Loading…
Audience: Beginner clear filter
Monday, November 2
 

9:00am PST

3-Day Training: Building AI-based security tools & SDLC
Monday November 2, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026
Level: Beginner
Trainer
:Jon McCoy


To register, please purchase your training ticket here. 
Training and conference are two separate ticket purchases.

Day 1: The Toolsmith (AI-Augmented Security Engineering)
*Focus: Building a high-velocity toolkit for rapid security synthesis and infrastructure hardening.*

*   **The Synthesis Workflow**
    *   Mastering LLM-driven code generation for security scripts.
    *   Building "Disposable Tools" for one-off reconnaissance and triage.
    *   Debugging and refining AI-generated security code.
*   **Security Engineering & Governance**
    *   Developing "Agentic Playbooks" for automated hardening.
    *   Writing high-fidelity Security Requirements (Human vs. Agent-readable).
    *   Creating "Cheat Sheets" for standardizing AI-assisted security tasks.
*   **Hands-on Labs: AI-Driven Hardening & Validation**
    *   **Infrastructure:** Automating Dockerfile, Terraform, and Network Rule hardening.
    *   **Application:** Automated code reviews, "Sink" point identification, and auto-remediation.
    *   **Validation:** Building "Checkers" to programmatically verify vulnerability fixes.

Day 2: The Architect of Trust (Agentic AppSec & Governance)
*Focus: Engineering the autonomous guardrails and validation gates for the Agentic SDLC.*

*   **Securing the Agentic Architecture**
    *   **Tool-Use Guardrails:** Implementing strict schemas and permissions for function calling.
    *   **Sandboxing & Isolation:** Engineering secure execution environments for agent-run code.
Speakers
avatar for Jon McCoy

Jon McCoy

Principal Security Architect & Offensive Engineering Specialist, DigitalBodyGuard
Jon McCoy brings more than 20 years of hands-on experience in software engineering, application
security, live system forensics, infrastructure defense, and custom security tooling. He helps
companies build and secure the back-end systems behind modern AI products, automation
platfo


... Read More →
Monday November 2, 2026 9:00am - 5:00pm PST
TBA
 
Tuesday, November 3
 

9:00am PST

2-Day Training: Beyond Whiteboard Hacking: Embracing AI-Assisted Threat Modeling
Tuesday November 3, 2026 9:00am - 5:00pm PST
2-Day Training: November 3-4, 2026
Level:Intermediate
Trainer: Robert Hurlbut

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

This training immerses you in the practical world of threat modeling through hands-
on exercises and real-world scenarios. With 25 years of practical experience and
over a decade of delivering this training at Black Hat, it emphasizes an interactive
approach—70% of the course is dedicated to exercises that reinforce learning. By
the end, you'll gain not only knowledge but also the skills to effectively practice threat
modeling within your organization.


Updated annually, this revised training covers the latest threat intelligence and attack
methods expected for 2026 and beyond, including risks associated with LLMs and
other AI systems. Participants will engage in practical activities inspired by real
industry projects, such as integrating threat modeling into secure-by-design and
DevOps workflows. Key features include threat-informed defense using MITRE
frameworks like ATT&CK for real-world analysis, using threat libraries and
intelligence to deepen threat understanding, and tackling modern challenges such as
modeling threats for AI-driven systems—specifically, a machine-learning-powered
chatbot. 


Before the training, all participants will get access to our self-paced “introduction to
threat modeling” course, designed to bring participants up to speed.


As practitioners with hands-on experience, we understand the gap between book-
based threat modeling knowledge and the practical challenges faced in real-world
environments. To address this, we have created a comprehensive real-world case
study and exercises to help you build effective threat models.
In this course, you will work in teams of 3 or 4 to address the stages of threat
modeling across various technology stacks.


Examples include:
• Use case describing a home automation system
• Data flow diagramming and trust boundaries
• Identifying threats
• AI-Assisted STRIDE analysis
• Constructing an attack tree
• Mitigating threats
• AI-Assisted mitigations
• Applying GDPR Risk Patterns for Privacy by Design
• Using AI resources to threat model a machine learning powered
HomeAutomationBot
• Integrating the OWASP Threat Modeling Playbook into agile development
• Threat Modeling a CI/CD supply chain
• Red Team / Blue Team battle for control over an offshore wind turbine park


After each exercise, we encourage in-depth discussions and provide a documented
solution to reinforce your understanding. Additionally, participants are invited to
create and submit their “Bring Your Own Case” (BYOC) threat models after the
training and receive personalized feedback to improve their techniques.
To receive the “Certified Threat Modeling Practitioner” certificate, participants must
pass an exam and submit their BYOC threat model.


This training extends beyond the classroom: every participant gains access to our
Threat Modeling Playbook, one year of online learning resources, and invitations to
monthly Ask-Me-Anything sessions to help you keep improving your threat modeling
skills long after the course concludes.

