Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore how artificial intelligence is revolutionizing offensive security through autonomous AI agents that think and operate like real attackers in this 54-minute conference talk. Learn about cutting-edge research and development in building AI systems that go beyond traditional automation to perform independent reconnaissance, analyze application behavior, and dynamically chain vulnerabilities across the entire attack kill chain. Discover how these agents navigate authentication flows, identify misconfigured headers and open endpoints, build real-time attack graphs, and make contextual decisions based on application responses without predefined exploit logic. Examine a detailed case study where an AI agent successfully navigated a modern web application's authentication, discovered an unlinked admin panel, and exploited an Insecure Direct Object Reference (IDOR) vulnerability by reasoning through weak session handling and misconfigured access controls. Understand the technical architecture behind these offensive AI systems, including autonomous reconnaissance modules, dynamic payload generators, and sophisticated memory and context handling mechanisms. Address the practical challenges of simulating real-world attacks at scale and the limitations currently faced in AI-driven offensive security. Gain insights from real-world research and development trials that demonstrate how machine reasoning and exploration can uncover vulnerabilities often missed by manual testing or traditional scripted approaches, offering practical perspectives for red teamers and security engineers looking to advance beyond conventional tooling.
Syllabus
Sandeep Kamble - When AI Goes Offensive, Exploiting the Unexploitable
Taught by
LASCON