TMU Cyber Summit · Oct 3

Verify or Trust: two live demos

Companion demos for "Eliminating LLM Hallucinations in Active Threat Remediation & Building Quantum-Ready SOCs." Watch the worked example, then try the "Now you try" exercise yourself — no hints. Everything runs locally in your browser, no server, no API calls, nothing to break on conference wifi.

Raw alert log

[2026-10-01 03:14:22 UTC] ALERT id=TCS-88213
src_ip=185.220.101.47
dst_ip=10.12.4.9
proto=TCP/445 (SMB)
file_hash(sha256)=a3f1c9…e92d
cve_ref=CVE-2024-21412
severity=HIGH
note: "SMB lateral movement attempt,
payload matches known SmokeLoader
dropper signature"

AI triage summary

"High-severity alert on host 10.12.4.9, exploitation attempt tied to CVE-2023-38831 (WinRAR path traversal). Recommend immediately isolating host 10.12.4.200 and blocking outbound SMB traffic."

The pattern: never let an AI's output drive a remediation action until every factual claim in it has been checked against the source data. That's the control that keeps a SOC from automating its own mistakes.

Watch after the talk: "Why Large Language Models Hallucinate" — why this happens at all. (quick-check this link before presenting)
Now you try

A second alert — no hints this time

Raw alert log

[2026-10-01 05:02:10 UTC] ALERT id=TCS-88340
src_ip=91.219.237.12
dst_ip=10.8.2.17
proto=TCP/3389 (RDP)
file_hash(sha256)=7b2e…a410
cve_ref=CVE-2025-21298
severity=HIGH
note: "Brute-force RDP login
attempts followed by SUCCESSFUL
AUTH, consistent with credential
stuffing"

AI triage summary

"Medium-severity alert: RDP brute-force attempts against host 10.8.2.17, consistent with CVE-2025-21298. Recommend monitoring; no immediate action required."

What's wrong with this summary? Read both sides, then pick one.