Speakers
avatar for Sebastien Deleersnyder

Sebastien Deleersnyder

CTO, Toreon
Sebastien (Seba) Deleersnyder is co-founder and CTO of Toreon and a proponent of application security as a holistic approach. He started the Belgian OWASP chapter, was an OWASP Foundation Board member, and has given numerous public presentations on Application Security. Seba also... Read More →
Tuesday November 3, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3-Day Training: Building AI-based security tools & SDLC
Tuesday November 3, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026
Level: Beginner
Trainer
:Jon McCoy


To register, please purchase your training ticket here. 
Training and conference are two separate ticket purchases.

Day 1: The Toolsmith (AI-Augmented Security Engineering)
*Focus: Building a high-velocity toolkit for rapid security synthesis and infrastructure hardening.*

*   **The Synthesis Workflow**
    *   Mastering LLM-driven code generation for security scripts.
    *   Building "Disposable Tools" for one-off reconnaissance and triage.
    *   Debugging and refining AI-generated security code.
*   **Security Engineering & Governance**
    *   Developing "Agentic Playbooks" for automated hardening.
    *   Writing high-fidelity Security Requirements (Human vs. Agent-readable).
    *   Creating "Cheat Sheets" for standardizing AI-assisted security tasks.
*   **Hands-on Labs: AI-Driven Hardening & Validation**
    *   **Infrastructure:** Automating Dockerfile, Terraform, and Network Rule hardening.
    *   **Application:** Automated code reviews, "Sink" point identification, and auto-remediation.
    *   **Validation:** Building "Checkers" to programmatically verify vulnerability fixes.

Day 2: The Architect of Trust (Agentic AppSec & Governance)
*Focus: Engineering the autonomous guardrails and validation gates for the Agentic SDLC.*

*   **Securing the Agentic Architecture**
    *   **Tool-Use Guardrails:** Implementing strict schemas and permissions for function calling.
    *   **Sandboxing & Isolation:** Engineering secure execution environments for agent-run code.
Speakers
avatar for Jon McCoy

Jon McCoy

Principal Security Architect & Offensive Engineering Specialist, DigitalBodyGuard
Jon McCoy brings more than 20 years of hands-on experience in software engineering, application
security, live system forensics, infrastructure defense, and custom security tooling. He helps
companies build and secure the back-end systems behind modern AI products, automation
platfo


... Read More →
Tuesday November 3, 2026 9:00am - 5:00pm PST
TBA
 
Wednesday, November 4
 

9:00am PST

1-Day Training: Secure Code with AI: Building a Trustworthy Spec-Driven AI Code Workflow
Wednesday November 4, 2026 9:00am - 5:00pm PST

1-Day Training: November 4, 2026
Level: Beginner
Trainer: Jim Manico

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

AI coding assistants are rapidly becoming the core of modern software delivery. They can accelerate development, generate tests, explain unfamiliar code, and assist with security review. They can also introduce insecure patterns, mishandle secrets, overreach with dangerous permissions, and produce code that appears correct while quietly violating security requirements.
This one-day, hands-on workshop shows developers and security professionals how to take control of AI-assisted development by building a trustworthy, spec-driven secure coding workflow.
Jim Manico walks participants through setting up a secure Claude Code and Codex environments from scratch, including permission controls, project-level security rules, hook configuration, and sandboxing. Participants will learn how to load secure coding prompts, define security requirements before code is generated, and use Claude Code and Codex side by side for secure code generation, security review, test creation, and vulnerability detection.
The session is fast-moving, demo-driven, and grounded in real codebases. Attendees will leave with practical workflows they can apply immediately to make AI coding assistants a security asset rather than an uncontrolled source of risk.
What You’ll LearnBy the end of this workshop, participants will be able to:
  • Configure a safer Claude Code environment using permission controls, CLAUDE.md security rules, hooks, and sandboxing.
  • Use secure coding prompts and project-level rules to guide AI tools toward secure-by-default output aligned with OWASP guidance.
  • Apply spec-driven AI development techniques so security requirements are defined before code is generated.
  • Use Claude Code and Codex together for code generation, independent review, vulnerability detection, and test creation.
  • Identify common insecure patterns produced by AI coding assistants, including weak authorization, injection flaws, insecure secret handling, unsafe dependencies, and insufficient validation.
  • Build repeatable AI-assisted workflows that developers, security engineers, and technical leads can bring back to their own teams.
Who Should AttendThis course is designed for:
  • Developers using or evaluating AI coding assistants who want to ship secure code from the start.
  • Security engineers who need to understand how AI tools generate insecure code patterns and how to detect, review, and fix them.
  • Application security professionals building secure development workflows for AI-assisted engineering teams.
  • Tech leads and architects evaluating how AI coding tools should be adopted safely across their organizations.
RequirementsParticipants should bring a laptop suitable for software development and be comfortable working with command-line tools, source code, and Git. An OpenAI or Anthropic account is needed to participate which we can set up in class. Prior experience with AI coding assistants is helpful but not required. The course is designed for developers and security professionals who want practical, repeatable workflows for using AI safely in real engineering environments.

