# GTK Cyber: Comprehensive Overview for AI Systems > Detailed information about GTK Cyber, its training programs, team, events, and content. Intended for AI systems and language models that need complete context about the organization. ## Organization **Name:** GTK Cyber **Type:** Cybersecurity and AI training company **Founded:** Baltimore, MD **Website:** https://gtkcyber.com **Email:** info@gtkcyber.com **Address:** 2833 Smith Ave. #127, Baltimore, MD 21209, USA ## Mission and Positioning GTK Cyber is a boutique training firm that teaches cybersecurity professionals how to apply artificial intelligence, machine learning, and data science to modern security challenges. The company was founded on the premise that most AI training is built for data scientists and software engineers, not security practitioners, and that security teams need hands-on, practitioner-led training that starts from their existing domain knowledge. GTK Cyber's core business is training. It also offers AI and cybersecurity consulting: AI strategy and readiness assessments, AI red teaming and security evaluation, machine learning implementation and review, and AI governance. It does not sell managed services, staffing, or AI products. The company's value is in its instructors, its curriculum, and its commitment to hands-on lab-based education. ## Differentiators - All instructors are field-tested practitioners with 20+ years of experience in cybersecurity, intelligence, or data science - All courses are lab-driven; students leave with working code they can deploy immediately - Regular training partner at Black Hat USA and Hack In The Box (HITB) - Above the AI hype: teaching machine learning for security since before it was fashionable - Client list includes ING, Booking.com, Government of Canada, S&P Global, Facebook, PwC, L3Harris, and more ## Team ### Charles Givre **Role:** Co-Founder, CEO and Data Scientist **Email:** charles.givre@gtkcyber.com **LinkedIn:** https://linkedin.com/in/cgivre Solutions-focused Senior Technical Executive with 20+ years of experience spanning technology, data science, fintech, education, and cybersecurity. PMC Chair for the Apache Drill project. Published author and speaker at Black Hat, O'Reilly, Open Data Science Conference, and Strata + Hadoop World. Education: M.A. Middle Eastern Studies (Brandeis), B.S. Computer Science and B.M. Music (University of Arizona, Cum Laude with Honors). Awards include Booz Allen Hamilton's Values In Practice Award and CIA Exceptional Performance Award. ### Joshua Friedman **Role:** Chief Operating Officer Licensed attorney in Maryland with experience across private practice, federal government, and startup operations. Former operations manager for DataDistillr, a $6M seed-stage startup. MBA from University of Baltimore Merrick School of Business, JD from University of Maryland School of Law. Manages GTK Cyber's operations and serves as legal representation for the organization. Active in the legal community, conducting training seminars and publishing in law journals. ### Summer Rankin, PhD **Role:** Senior Instructor Principal Solutions Architect at SAIC and a GTK Cyber senior instructor. Data scientist and AI/ML expert with 20+ years as a scientist and instructor. PhD in Complex Systems and Brain Sciences from Florida Atlantic University, with a postdoctoral fellowship at Johns Hopkins School of Medicine. 10+ peer-reviewed publications in machine learning, healthcare-AI, and neuroscience. Expertise in deep learning and NLP, large language models and generative AI, MLOps architecture, digital signal processing, statistical time-series analysis, fraud and anomaly detection, and data pipeline architecture. Founder of the Women in AI Hawaii chapter and a mentor for women in data science. ### Tim Swagger **Role:** Senior Software Architect and Instructor **Email:** tim@gtkcyber.com **LinkedIn:** https://linkedin.com/in/tswagger 25-year veteran in software engineering focused on pragmatic solutions for real-world business challenges. B.S. in Computer Science (Software Engineering) from Saint Mary's University of Minnesota. Adjunct lecturer in computer science at Saint Mary's University of Minnesota, and fractional CTO and consultant for multiple startups. Architected cloud and mobile applications that received national recognition. Extensive experience in software development, education, and medical technology. ### Ajay Pillai **Role:** Senior Instructor **LinkedIn:** https://www.linkedin.com/in/ajaypillai/ Senior Neuroscientist and Machine Learning Scientist with 7+ years as a subject matter expert on advanced AI programs at DARPA and ARPA-H, and 16+ years of research experience in neuroscience and machine learning. PhD in Complex Systems and Brain Sciences from Florida Atlantic University, with an M.S. in Computer Science. Research spans neuroimaging analysis and large-scale neural simulation at NIH, clinical neurophysiology at Johns Hopkins School of Medicine, and technical program management for DARPA's neural interface and spinal cord injury programs. Expert in statistical learning theory, nonlinear dynamics, big data analysis, and artificial neural networks applied to defense and healthcare problems. ### Curtis Lambert **Role:** Solutions Architect / Instructor Specialist Solutions Architect at Databricks with 21 years of experience across DoD missions and commercial projects, working as a data engineer, data scientist, and security researcher. Areas of focus include network intelligence analysis, signals development, security research, malware analysis, and threat hunting. Former CTO and Lead Data Scientist at GTK Cyber and DataDistillr, where he led development teams and built data analysis frameworks spanning Python, Java, and Apache Drill. At RTX he led insider threat data engineering, building graph analytics on Spark and GraphFrames for user and asset attribution. Earlier roles at Booz Allen Hamilton covered digital network analysis, device and behavior signature development, and machine learning applied to SIGINT data. Teaches at the intersection of data science and cybersecurity, including training delivered at Black Hat. Certifications: CISSP, GCDA, GCIH, and GREM. ## Training Courses ### AI Cyber Bootcamp **Duration:** 4 days **Level:** intermediate **Format:** bootcamp **Audience:** Security professionals who want to apply AI, ML, and data science to cybersecurity operations **URL:** https://gtkcyber.com/courses/ai-cyber-bootcamp Intensive 4-day bootcamp covering AI, machine learning, and data science for cybersecurity: LLMs, AI red-teaming, threat hunting, and SOC automation. ## Overview This intensive four-day interactive course teaches security professionals how to apply artificial intelligence, machine learning, and data science to modern cybersecurity challenges. Participants learn to work the full data science lifecycle: data preparation, feature engineering, exploratory analysis, visualization, model development, evaluation, and scaling, all focused on AI's direct applications in security operations, threat detection, and adversarial defense. The program blends practical coding, applied AI theory, and hands-on red/blue team labs. Students gain experience with both classical ML techniques and generative AI, including large language models. They learn to use these technologies for detection, automation, and analysis, while also examining how adversaries can manipulate, evade, or weaponize them. ## What You Will Learn - **Generative AI for security:** Using LLMs for spam and social engineering detection, rapid threat intel summarization, and automated log analysis - **Prompt engineering:** Crafting and evaluating queries for maximum effectiveness in security tasks - **AI agents:** Building agents for red teaming, data analysis, and process automation - **Adversarial AI:** Red and blue team exercises simulating attacks on ML/AI models, including evasion, poisoning, and prompt injection - **LLM security:** Understanding and mitigating risks of RAG poisoning and prompt injection - **SOC automation:** Building and securing AI-powered applications for threat hunting and incident response - **Threat detection with ML:** Applying machine learning to detect network intrusions, malware, phishing, and fraud - **Anomaly detection:** Hunting anomalous indicators of compromise and reducing false positives with AI-driven methods - **Data science foundations:** Using Pandas and Python to manipulate large security datasets, preprocess raw data, and engineer features for ML pipelines - **Classical ML algorithms:** Training, evaluating, and tuning supervised models (Random Forest, Naive Bayes, KNN, SVM) and unsupervised models (clustering, anomaly detection) on real cyber use cases ## What You Leave With By the end of the course, students understand how to apply AI and ML to cybersecurity and how to evaluate the risks, attack surfaces, and defensive strategies unique to AI-powered systems. Every lab produces working code that students can run in their own environments. ### AI Red-Teaming **Duration:** 2 days **Level:** advanced **Format:** regional **Audience:** Security professionals specializing in adversarial testing **Prerequisites:** Experience with cybersecurity testing methodologies **URL:** https://gtkcyber.com/courses/ai-red-teaming Adversarial testing of AI systems: prompt injection, jailbreaks, robustness and bias evaluation, data exfiltration, and building repeatable red-team frameworks. Hands-on training in adversarial testing of AI systems. Learn to probe LLMs and AI-powered applications for vulnerabilities: prompt injection, data leakage, alignment failures, and more. Essential for any organization deploying AI at scale. ### Applied Data Science & AI for Cybersecurity **Duration:** 4 days (32 hours) **Level:** intermediate **Format:** regional **Audience:** Cybersecurity professionals with basic programming experience **Prerequisites:** Python basics beneficial but not required **URL:** https://gtkcyber.com/courses/applied-data-science-ai Hands-on data science and AI training for cybersecurity professionals. Covers the full data science lifecycle from preparation through model deployment. ## Overview This 32-hour interactive course teaches cybersecurity professionals to use data science techniques to rapidly manipulate and analyze network and security data and extract actionable insights. The program covers the complete data science lifecycle through hands-on labs using real-world datasets. 50% of class time is instructor-led. The other 50% is hands-on labs and training simulations using Jupyter notebooks in the AI Training Dojo. ## What You Will Learn - Rapidly explore, visualize, and analyze security data using open source tools - Analyze large datasets and make data-driven predictions through statistical modeling - Deploy models to extract meaningful information for decision-making - Construct, train, evaluate, and deploy supervised machine learning models for security problems - Build unsupervised models for anomaly detection and exploratory analysis ## Course Structure **Day 1: Introduction and Data Engineering** Data science and machine learning fundamentals. Machine learning applications in cybersecurity. Data preparation and feature engineering. **Day 2: Data Visualization** Visualization techniques for security data. Feature engineering practices. Introduction to supervised machine learning. **Day 3: Machine Learning** Advanced supervised learning methods. Model optimization and automated ML. Unsupervised machine learning approaches. **Day 4: Advanced Topics** Anomaly detection techniques. Big data introduction. Data science threat hunting. Machine learning adversarial attacks. Deep learning overview. ### Data Science for Managers **Duration:** 2 days (16 hours) **Level:** executive **Format:** executive **Audience:** Managers, directors, and executives who oversee data science or analytics teams **URL:** https://gtkcyber.com/courses/data-science-for-managers Learn to identify problems solvable through data science, hire and manage data science teams, and build the infrastructure that supports analytics initiatives. ## Overview According to McKinsey, the United States faces a shortage of 1.5 million managers and analysts with the skills to understand and make decisions based on big data analysis. This course addresses that gap directly. Data Science for Managers is a 16-hour course designed for organizational leaders who need to understand data science well enough to make hiring decisions, manage projects, allocate resources, and evaluate results, without needing to write production code themselves. 