Defense Systems That Think, Hunt, and Respond
The attackers are already using AI. Phishing campaigns written by LLMs. Polymorphic malware that rewrites itself every execution. Reconnaissance bots that map your attack surface faster than your team can patch it. The question is no longer if AI will reshape cybersecurity it's whether your defense will be as intelligent as the offense.
In this 300-level session, we go deep into architecting autonomous cyber defense systems using agentic AI on AWS. You'll see how to build multi-agent security architectures where specialized AI agents handle threat detection, investigation, and response in parallel triaging thousands of alerts in seconds, correlating signals across SIEM, endpoint, and network telemetry, and autonomously containing threats before they escalate.
We'll walk through real architecture patterns using Amazon Bedrock Agents for reasoning and orchestration, Amazon GuardDuty and AWS Security Hub as signal sources, and Amazon EventBridge + AWS Step Functions for automated response playbooks all governed by human-in-the-loop guardrails that keep your autonomous agents accountable. You'll learn how to implement retrieval-augmented threat intelligence, build self-improving detection agents that learn from your SOC analysts' decisions, and deploy the whole system within zero-trust, data-sovereign boundaries.