SAINTCON 26 · Session
Scaling Threat Detection with AI using Detection-as-Code
Threat detection from research to implementation has been historically manual and slow. For blue teams operating across sprawling tech stack environments, this can creates a scalability challenge. Meanwhile, threat actors using AI tools have only lowered the barrier to weaponization and exploitation as they accelerate the pace of their attacks.
This session explores how AI coding agents, layered on top of a Detection-as-Code foundation, can dramatically compress the path from detection hypothesis to production from weeks to hours and deliver solid detection content at a much faster speed. We will highlight the integration points where AI agents reliably pay off, including drafting boilerplate detection logic, applying style guides, performing bulk edits across hundreds of rules behind human review, and more. We’ll also share the areas where these agents fall short, teaching us where the human must stay in the loop. Attendees will leave with a practical, phased implementation model they can apply directly to scale detection engineering in their own environments.