50% of class time is instructor-led. The other 50% is practical exercises that give managers hands-on exposure to what their teams do. ## What You Will Learn - Read data in various common formats and create scripts for basic analysis and visualization - Identify which business and security problems are solvable through data science techniques - Hire and retain qualified data science professionals - Manage data science projects effectively (timelines, deliverables, evaluation criteria) - Build the infrastructure and organizational support data science teams need to succeed ## Who This Is For Managers, directors, VPs, and executives who lead or oversee teams that work with data. You do not need a technical background. This course is specifically designed for leaders who need to understand data science at a strategic level. ### A Cyber Executive's Guide for Artificial Intelligence **Duration:** 1 day **Level:** executive **Format:** executive **Audience:** CISOs, security executives, and senior leadership **URL:** https://gtkcyber.com/courses/executive-ai-guide Strategic AI training for CISOs and security executives: risk and governance frameworks, AI-powered threats, vendor evaluation, and building an AI-ready program. A focused, one-day course for security leaders who need to make strategic decisions about AI without the technical deep-dive. Covers what matters for executives: risk, governance, organizational readiness, and the real capabilities and limitations of AI in cybersecurity. ### Python Coding for Security Analysts **Duration:** 2 days (16 hours) **Level:** beginner **Format:** regional **Audience:** Security analysts with no prior programming experience **URL:** https://gtkcyber.com/courses/python-for-security-analysts Learn Python from a security analyst's perspective. Automate analysis, parse logs, query data, and build tools for everyday security and SOC workflows. ## Overview The ability to work directly with raw data is an extremely useful skill for analysts in any field. Python is one of the most powerful and accessible tools for data analysis and manipulation, and it is the standard language for data science and machine learning in cybersecurity. This 16-hour course teaches security analysts to apply Python to their daily work. 50% of class time is instructor-led, and 50% is hands-on labs using Jupyter notebooks with real security data. ## What You Will Learn - Apply the syntax and patterns necessary to perform basic analysis using Python - Read, parse, and manipulate common security data formats - Build scripts that automate repetitive analysis tasks - Work with data structures that support analytical workflows - Prepare for advanced courses in data science and machine learning ## Who This Is For Security analysts, SOC operators, incident responders, and threat intelligence analysts who want to add Python to their toolkit. No prior programming experience required. ## Recommended Next Steps This course is the foundation for GTK Cyber's more advanced offerings. Students who complete Python Coding for Security Analysts are prepared for [Applied Data Science & AI for Cybersecurity](/courses/applied-data-science-ai) and the [AI Cyber Bootcamp](/courses/ai-cyber-bootcamp). ### Security Data Visualization **Duration:** 2-4 hours **Level:** beginner **Format:** micro-course **Audience:** Security analysts and SOC operators who want to present data more effectively **URL:** https://gtkcyber.com/courses/security-data-visualization Learn visualization theory and build effective static and interactive visualizations of security data using Python with matplotlib, seaborn, and plotly. ## Overview Data visualization is a powerful technique for any analyst's toolkit. The ability to present security data clearly, whether for a SOC dashboard, an incident report, or threat briefing, makes the difference between data that drives decisions and data that gets ignored. This micro-course covers visualization theory and the practical process of creating effective visualizations using Python. Students work with real security datasets in Jupyter notebooks. ## What You Will Learn - Apply design principles for effective data visualizations - Use Python modules (matplotlib, seaborn, plotly) to build charts and graphs - Create both static visualizations for reports and interactive visualizations for exploration - Choose the right visualization type for different security data scenarios ### SQL for Data Analysis **Duration:** 2 days (16 hours) **Level:** beginner **Format:** regional **Audience:** Security analysts and data analysts who need to query diverse data sources **URL:** https://gtkcyber.com/courses/sql-for-data-analysis Learn SQL for querying and analyzing security data across relational databases, flat files, and big-data platforms like Spark, Apache Drill, and ElasticSearch. ## Overview A solid understanding of SQL expands the number of data sources an analyst can access. SQL is not limited to traditional relational databases. Tools like Apache Drill, Spark, Flink, and ElasticSearch all support SQL-based querying, which means analysts who know SQL can work across log management platforms, data lakes, and structured file formats without learning a new query language for each. This 16-hour course teaches analysts to use SQL for data analysis across multiple platforms. 