communication), endpoint behavior (e.g., unusual process execution), or user activity that deviate from learned baselines of normal. Anomaly Detection Establishes a baseline of "normal" for systems, networks, or users, then flags statistically significant deviations that could indicate zero-day attacks, insider threats, or compromised accounts. Often unsupervised. Malware Analysis Automates classification of malware into families, predicts malicious intent from code structure (static analysis) or behavior in a sandbox (dynamic analysis), and identifies obfuscation techniques. Phishing Detection Uses NLP and ML to analyze email content (text, links, headers, attachments) and sender reputation to identify sophisticated phishing attempts that bypass simple keyword filters. Threat Intelligence Processes and correlates vast amounts of unstructured data (blogs, forums, dark web, CTI feeds) to identify emerging TTPs (Tactics, Techniques, Procedures), predict attack campaigns, and prioritize vulnerabilities Incident Response Automation (SOAR - Security Orchestration, Automation and Response) Automates and orchestrates initial response actions (e.g., isolating endpoints, blocking IPs, enriching alerts) based on AI-driven analysis and predefined playbooks. CORE USE CASES OF AI IN SECURITY