Bibliography · auto-derived from course content · 14 modules

AI Security Operations Mastery bibliography

55 unique peer-reviewed primary sources, deduplicated across 14 modules. Auto-generated from the course's actual references data, when the course adds a citation, this page updates automatically. The full DecipherU sourcing standard is at /academic-rigor.

Peer-reviewed journals · 4

  1. Lewis, P., Perez, E., Piktus, A., Petroni, F., Karpukhin, V., Goyal, N., et al. (2020). Retrieval-Augmented Generation for Knowledge-Intensive NLP Tasks. Advances in Neural Information Processing Systems (NeurIPS). https://arxiv.org/abs/2005.11401
  2. Reimers, N., & Gurevych, I. (2019). Sentence-BERT: Sentence Embeddings using Siamese BERT-Networks. Proceedings of the 2019 Conference on Empirical Methods in Natural Language Processing (EMNLP). https://arxiv.org/abs/1908.10084
  3. European Union (2024). Regulation (EU) 2024/1689 (Artificial Intelligence Act). Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  4. Wei, J., Wang, X., Schuurmans, D., Bosma, M., Ichter, B., Xia, F., Chi, E., Le, Q., & Zhou, D. (2022). Chain-of-Thought Prompting Elicits Reasoning in Large Language Models. Advances in Neural Information Processing Systems (NeurIPS). https://arxiv.org/abs/2201.11903

Standards-body + government · 11

  1. MITRE Corporation (2024). MITRE ATT&CK Enterprise Matrix v15. MITRE Corporation. https://attack.mitre.org/matrices/enterprise/
  2. MITRE Corporation (2024). MITRE ATLAS: Adversarial Threat Landscape for Artificial Intelligence Systems. MITRE Corporation. https://atlas.mitre.org/
  3. MITRE Corporation (2024). MITRE ATLAS Tactics and Techniques. MITRE Corporation. https://atlas.mitre.org/matrices/ATLAS
  4. MITRE Corporation (2024). MITRE D3FEND: A Knowledge Graph of Cybersecurity Countermeasures. MITRE Corporation. https://d3fend.mitre.org/
  5. MITRE Corporation (2024). MITRE ATT&CK: Indicator of Compromise Patterns. MITRE Corporation. https://attack.mitre.org/
  6. MITRE Corporation (2024). MITRE ATT&CK Threat Group and Software Profiles. MITRE Corporation. https://attack.mitre.org/groups/
  7. Crowley, C., & Pescatore, J. (2023). SANS 2023 SOC Survey. SANS Institute. https://www.sans.org/white-papers/2023-sans-soc-survey
  8. OWASP Foundation (2024). OWASP Top 10 for Large Language Model Applications. OWASP Foundation. https://genai.owasp.org/llm-top-10/Cited in 3 modules
  9. Lee, R. M., Lee, R. M., & Bianco, D. (2017). Generating Hypotheses for Successful Threat Hunting. SANS Institute Reading Room. https://www.sans.org/white-papers/37172/
  10. National Institute of Standards and Technology (2023). AI Risk Management Framework (NIST AI 100-1, Version 1.0). NIST. doi:10.6028/NIST.AI.100-1
  11. National Institute of Standards and Technology (2024). NIST Cybersecurity Framework 2.0. NIST. doi:10.6028/NIST.CSWP.29

Books + monographs · 2

  1. Heuer, R. J., Jr., & Pherson, R. H. (2014). Structured Analytic Techniques for Intelligence Analysis (2nd ed.). CQ Press, Washington DC.
  2. Liang, P., Bommasani, R., Lee, T., Tsipras, D., Soylu, D., Yasunaga, M., et al. (2022). Holistic Evaluation of Language Models (HELM). Stanford Center for Research on Foundation Models. https://crfm.stanford.edu/helm/