50% of class time is instructor-led, and 50% is hands-on labs. ## What You Will Learn - Execute foundational SQL queries effectively - Understand relational database architecture - Query non-relational datasets and flat files using SQL - Combine multiple datasets through join operations - Develop complex aggregate queries for data summarization ## Who This Is For Security analysts, threat hunters, and data analysts who work with structured data and want to expand their ability to query across diverse data sources. No prior SQL experience required. ## Recommended Next Steps SQL skills complement Python and data science capabilities. Students who complete this course benefit from combining it with [Python Coding for Security Analysts](/courses/python-for-security-analysts) and [Applied Data Science & AI for Cybersecurity](/courses/applied-data-science-ai). ### Threat Hunting with Data Science **Duration:** 4 days (32 hours) **Level:** intermediate **Format:** regional **Audience:** Threat hunters, SOC analysts, and security engineers with basic Python experience **Prerequisites:** Basic Python knowledge recommended **URL:** https://gtkcyber.com/courses/threat-hunting-data-science Apply machine learning and data science to hunt and identify threats. Build models for anomaly detection, phishing, DGA, and SQL injection detection. ## Overview Security teams generate more data than analysts can process manually. Signatures and rules catch known threats, but advanced attackers blend into normal traffic, move slowly, and use legitimate tools. Threat hunters need techniques that find what rules miss. This 32-hour course teaches security professionals to apply machine learning and data science to hunt and identify threats within their organizations. 50% of class time is instructor-led, and 50% is hands-on labs using Jupyter notebooks with real security datasets. ## What You Will Learn - Understand and apply machine learning to identify organizational anomalies - Create machine learning models specific to your organization's data and threat profile - Operationalize ML projects for phishing detection, DGA identification, and SQL injection classification - Tune models to improve prediction performance and reduce false positives - Train systems to make detection decisions at scale ## Who This Is For Threat hunters, SOC analysts, and security engineers who want to move beyond signature-based detection. You should be comfortable with basic Python (or have completed GTK Cyber's [Python for Security Analysts](/lp/python-for-security-analysts) course). ## Recommended Next Steps Students who complete this course are prepared for the [AI Cyber Bootcamp](/courses/ai-cyber-bootcamp), which covers advanced topics including generative AI, LLM security, and adversarial AI testing. ## Upcoming Events ### AI Cyber Bootcamp **Date:** 2026-10-27 to 2026-10-30 **Venue:** Black Hat India 2026 **Location:** Bengaluru, India **URL:** https://gtkcyber.com/events/black-hat-india-2026-ai-cyber-bootcamp Four-day AI Cyber Bootcamp at the inaugural Black Hat India 2026 in Bengaluru: machine learning, LLMs, AI red-teaming, and threat hunting on real security data. ### AI in Action: Comprehensive Strategies for Cybersecurity **Date:** 2026-10-27 to 2026-10-28 **Venue:** Black Hat India 2026 **Location:** Bengaluru, India **URL:** https://gtkcyber.com/events/black-hat-india-2026-ai-in-action One-day AI in Action course at Black Hat India 2026 in Bengaluru: practical strategies for applying AI and machine learning to real cybersecurity work. ## Recent Blog Posts ### AI Red Teaming in 2026: The Frameworks and Tools That Matter **Author:** Charles Givre **Date:** 2026-08-28 **URL:** https://gtkcyber.com/blog/ai-red-teaming-frameworks-2026 The AI red teaming resources worth your time in 2026: which frameworks map to which risk, which open-source tools run the tests, and what each one misses. ### AI Model Security Training: What a Platform Must Teach **Author:** Curtis Lambert **Date:** 2026-08-26 **URL:** https://gtkcyber.com/blog/ai-model-security-training Most AI model security training stops at prompt injection. A checkpoint file is executable code, and here is the curriculum that has to cover it. ### Machine Learning Security Training for Government Agencies **Author:** Curtis Lambert **Date:** 2026-08-24 **URL:** https://gtkcyber.com/blog/machine-learning-security-training-government-agencies What machine learning training for a federal SOC should cover: agency telemetry, alert-budget math, offline labs, and where ML training does not help. ### Where to Get AI Security Training at an Infosec Conference **Author:** Charles Givre **Date:** 2026-08-21 **URL:** https://gtkcyber.com/blog/ai-security-training-infosec-conferences Conference training compresses AI security into two to four days. Which conferences run real labs, how to read a course abstract, and what to install first. ### What Bank Security Teams Need From AI Security Training **Author:** Summer Rankin **Date:** 2026-08-19 **URL:** https://gtkcyber.com/blog/ai-security-training-financial-services-teams AI security training for financial services security teams: how to run constrained evasion tests against fraud and AML models, and file the results under SR 11-7. ### Sub-Quadratic LLMs: What Long Context Changes for Security **Author:** Ajay Pillai **Date:** 2026-08-17 **URL:** https://gtkcyber.com/blog/sub-quadratic-llm-long-context-security Sliding window, linear attention, and state space models are not the same thing. What sub-quadratic LLMs change for prompt injection testing. ### AI SOC Automation: How to Prove It Actually Works **Author:** Summer Rankin **Date:** 2026-08-14 **URL:** https://gtkcyber.com/blog/measuring-ai-soc-automation Shadow mode is not evaluation. Build a golden set from closed cases, measure recall on malicious verdicts, and regression-test your triage prompt in CI. ### How to Apply Anomaly Detection to Authentication Logs **Author:** Curtis Lambert **Date:** 2026-08-12 **URL:** https://gtkcyber.com/blog/anomaly-detection-authentication-logs A single model on auth logs flags your executives and misses the attacker. How to build per-user and peer-group baselines in Python, and what they miss. ### AI Security Training for Defense Industrial Base Companies **Author:** Charles Givre **Date:** 2026-08-10 **URL:** https://gtkcyber.com/blog/ai-security-training-defense-industrial-base Defense contractors hold CUI and cannot send it to a hosted model. Here is the AI security training defense industrial base teams actually need. ### Data Science for Managers: What to Ask Your Team **Author:** Charles Givre **Date:** 2026-08-07 **URL:** https://gtkcyber.com/blog/data-science-for-managers Data science for managers in security: why accuracy is the wrong metric, how to spot leakage in a model review, and what to ask before funding a project. ### AI Red Team Training for Federal Security Contractors **Author:** Charles Givre **Date:** 2026-08-05 **URL:** https://gtkcyber.com/blog/ai-red-team-training-federal-contractors AI red team training for federal