Training Description
Key Takeaways
- Focuses on holistic, human-centered approaches to cyberattack investigation
- Explores provenance graphs, causal inference, and explainable security analytics
- Integrates AI, systems design, and human factors for advanced threat response
- Targets cybersecurity researchers, practitioners, and analysts across sectors
- Emphasizes interactive workshops, live demonstrations, and community building
The Workshop on Attack Provenance, Reasoning, and Investigation for Security in the Monitored Environment (PRISM) 2026 is a pioneering event co-located with the NDSS Symposium. Designed for both academic and practitioner audiences, PRISM aims to redefine how the cybersecurity community investigates and responds to sophisticated cyber threats. By fostering collaboration and knowledge exchange, the workshop seeks to establish new standards for effective, explainable, and analyst-friendly security analytics.
Advancing Holistic Cyberattack Investigation
PRISM 2026 is dedicated to moving beyond fragmented, alert-centric detection methods. The workshop emphasizes holistic reasoning and causal understanding in cyberattack investigations. Attendees will explore the latest research on provenance graphs, attack-path reconstruction, and causal inference, all aimed at providing a comprehensive view of complex attack scenarios.
By integrating AI and machine learning models—such as graph learning, diffusion models, and large language models—the event highlights innovative approaches to detection and investigation. These technologies are presented alongside discussions on provenance analytics infrastructure, cross-domain correlation, and the challenges of modern deployment environments, including cloud, containers, IoT, and cyber-physical systems.
Human-Centered and Explainable Security Analytics
A core theme of PRISM is the development of analyst-friendly tools and methods that prioritize human factors in security operations. The workshop addresses the need for explainable analytics, real-time investigation pipelines, and robust log capture and integrity. Attendees will engage with standards such as W3C PROV, OpenTelemetry, and MITRE ATT&CK, as well as discussions on privacy and governance for provenance data.
Interactive sessions, including live demonstrations and tutorials, provide practical insights into the application of these technologies. The event encourages active participation, fostering a collaborative environment for sharing research, best practices, and innovative solutions.
Audience and Impact
PRISM 2026 is tailored for cybersecurity researchers, analysts, incident responders, security engineers, and system architects from industry, government, and academia. The workshop serves as a catalyst for shifting the security community’s approach to threat investigation, emphasizing education, thought leadership, and community building over direct product marketing.
By establishing a new foundation for defenders, PRISM aims to address the pressing challenges of modern cyber defense and contribute to a safer, more trustworthy digital environment.

