you who it is talking to. You will learn about common formats (Squid, Blue Coat, Palo Alto) and understand how to recognize C2 beaconing: regular intervals with jitter, always the same target, similar data volumes, often at night and on weekends. After that, you will have ChatGPT detect exactly this pattern in real proxy logs.
300 alerts in the morning, 500 by noon, and half is noise – but which half? This lesson transforms ChatGPT into a triage assistant for you, including a ready-made template with role, environment, working hours, and critical assets. With real alert formats from Splunk, Microsoft Sentinel, and Elastic, you receive true/false positives, priority P1 to P4, and a comprehensible rationale.
After the incident comes the part that everyone likes to skip: documenting and sharing. You go through the IOC categories – Network, Host, Behavior – and learn which artifacts truly have attack significance and which are just noise. From anonymized log files of a real phishing case, you extract the IOCs with ChatGPT and map them to MITRE ATT&CK so that your report is understood worldwide.
Tuesday morning, 9:47 AM: The SIEM is exploding, the helpdesk hotline is ringing, there is a ransom note on the file server. It is exactly at this moment that most mistakes happen, and this is where the lesson begins – not to see ChatGPT as a substitute for your knowledge, but as a Second Brain that asks the questions you forget in the stress. You simulate the complete process from the first alerts to the containment decisions.
Every team has playbooks – mostly outdated and gathering dust somewhere in SharePoint. You first get the structure that a usable playbook needs: metadata, triggers and scope, triage, containment, eradication, recovery, post-incident, and references. After that, you let ChatGPT fill in the framework and adjust it to your specific environment in about 30 minutes.
The incident is over, everyone breathes a sigh of relief – and then comes the part that no one likes. After 48 hours of continuous operation, your notes are chaotic, timestamps are missing, and yet insurance, compliance, and legal want a clean report. Here, you turn that very note chaos into a structured timeline and a completed incident report with ChatGPT – in minutes instead of hours.
The malware has been identified, but who is behind it, how do they work – and what comes next? You will learn about the most important OSINT sources, from Mandiant, CrowdStrike, and Microsoft reports to CISA and BSI, as well as MITRE ATT&CK Groups, Malpedia, and Ransom-Wiki. Afterwards, you will aggregate the material with ChatGPT into a threat intelligence report and then know where to specifically reinforce your detections.
“Is this critical? Do we need to patch tonight?” – the question from the CISO that you cannot answer with a CVSS score alone. You work through the core questions: What is the vulnerability, how bad is it really (CVSS, EPSS, Temporal), are there exploits in Exploit-DB, GitHub or Metasploit, and is the system reachable in your environment? With ChatGPT, you arrive at a data-driven patch decision in minutes instead of relying on gut feeling.
In the past, scripting meant sifting through Stack Overflow, piecing together snippets, and debugging for hours. Today, ChatGPT delivers the first draft in seconds – but AI-generated code is not automatically safe or correct. You get a prompt template with purpose, input, output, environment, error handling, and security guidelines, and use it to build three scripts for threat hunting, hardening check, and incident response.
You have threat intelligence, IOCs, and TTPs – but do you even notice when the attack is happening? This lesson is about Sigma as a platform-independent rule language: write once, then convert to Splunk, Sentinel, Elastic, QRadar, or CrowdStrike. In the real-world scenario LSASS Credential Dumping, you will generate, test, and optimize your rule with ChatGPT.
The log file contains usernames, email addresses, internal server names, and sometimes passwords in plain text – and this is exactly what you are about to send to an external service. This lesson draws the line and shows you for each provider and plan who is training with your data and how long it is stored. You will also receive specific rules, anonymization techniques, and the secure alternative through local models.
Uncomfortable truth: Attackers use the same tools as you, just without terms of use and without an ethical brake. You see how AI elevates phishing to a new level – no more spelling mistakes and "Dear Customer" – and how malware development, deepfakes, and voice cloning are accelerated. The goal is not panic, but preparation: Only those who understand the offensive can defend effectively.