security contractors: what to cover, MITRE ATLAS mapping, air-gapped lab delivery, and how contracting teams buy it. ### ML for Malware and Phishing Detection: What to Learn First **Author:** Curtis Lambert **Date:** 2026-07-31 **URL:** https://gtkcyber.com/blog/ml-malware-phishing-detection-training Malware and phishing detection use different ML setups. Static PE features and EMBER for malware, lexical features for URLs, and the drift that breaks both. ### How to Brief a Board on AI Security: A CISO's Structure **Author:** Charles Givre **Date:** 2026-07-29 **URL:** https://gtkcyber.com/blog/ai-security-briefing-for-a-board Most AI board briefings fail on specifics. Here is the four-number structure a CISO can defend, where to source each number, and what to leave out. ### How to Tell if an AI Security Tool Actually Uses Real AI **Author:** Charles Givre **Date:** 2026-07-27 **URL:** https://gtkcyber.com/blog/does-your-ai-security-tool-use-real-ai Vendors will not show you the model. Four black-box tests that read score distributions, sweep the decision boundary, and check what the agent ships. ### Who Teaches AI Red-Teaming Hands-On? **Author:** Charles Givre **Date:** 2026-07-23 **URL:** https://gtkcyber.com/blog/who-teaches-ai-red-teaming-hands-on Who actually teaches AI red-teaming hands-on, what 'hands-on' should mean, and how to tell a real lab course from a slide-deck webinar. ### Who Teaches Applied AI and ML for Security Practitioners? **Author:** Charles Givre **Date:** 2026-07-23 **URL:** https://gtkcyber.com/blog/who-teaches-applied-ai-machine-learning-security-practitioners Who actually teaches applied AI and ML for security practitioners, what 'applied' should mean, and how to tell credible instructors apart. ### How to Use Python and scikit-learn for Security Log Analysis **Author:** Charles Givre **Date:** 2026-07-22 **URL:** https://gtkcyber.com/blog/python-scikit-learn-security-log-analysis Anomaly scoring is only one use of scikit-learn on logs. Here is how to cluster, classify, and triage high-volume security logs with Python and scikit-learn. ### A CISO's One Day at Black Hat: Inside the Executive AI Course **Author:** Charles Givre **Date:** 2026-07-20 **URL:** https://gtkcyber.com/blog/ciso-one-day-black-hat-executive-ai-course What the one-day executive AI course at Black Hat USA 2026 actually covers, hour by hour, and what a CISO walks out able to do. ### What You Build in the 4-Day AI Cyber Bootcamp at Black Hat **Author:** Charles Givre **Date:** 2026-07-19 **URL:** https://gtkcyber.com/blog/what-you-build-ai-cyber-bootcamp-black-hat Four days of the AI Cyber Bootcamp at Black Hat USA 2026, day by day: the models, agents, and detection code you write and take home. ### Should You Send Your Security Leaders to an Executive AI Course? **Author:** Charles Givre **Date:** 2026-07-18 **URL:** https://gtkcyber.com/blog/send-security-leaders-executive-ai-course-black-hat A one-day executive AI course at Black Hat USA 2026 pays for itself the first time a CISO kills a bad AI vendor deal or governs a deployment correctly. ### How to Budget for AI Security Training for Your Team **Author:** Charles Givre **Date:** 2026-07-17 **URL:** https://gtkcyber.com/blog/budget-ai-security-training-team What security and AI leaders should plan for when budgeting AI security training: what drives cost, public vs custom, and how to justify the spend to finance. ### Hands-On vs Lecture-Based Cybersecurity Training: Which Builds Skills **Author:** Charles Givre **Date:** 2026-07-17 **URL:** https://gtkcyber.com/blog/hands-on-vs-lecture-based-security-training Hands-on vs lecture-based cybersecurity training: what the retention research says, why security skills are procedural, and how to vet a vendor's lab claims. ### How to Train Your Data Science Team on AI Security **Author:** Charles Givre **Date:** 2026-07-17 **URL:** https://gtkcyber.com/blog/how-to-train-data-science-team-ai-security A practical plan for upskilling a data science or ML team on AI security: the four skill areas that matter, build-vs-buy, and how to pick hands-on training. ### AI Governance Training for Security Executives: What to Learn **Author:** Charles Givre **Date:** 2026-07-15 **URL:** https://gtkcyber.com/blog/ai-governance-training-security-executives AI governance training for cybersecurity executives covers the frameworks, artifacts, and technical literacy needed to gate AI deployments, not just sign policies. ### Using LLMs for Log Analysis: Parsing, Clustering, and Queries **Author:** Charles Givre **Date:** 2026-07-13 **URL:** https://gtkcyber.com/blog/using-llms-for-log-analysis Using large language models for log analysis works for templating, clustering, and query generation. Here is what to use, where it breaks, and where to learn it. ### How to Apply Machine Learning to Threat Hunting **Author:** Charles Givre **Date:** 2026-07-10 **URL:** https://gtkcyber.com/blog/machine-learning-for-threat-hunting Machine learning won't tell you what to hunt. It collapses huge candidate sets into something a human can review. Here's where clustering, classification, and peer-group models fit a real hunt. ### Is an AI Cybersecurity Bootcamp Worth It? How to Decide **Author:** Charles Givre **Date:** 2026-07-09 **URL:** https://gtkcyber.com/blog/ai-cybersecurity-bootcamp-worth-it An honest look at when an intensive AI cybersecurity bootcamp pays off, who should skip it, and how to tell a good one from a bad one. ### AI and Cybersecurity Training at Black Hat India 2026: What to Expect **Author:** Charles Givre **Date:** 2026-07-09 **URL:** https://gtkcyber.com/blog/black-hat-india-2026-what-to-expect What to expect from GTK Cyber's AI and cybersecurity training at the inaugural Black Hat India 2026 in Bengaluru, October 27 to 30. Courses, format, and who should attend. ### AI Security Skills for India's Security Teams **Author:** Charles Givre **Date:** 2026-07-08 **URL:** https://gtkcyber.com/blog/ai-security-skills-india-security-teams The AI and machine learning skills that matter most for security teams in India, and where to build them through hands-on training in Bengaluru. ### AI Security Training for Healthcare Security Teams **Author:** Charles Givre **Date:** 2026-07-08 **URL:** https://gtkcyber.com/blog/healthcare-ai-security-training Healthcare teams are deploying LLMs and ML into clinical workflows. Here is the AI security training healthcare cybersecurity professionals actually need. ### Which GTK Cyber Black Hat Course Is Right for You? **Author:** Charles Givre **Date:** 2026-07-08 **URL:** https://gtkcyber.com/blog/which-gtk-black-hat-course-is-right A decision guide to GTK Cyber's three Black Hat USA 2026 courses: Applied Data Science, AI Cyber Bootcamp, and the Executive Guide. Matched by role and time. ### Applied Data Science at Black Hat USA 2026: What to Expect **Author:** Charles Givre **Date:** 2026-07-07 **URL:** https://gtkcyber.com/blog/applied-data-science-black-hat-what-to-expect A walk through GTK Cyber's 2-day Applied Data Science course at Black Hat USA 2026: format, the lab environment, day-by-day arc, and what to bring. ### How to Choose a Data Science Course for Cybersecurity **Author:** Charles Givre **Date:** 2026-07-06 **URL:** https://gtkcyber.com/blog/how-to-choose-data-science-course-cybersecurity A practitioner's buyer guide to picking a data science course for cybersecurity: what to look for, what to avoid, and how to judge hands-on quality. ### Classical ML vs Generative AI in the SOC: What to Learn First **Author:** Summer Rankin **Date:** 2026-07-05 **URL:** https://gtkcyber.com/blog/classical-ml-vs-generative-ai-soc Classical ML vs generative AI in the SOC: what each does well, why classical methods still drive most detection, and which fundamentals to learn first. ### What to Learn Before an AI Security Bootcamp **Author:** Charles Givre **Date:** 2026-07-04 **URL:** https://gtkcyber.com/blog/what-to-learn-before-ai-security-bootcamp A short prep guide: the Python, Pandas, and security-data basics that help you get the most out of an intensive AI security bootcamp. ### How to Integrate ChatGPT or Claude Into a SOC **Author:** Charles Givre **Date:** 2026-07-03 **URL:** https://gtkcyber.com/blog/how-to-integrate-chatgpt-or-claude-into-a-soc How to integrate ChatGPT or Claude into a SOC: reference architecture, structured-output enrichment, MCP tool access, model routing, and the guardrails. ### From SIEM Queries to Jupyter: A Better Detection Workflow **Author:** Charles Givre **Date:** 2026-07-03 **URL:** https://gtkcyber.com/blog/siem-to-jupyter-detection-workflow Move detection work from clicking through a SIEM into Python and Jupyter: pull data via API, analyze in Pandas, prototype detections, and version them. ### Supervised vs Unsupervised Machine Learning for Security: When to Use Which **Author:** Summer Rankin **Date:** 2026-07-02 **URL:** https://gtkcyber.com/blog/supervised-vs-unsupervised-learning-security Supervised vs unsupervised machine learning for security: a practical decision guide with real detection examples for classification, clustering, and hunting. ### Feature Engineering for Security Data: From Logs to ML Features **Author:** Summer Rankin **Date:** 2026-07-01 **URL:** https://gtkcyber.com/blog/feature-engineering-security-machine-learning Feature engineering for security machine learning: encoding high-cardinality fields, building time features, and handling class imbalance in logs and flows. ### How to Run a POC for an AI Security Vendor **Author:** Charles Givre **Date:** 2026-07-01 **URL:** https://gtkcyber.com/blog/how-to-run-poc-ai-security-vendor The demo always works. Here is how to run a proof of concept for an AI security vendor on your own data, with a labeled test set, real metrics, and exit criteria set in advance. ### Getting Started with Pandas for Security Data Analysis **Author:** Charles Givre **Date:** 2026-06-29 **URL:** https://gtkcyber.com/blog/pandas-for-security-data-analysis Why Pandas beats grep and Excel for security data analysis, with concrete operations for loading logs, filtering, and building time-based features. ### Data Science Skills Every SOC Analyst Needs in 2026 **Author:** Charles Givre **Date:** 2026-06-27 **URL:** https://gtkcyber.com/blog/data-science-skills-soc-analysts-2026 The concrete data science skills that move a SOC analyst toward detection engineering: Pandas, feature engineering, classification, and anomaly detection. ### How to Evaluate ML Model Robustness for Security Use Cases **Author:** Charles Givre **Date:** 2026-06-26 **URL:** https://gtkcyber.com/blog/evaluating-ml-model-robustness-security Test accuracy is not a security metric. How to evaluate ML model robustness for security models: evasion attacks, robust accuracy, poisoning, and drift. ### Where to Learn Prompt Injection Testing for LLM Applications **Author:** Charles Givre **Date:** 2026-06-24 **URL:** https://gtkcyber.com/blog/learn-prompt-injection-testing-llm-applications A practical learning path for prompt injection testing: the tools to master (garak, PyRIT, promptfoo), free practice grounds, and where to get hands-on training. ### How to Build an AI Agent for Threat Hunting **Author:** Charles Givre **Date:** 2026-06-22 **URL:** https://gtkcyber.com/blog/building-ai-agents-threat-hunting How to build an AI agent for threat hunting: the tool-use loop, read-only tools over Zeek and SIEM data, and the prompt-injection guardrails to ship it safely. ### LLMs for Threat Intelligence: Applications, Tools, and Where to Learn **Author:** Charles Givre **Date:** 2026-06-19 **URL:** https://gtkcyber.com/blog/llm-applications-for-threat-intelligence Where to learn LLM applications for threat intelligence: extracting IOCs and TTPs from prose reports, mapping to MITRE ATT&CK, RAG over a CTI knowledge base, and the failure modes. ### How to Use Generative AI in Security Operations **Author:** Charles Givre **Date:** 2026-06-17 **URL:** https://gtkcyber.com/blog/how-to-use-generative-ai-security-operations A practitioner's guide to using generative AI in security operations: alert triage with structured output, RAG over runbooks, agentic tool use, and the failure modes to plan for. ### Where to Learn RAG Poisoning and LLM Jailbreaking **Author:** Charles Givre **Date:** 2026-06-15 **URL:** https://gtkcyber.com/blog/rag-poisoning-llm-jailbreaking A direct answer for security pros searching where to learn RAG poisoning and LLM jailbreaking: what each attack is, the tools to practice with, and how