Hackfest - Level UP

Your Brain is Lying to You: Cognitive Bias in Security Investigations
Langue: English

Security investigations feel rigorous — but they're shaped by the same cognitive shortcuts that affect every high-stakes decision made under pressure. This talk explores how confirmation bias, anchoring, and automation bias play out in real investigations, and how AI tools amplify these patterns rather than fix them. Through real-world examples from the SOC, you'll walk away with a clearer understanding of how your brain works against you during investigations — and practical techniques to build in the checks.


Overview
We invest heavily in tooling, detection engineering, and threat intelligence. We invest far less in understanding how analysts actually make decisions under pressure — and where those decisions quietly go wrong. This talk makes that case through real SOC stories and walks away with actionable techniques.
Sections
Introduction — 1 min
Brief framing: who I am, why I care about this, and why this talk comes from experience rather than research.
The Setup: Target Breach — 2 min
FireEye flagged the intrusion correctly. The alerts fired. Nobody acted. The gap between the alert and the decision is where investigations actually succeed or fail — and that gap is human.
Act 1: How Our Brains Work Against Us — 9 min
Two biases explored through real investigation stories:

Confirmation bias: the mental model that decided threats only come from outside — and the laptop that stayed unlocked
Anchoring: a malware file with .pdf in the name, a colleague who closed the alert, and the second detection that forced a rethink. The attacker wasn't targeting analysts — they were targeting the user. The analyst fell for the same trick anyway.

Act 2: How AI Makes It Worse — 7 min

Automation bias: hours of investigation built on an AWS abuse notification that turned out to be a bug on AWS's side. We interrogated ourselves. We never questioned the source.
AI sycophancy: AI is designed to be agreeable. Bring it a hypothesis and it will help you build it — not challenge it.
AI anchoring: how AI verdicts affect team dynamics, not just individual analysis.
AI hallucination: a remediation command that didn't exist, defended with another hallucination.
De-skilling: the long-term cost of outsourcing judgment.

What To Do — 3 min
Three levels — individual habits (name your hypothesis out loud, question the source, make AI argue with you), team practices (don't investigate alone, run tabletops), and culture (normalize "right to error"). Closes with: awareness alone reduces bias by 29%.
Close — 1 min
We spend enormous energy understanding how attackers think. We should spend the same energy understanding how we think.

L'image de profil de l'intervenant
Anastasiia Mytrofanovska

Security Operations Manager and investigator — I spend my days untangling cases, diving into logs, and figuring out what actually happened. Curiosity is what drives me, and I've been in tech long enough to know that the best part of this field is the people in it. Happy to be part of this community and always excited to learn from the folks around me!