Imagine ChatGPT confidently assigns an IP address to the Lazarus Group, management is alarmed, external forensic experts are called in – and then it was all made up. That’s exactly what a hallucination is, and it comes without any warning. You will learn why LLMs produce such things as text prediction machines and how to systematically verify IOCs, CVE details, and threat actor associations before taking action.
In conclusion, it is about what often gets overlooked: responsibility. Four pillars guide you through daily life – transparency, accountability, duty of care, and proportionality – complemented by clear cases in which you consciously do not use AI, such as in legal questions or personnel decisions. The key takeaway of the lesson: AI's mistakes are your mistakes if you do not verify them.
“I have ChatGPT, I don’t need anything else” – this sentence costs you time every day. Every model has its own strengths and weaknesses: ChatGPT struggles with real-time research, Gemini with very long documents, Claude is strong in text but not designed for office processes, and that’s where Copilot shines. This lesson shows you why a multi-model strategy is not a luxury and how to effectively combine multiple LLMs.
The all-rounder in detail: ChatGPT as an assistant that writes texts, provides ideas, builds concepts, and produces code. Marco addresses the strengths of the current version – significantly better context processing, very natural writing style, enormous foundational knowledge – and guides you through the interface and main features. Afterward, you will know how to use ChatGPT in your daily security tasks and where another model might be the better choice.
200-page document, and you need a precise summary in seconds – that's Claude's home game. Anthropic's model is designed for long contexts, well over 100,000 tokens, and is noticeably less prone to hallucinations. For long logs, extensive reports, and documentation, this is exactly the combination you need.
Writing emails, creating presentations, assembling Excel sheets – and it takes forever. Copilot is right in Word, Excel, PowerPoint, Outlook, and Teams and takes care of exactly this tedious work for you, including meeting minutes from which you can directly draw summaries. It is important to know: This all depends on Microsoft 365, the standalone Office packages are excluded.
Clicking through twenty websites for a single clear answer – that doesn't have to be the case. Perplexity is an AI search engine that gives you the answer and provides the source, which is invaluable for CVE research and hard facts. You see the free version, its limitations, and what it’s worth switching to.
Grok is the AI from Elon Musk's xAI and is integrated directly into X, the former Twitter. The advantage lies in real-time access to posts, news, and trends – practical when a new threat is making the rounds and has not yet appeared in any report. Marco will guide you through the interface on the xAI page and show where Grok really makes sense in everyday life.
One login, many models: Poe from Quora consolidates ChatGPT, Claude, Gemini, and more into a single interface. This saves you from juggling multiple accounts and makes direct comparisons easy – ideal if you want to find out which model solves your task best. Additionally, you get an overview of the points system and the pricing models from the free plan to the large subscription.
AI models like GPT variants or Llama directly on your own computer, without a subscription and without the cloud – that's what LM Studio is for. The desktop app for Windows, Mac, and Linux downloads local language models and makes them usable with just a few clicks. For everyone who needs to analyze sensitive data, this is the clean solution: What stays on your computer does not end up in foreign training data.
If you want full control, you just run the model on your own. Ollama is open source, free, and runs on Mac, Windows, and Linux – with models like Llama, Mistral, or Phi directly on your computer, without the internet and without a subscription. For confidential analyses, this means: no data leaves your PC, no training data discussions, no hidden costs.
After all the tools, the question that really matters in everyday life arises: Which model should I use for this task? You get a beginner's rule that covers about 90% – ChatGPT for texts, Claude for long content, Gemini for research, Copilot for office tasks, Perplexity for facts with sources. Following that is the pro rule for anyone who produces or automates regularly.
The most open ChatGPT, type a prompt, and hope – while the real leap lies elsewhere. You deploy the models as a team: one researches, one writes, one checks, one automates. Specifically, you build a four-model workflow using Perplexity, Claude, ChatGPT, and Gemini, allowing you to work as an individual like a whole editorial team.
The final lesson of the module turns the tables: You don't need a single model, you need a system. Your setup will be built on three levels, so that each model takes on exactly what it was designed for – instead of randomly typing something in somewhere. The result is a personal AI toolkit that allows you to work faster and more structured every day.
Comment now „GenAI for Cybersecurity - Practical Course for Professionals“