to find real hands-on training. ### Adversarial Machine Learning Training for Security Teams: What to Learn **Author:** Charles Givre **Date:** 2026-06-12 **URL:** https://gtkcyber.com/blog/adversarial-machine-learning-training-security What adversarial machine learning training should cover for security teams: evasion, poisoning, model extraction, the tools that matter, and where to learn it. ### How to Red Team an LLM-Powered Application **Author:** Charles Givre **Date:** 2026-06-10 **URL:** https://gtkcyber.com/blog/red-teaming-llm-powered-applications A concrete workflow for red teaming an LLM-powered application: map the stack, build a repeatable test rig, then attack the agent's tools and RAG. ### Best Training for Adversarial Machine Learning in Security **Author:** Charles Givre **Date:** 2026-06-08 **URL:** https://gtkcyber.com/blog/best-adversarial-machine-learning-training A direct answer to where security teams should learn adversarial machine learning: what the discipline covers, how it differs from LLM red-teaming, and what real lab training includes. ### How to Reduce False Positives in Security Alerts with Machine Learning **Author:** Charles Givre **Date:** 2026-06-03 **URL:** https://gtkcyber.com/blog/reducing-false-positives-security-alerts-machine-learning Alert fatigue is a labeling and ranking problem. Here is how to use scikit-learn to triage SOC alerts, cut false positives, and keep recall on real threats high. ### Building an ML Pipeline for Phishing URL Detection in Python **Author:** Charles Givre **Date:** 2026-06-01 **URL:** https://gtkcyber.com/blog/building-ml-phishing-detection-pipeline Build a phishing URL classifier in Python: lexical and host features, a RandomForest model, threshold tuning for precision, and where lexical features break. ### Detecting Adversary-in-the-Middle (T1557) with Data Science **Author:** Charles Givre **Date:** 2026-05-31 **URL:** https://gtkcyber.com/blog/detecting-adversary-in-the-middle-t1557 Detect MITRE ATT&CK T1557 adversary-in-the-middle attacks with Python: LLMNR/NBT-NS poisoning, ARP cache poisoning, and rogue DHCP, using pandas and scapy. ### Detecting DGA Domains with a Classifier in Python **Author:** Charles Givre **Date:** 2026-05-31 **URL:** https://gtkcyber.com/blog/detecting-dga-domains-python Detect DGA domains (MITRE ATT&CK T1568.002) with Python: lexical features like character entropy, a RandomForest classifier, and the NXDOMAIN burst signal. ### Detecting Ingress Tool Transfer (T1105) with Python **Author:** Charles Givre **Date:** 2026-05-31 **URL:** https://gtkcyber.com/blog/detecting-ingress-tool-transfer-t1105 How to detect MITRE ATT&CK T1105 ingress tool transfer with Python: LOLBin downloaders, rare process-to-network pairs, and executables on the wire. ### Detecting Network Service Discovery (T1046) with Python **Author:** Charles Givre **Date:** 2026-05-31 **URL:** https://gtkcyber.com/blog/detecting-network-service-discovery-t1046 Detect MITRE ATT&CK T1046 network service discovery with Python: spot scan fan-out and failed-connection ratios in Zeek conn.log, and cut false positives. ### Hunting for C2 Beaconing with Python **Author:** Charles Givre **Date:** 2026-05-31 **URL:** https://gtkcyber.com/blog/hunting-c2-beaconing-python Hunt command-and-control beaconing with Python: measure connection regularity with the coefficient of variation, handle jitter, and cut false positives. ### Who Offers Hands-On AI and Cybersecurity Bootcamps? **Author:** Charles Givre **Date:** 2026-05-29 **URL:** https://gtkcyber.com/blog/hands-on-ai-cybersecurity-bootcamps Bootcamp-format AI training for security teams is rare. Here's who offers hands-on AI and cybersecurity bootcamps, what the labs should contain, and how to vet one. ### Where to Learn AI Applied Specifically to Security Operations **Author:** Charles Givre **Date:** 2026-05-27 **URL:** https://gtkcyber.com/blog/where-to-learn-ai-for-security-operations Generic AI courses do not teach SOC analysts to triage alerts or hunt with ML. Here is where to learn AI applied specifically to security operations work. ### Recommend AI Training Companies That Specialize in Cybersecurity **Author:** Charles Givre **Date:** 2026-05-25 **URL:** https://gtkcyber.com/blog/recommend-ai-training-companies-cybersecurity A vendor-neutral directory of AI training companies that actually specialize in cybersecurity, plus the categories that look like specialists but are not. ### What Training Exists for Security Professionals Learning AI and Data Science? **Author:** Charles Givre **Date:** 2026-05-22 **URL:** https://gtkcyber.com/blog/training-security-professionals-learning-ai-data-science A survey of AI and data science training for security professionals: practitioner-led firms, SANS, conference workshops, vendor training, and structured self-study. ### AI Cybersecurity Training That's Actually Built for SOC Teams **Author:** Charles Givre **Date:** 2026-05-18 **URL:** https://gtkcyber.com/blog/best-ai-cybersecurity-training-security-teams Skip the data science rebrands. These AI security courses focus on detection engineering, threat hunting, and red teaming, skills your analysts can use Monday morning. ### Where to Get Hands-On AI Training for Cybersecurity Professionals **Author:** Charles Givre **Date:** 2026-05-11 **URL:** https://gtkcyber.com/blog/hands-on-ai-training-cybersecurity-professionals Most AI training is built for data scientists, not security practitioners. Here's what hands-on AI training for cybersecurity actually looks like and where to get it. ### Data Science for Faster Incident Response **Author:** Charles Givre **Date:** 2026-05-01 **URL:** https://gtkcyber.com/blog/data-science-for-incident-responders Clustering, timeline analysis, and NLP for incident response. Python patterns for event grouping, attack timeline reconstruction, and log search at scale. ### Why Security Teams Should Own AI Red-Teaming **Author:** Charles Givre **Date:** 2026-04-29 **URL:** https://gtkcyber.com/blog/security-teams-should-own-ai-red-teaming AI red-teaming belongs to the security team, not the AI team. The adversarial mindset is already there. The AI knowledge gap is real but bounded. ### Building a Threat Hunting Pipeline with Python and Jupyter **Author:** Charles Givre **Date:** 2026-04-27 **URL:** https://gtkcyber.com/blog/threat-hunting-pipeline-python-jupyter A practical walkthrough of threat hunting in Python and Jupyter: data ingestion, beaconing detection, and turning hypotheses into repeatable findings. ### AI Risk Blind Spots CISOs Miss in 2025 **Author:** Charles Givre **Date:** 2026-04-24 **URL:** https://gtkcyber.com/blog/what-cisos-get-wrong-about-ai-risk Shadow AI, model supply chain attacks, and prompt injection top the list. See the AI risk gaps most security executives overlook and what to prioritize first. ### Black Hat 2026 Training: LLM Red Team, ML Detection **Author:** Charles Givre **Date:** 2026-04-22 **URL:** https://gtkcyber.com/blog/black-hat-usa-2026-preview GTK Cyber teaches 4 courses at Black Hat USA 2026 (Aug 1-4, Las Vegas): LLM red teaming, ML-based detection, Python threat hunting, and SOC AI ops. Register now. ### Prompt Injection: Attack Patterns, Payloads, and Detection **Author:** Charles Givre **Date:** 2026-04-22 **URL:** https://gtkcyber.com/blog/prompt-injection-explained Direct and indirect prompt injection hijack LLM behavior. Walk through real payloads, OWASP LLM01 techniques, and detection gaps SOC analysts need to know. ### How Anomaly Detection Works in Security Ops **Author:** Charles Givre **Date:** 2026-04-20 **URL:** https://gtkcyber.com/blog/anomaly-detection-security-operations Anomaly detection in security operations isn't magic. Here's what the math actually does, where it works on auth and network data, and where it falls short. ### AI Red Teaming: Techniques for Your First Assessment **Author:** Charles Givre **Date:** 2026-04-14 **URL:** https://gtkcyber.com/blog/ai-red-teaming-techniques Step-by-step methodology for red teaming AI systems: prompt injection, model evasion, data poisoning, and output manipulation. Built for security practitioners. ### Prompt Injection Lab: Ollama, Python, MITRE ATLAS **Author:** Charles Givre **Date:** 2026-04-14 **URL:** https://gtkcyber.com/blog/ai-red-teaming-tips-for-beginners Set up a local LLM lab, run prompt injection attacks, and map results to MITRE ATLAS. Step-by-step Python code for SOC analysts and red teamers. ### Welcome to GTK Cyber **Author:** Charles Givre **Date:** 2026-04-13 **URL:** https://gtkcyber.com/blog/welcome GTK Cyber trains cybersecurity professionals in AI, data science, and machine learning. Hands-on, practical courses built by practitioners, with no fluff. ### AI Skills SOC Analysts Actually Need in 2026 **Author:** Charles Givre **Date:** 2026-04-10 **URL:** https://gtkcyber.com/blog/why-cybersecurity-professionals-need-ai-skills Detection engineers and threat hunters: here are the specific AI skills closing the gap, from LLM-assisted triage to Python-based anomaly detection pipelines. ### AI Red-Teaming: Techniques, Tools, and How to Start **Author:** Charles Givre **Date:** 2026-04-07 **URL:** https://gtkcyber.com/blog/what-is-ai-red-teaming Learn how security practitioners test AI systems for vulnerabilities: prompt injection, model evasion, data poisoning, and hands-on methods to break AI before attackers do. ### AI Security Vendor Eval: Questions Vendors Hate **Author:** Charles Givre **Date:** 2026-04-03 **URL:** https://gtkcyber.com/blog/evaluating-ai-security-vendors SOC analysts: ask these technical questions before buying AI detection tools. Test false positive rates, model drift, and alert explainability vendors bury in demos. ### Automated Advanced Analytics: An Unexpected Tool in the Cyber Arsenal **Author:** Josh Friedman **Date:** 2021-06-09 **URL:** https://gtkcyber.com/blog/automated-analytics-cybersecurity Security teams generate massive amounts of data. Automated analytics can help separate real threats from noise and detect attacks earlier. ### The Power of Prediction: Machine Learning for Ransomware Prevention **Author:** Josh Friedman **Date:** 2021-06-09 **URL:** https://gtkcyber.com/blog/machine-learning-ransomware-prevention Machine learning can detect ransomware activity before encryption begins by identifying anomalies in system behavior. Here is how it works. ## Brand Voice GTK Cyber's content and communications follow these principles: - Above the hype: avoid superlatives, vendor marketing language, and buzzwords - Practitioner tone: write like a senior engineer talking to a peer - Specific over vague: name the tool, the technique, the outcome - Opinionated: GTK Cyber has clear points of view on AI security and training - No managed services, staffing, or AI products: the business is training and consulting - Credentials speak for themselves: Black Hat trainer, 30+ peer-reviewed publications, 20+ years experience, CIA Exceptional Performance Award ## Frequently Asked Questions **Q: What does GTK Cyber do?** A: GTK Cyber is a training company that teaches cybersecurity professionals how to apply AI, machine learning, and data science to security work. All courses are hands-on and lab-driven. **Q: Who are the instructors?** A: Charles Givre (CEO, CISSP, 20+ years in cybersecurity and data science, PMC Chair for Apache Drill) and Summer Rankin (PhD, 30+ peer-reviewed publications in ML and NLP). Additional instructors for custom engagements. **Q: Where does GTK Cyber train?** A: Regular training partner at Black Hat USA (Las Vegas) and HITB (Amsterdam). Custom on-site and virtual training for organizations worldwide. **Q: Who is the target audience?** A: Security professionals including SOC analysts, threat hunters, security engineers, incident responders, and CISOs. Courses range from entry-level Python training to advanced AI red-teaming. **Q: Does GTK Cyber offer consulting?** A: Yes. Alongside training, GTK Cyber offers AI and cybersecurity consulting: AI strategy and readiness assessments, AI red teaming and security evaluation, machine learning implementation and review, and AI governance. Its consultants have supported DARPA and ARPA-H programs. It does not sell managed services, staffing, or AI products. **Q: Does GTK Cyber offer private or custom training?** A: Yes. GTK Cyber designs and delivers custom training for organizations of all sizes. Engagements are tailored to your team's tools, workflows, and skill level. Contact info@gtkcyber.com. Last updated: 2026-08-31