Other primary sources · 38

  1. Cybersecurity and Infrastructure Security Agency (CISA) (2024). Identifying and Mitigating Living off the Land Techniques. Joint Cybersecurity Advisory AA24-038A (CISA, NSA, FBI, ACSC, CCCS, NCSC-NZ, NCSC-UK). https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques
  2. AICPA (2024). Trust Services Criteria (SOC 2). American Institute of CPAs. https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2
  3. Cloud Security Alliance (2024). Cloud Controls Matrix v4. Cloud Security Alliance. https://cloudsecurityalliance.org/research/cloud-controls-matrix/
  4. Cloud Security Alliance (2024). CSA Top Threats to Cloud Computing. Cloud Security Alliance. https://cloudsecurityalliance.org/artifacts/top-threats-to-cloud-computing-pandemic-eleven/
  5. Anthropic (2024). Claude API Documentation. Anthropic Developer Documentation. https://docs.anthropic.com/
  6. Anthropic (2024). Tool Use and Structured Output with Claude. Anthropic API Documentation. https://docs.anthropic.com/en/docs/agents-and-tools/tool-use/overview
  7. Anthropic (2024). Claude API Pricing. Anthropic. https://www.anthropic.com/pricing
  8. Caltagirone, S., Pendergast, A., & Betz, C. (2013). The Diamond Model of Intrusion Analysis. Center for Cyber Intelligence Analysis and Threat Research, Technical Report. https://www.activeresponse.org/wp-content/uploads/2013/07/diamond.pdf
  9. Cichonski, P., Millar, T., Grance, T., & Scarfone, K. (2012). Computer Security Incident Handling Guide (NIST Special Publication 800-61 Revision 2). National Institute of Standards and Technology. doi:10.6028/NIST.SP.800-61r2
  10. Microsoft Corporation (2024). Microsoft Security Copilot Documentation. Microsoft Learn. https://learn.microsoft.com/en-us/copilot/security/Cited in 2 modules
  11. Microsoft Corporation (2024). Microsoft Security Copilot: Incident Summarization Patterns. Microsoft Learn. https://learn.microsoft.com/en-us/copilot/security/
  12. Microsoft Corporation (2024). KQL Reference and Microsoft Sentinel Hunting Queries. Microsoft Learn. https://learn.microsoft.com/en-us/azure/data-explorer/kusto/query/
  13. Microsoft Corporation (2024). Microsoft Sentinel: Detection Rule Health and Continuous Evaluation. Microsoft Learn. https://learn.microsoft.com/en-us/azure/sentinel/
  14. Microsoft Corporation (2024). Microsoft Sentinel Automation Rules and Playbooks. Microsoft Learn. https://learn.microsoft.com/en-us/azure/sentinel/automate-incident-handling-with-automation-rules
  15. Microsoft Corporation (2024). Azure Privileged Identity Management Documentation. Microsoft Learn. https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-configure
  16. Microsoft Corporation (2024). Microsoft Defender for Cloud. Microsoft Learn. https://learn.microsoft.com/en-us/azure/defender-for-cloud/
  17. Guo, C., Pleiss, G., Sun, Y., & Weinberger, K. Q. (2017). On Calibration of Modern Neural Networks. Proceedings of the 34th International Conference on Machine Learning. https://arxiv.org/abs/1706.04599
  18. HashiCorp (2024). Terraform Security Best Practices. HashiCorp Documentation. https://developer.hashicorp.com/terraform/cloud-docs
  19. Heuer, R. J., Jr. (1999). Psychology of Intelligence Analysis. Center for the Study of Intelligence, Central Intelligence Agency. https://www.cia.gov/resources/csi/books-monographs/psychology-of-intelligence-analysis-2/Cited in 2 modules
  20. CrowdStrike Holdings (2024). Charlotte AI: Generative AI Security Analyst. CrowdStrike Documentation. https://www.crowdstrike.com/platform/charlotte-ai/Cited in 2 modules
  21. Splunk Inc. (2024). Splunk AI and SOC Copilot Documentation. Splunk Docs. https://docs.splunk.com/Documentation
  22. Splunk Inc. (2024). Splunk Search Reference. Splunk Docs. https://docs.splunk.com/Documentation/Splunk/latest/SearchReference
  23. Splunk Inc. (2024). Splunk SOAR (Phantom) Documentation. Splunk Docs. https://docs.splunk.com/Documentation/SOAR
  24. Splunk Inc. (2024). Splunk SOC Copilot. Splunk Docs. https://docs.splunk.com/Documentation
  25. Office of the Director of National Intelligence (2015). Intelligence Community Directive 203: Analytic Standards. ODNI. https://www.dni.gov/files/documents/ICD/ICD%20203%20Analytic%20Standards.pdf
  26. ISC2 (2024). Cybersecurity Workforce Study 2024: AI Skills and the Workforce. International Information System Security Certification Consortium. https://www.isc2.org/research
  27. Google LLC (2024). Google Cloud IAM Recommender. Google Cloud Documentation. https://cloud.google.com/iam/docs/recommender-overview
  28. Google LLC (2024). Google Security Command Center. Google Cloud Documentation. https://cloud.google.com/security-command-center/docs
  29. OpenAI (2024). Structured Outputs Guide. OpenAI API Documentation. https://platform.openai.com/docs/guides/structured-outputs
  30. OpenAI (2024). OpenAI API Pricing. OpenAI. https://openai.com/api/pricing/
  31. Forrester Research (2024). Forrester Research Topic Pages on AI Security Tools (cite the existence, not the analyst data). Forrester Research. https://www.forrester.com/
  32. Roth, F., & SigmaHQ contributors (2024). Sigma: Generic Signature Format for SIEM Systems. SigmaHQ project (github.com/SigmaHQ/sigma). https://github.com/SigmaHQ/sigma
  33. Amazon Web Services (2024). AWS IAM Access Analyzer Documentation. AWS Documentation. https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html
  34. Amazon Web Services (2024). AWS CloudTrail Documentation. AWS Documentation. https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-user-guide.html
  35. Amazon Web Services (2024). AWS Security Hub. AWS Documentation. https://docs.aws.amazon.com/securityhub/
  36. Sommer, R., & Paxson, V. (2010). Outside the Closed World: On Using Machine Learning for Network Intrusion Detection. Proceedings of the 2010 IEEE Symposium on Security and Privacy. https://www.icir.org/robin/papers/oakland10-ml.pdf
  37. U.S. Bureau of Labor Statistics (2024). Occupational Employment and Wage Statistics, May 2024: Information Security Analysts (15-1212). U.S. Department of Labor. https://www.bls.gov/oes/current/oes151212.htm
  38. U.S. Bureau of Labor Statistics (2024). Occupational Employment and Wage Statistics, May 2024: Information Security Engineers and Architects. U.S. Department of Labor. https://www.bls.gov/oes/current/oes151212.htm

Export

Cite this bibliography in your own work

One-click copy of the entire bibliography in three formats. The same data, machine-readable, audit-ready.