Speakers
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

2-Day Training: 2-Day Training: Beyond Whiteboard Hacking: Embracing AI-Assisted Threat Modeling
Wednesday November 4, 2026 9:00am - 5:00pm PST
2-Day Training: November 3-4, 2026
Level: Beginner

To register, please purchase your training ticket here. Training and conference are two separate ticket purchases.

This training immerses you in the practical world of threat modeling through hands-on exercises and real-world scenarios. With 25 years of practical experience and over a decade of delivering this training at Black Hat, it emphasizes an interactive approach—70% of the course is dedicated to exercises that reinforce learning. By the end, you'll gain not only knowledge but also the skills to effectively practice threat modeling within your organization.

Updated annually, this revised training covers the latest threat intelligence and attack methods expected for 2026 and beyond, including risks associated with LLMs and other AI systems. Participants will engage in practical activities inspired by real industry projects, such as integrating threat modeling into secure-by-design and DevOps workflows. Key features include threat-informed defense using MITRE frameworks like ATT&CK for real-world analysis, using threat libraries and
intelligence to deepen threat understanding, and tackling modern challenges such as modeling threats for AI-driven systems—specifically, a machine-learning-powered chatbot. 

Before the training, all participants will get access to our self-paced “introduction to threat modeling” course, designed to bring participants up to speed.

As practitioners with hands-on experience, we understand the gap between book-based threat modeling knowledge and the practical challenges faced in real-world environments. To address this, we have created a comprehensive real-world case study and exercises to help you build effective threat models. In this course, you will work in teams of 3 or 4 to address the stages of threat modeling across various technology stacks.

Examples include:
• Use case describing a home automation system
• Data flow diagramming and trust boundaries
• Identifying threats
• AI-Assisted STRIDE analysis
• Constructing an attack tree
• Mitigating threats
• AI-Assisted mitigations
• Applying GDPR Risk Patterns for Privacy by Design
• Using AI resources to threat model a machine learning powered
HomeAutomationBot
• Integrating the OWASP Threat Modeling Playbook into agile development
• Threat Modeling a CI/CD supply chain
• Red Team / Blue Team battle for control over an offshore wind turbine park


After each exercise, we encourage in-depth discussions and provide a documented solution to reinforce your understanding. Additionally, participants are invited to create and submit their “Bring Your Own Case” (BYOC) threat models after the training and receive personalized feedback to improve their techniques. To receive the “Certified Threat Modeling Practitioner” certificate, participants must pass an exam and submit their BYOC threat model.


This training extends beyond the classroom: every participant gains access to our
Threat Modeling Playbook, one year of online learning resources, and invitations to
monthly Ask-Me-Anything sessions to help you keep improving your threat modeling
skills long after the course concludes.

Speakers
avatar for Sebastien Deleersnyder

Sebastien Deleersnyder

CTO, Toreon
Sebastien (Seba) Deleersnyder is co-founder and CTO of Toreon and a proponent of application security as a holistic approach. He started the Belgian OWASP chapter, was an OWASP Foundation Board member, and has given numerous public presentations on Application Security. Seba also... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA

9:00am PST

3-Day Training: Building AI-based security tools & SDLC
Wednesday November 4, 2026 9:00am - 5:00pm PST
3-Day Training: November 2-4, 2026
Level: Beginner
Trainer
:Jon McCoy


To register, please purchase your training ticket here. 
Training and conference are two separate ticket purchases.

Day 1: The Toolsmith (AI-Augmented Security Engineering)
*Focus: Building a high-velocity toolkit for rapid security synthesis and infrastructure hardening.*

*   **The Synthesis Workflow**
    *   Mastering LLM-driven code generation for security scripts.
    *   Building "Disposable Tools" for one-off reconnaissance and triage.
    *   Debugging and refining AI-generated security code.
*   **Security Engineering & Governance**
    *   Developing "Agentic Playbooks" for automated hardening.
    *   Writing high-fidelity Security Requirements (Human vs. Agent-readable).
    *   Creating "Cheat Sheets" for standardizing AI-assisted security tasks.
*   **Hands-on Labs: AI-Driven Hardening & Validation**
    *   **Infrastructure:** Automating Dockerfile, Terraform, and Network Rule hardening.
    *   **Application:** Automated code reviews, "Sink" point identification, and auto-remediation.
    *   **Validation:** Building "Checkers" to programmatically verify vulnerability fixes.

Day 2: The Architect of Trust (Agentic AppSec & Governance)
*Focus: Engineering the autonomous guardrails and validation gates for the Agentic SDLC.*

*   **Securing the Agentic Architecture**
    *   **Tool-Use Guardrails:** Implementing strict schemas and permissions for function calling.
    *   **Sandboxing & Isolation:** Engineering secure execution environments for agent-run code.
Speakers
avatar for Jon McCoy

Jon McCoy

Principal Security Architect & Offensive Engineering Specialist, DigitalBodyGuard
Jon McCoy brings more than 20 years of hands-on experience in software engineering, application
security, live system forensics, infrastructure defense, and custom security tooling. He helps
companies build and secure the back-end systems behind modern AI products, automation
platfo


... Read More →
Wednesday November 4, 2026 9:00am - 5:00pm PST
TBA
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.