SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Generative AI can do some very cool things. But it can also do some incredibly dumb things too. In this talk, Andy will be exploring the internal trust boundaries within LLM-based apps and offering recommendations for managing the security threats that emerge due to the chaotic nature of language models.
Meeting the minimum requirements of your job description takes incredible knowledge, effort. However, employers do not let you in on a little secret of theirs: they expect more out of than just the minimum requirements of your role. In this talk, we will go into tips and tricks you can employ to stretch yourself out of your comfort zone and allow you to shine in your career to current and future employers.
Penetration testing is due for a major overhaul. We need to move away from rigid, checklist-driven assessments and adopt a more agile, continuous, and comprehensive methodology. Pentesters must cover the entire application, no blind spots, no shortcuts. But how do we evolve from ticking boxes to delivering real, lasting value?
AI is the hot new thing and is here to stay. Developers need to embrace it the best they can before being left behind in the dust. For offensive tool developers, they need to leverage models to the fullest extent possible. One of the things that can help speed up the development of a new C2 framework is an AI model like Grok.