Exploiting 10x Faster

AI Agents for Vulnerability Finding and Exploitation.

The training

Exploiting 10x Faster: AI Agents for Vulnerability Finding and Exploitation

This four-day training is built for experienced vulnerability researchers who want to bring the latest AI Agents, frontier models, Skills, Subagents, and Model Context Protocol (MCP) tooling into their workflow to accelerate reverse engineering, vulnerability finding, and exploit development. Through focused lectures and hands-on labs, you'll use agentic workflows to explore large codebases, surface high-impact bugs, speed up crash triage, and automate reversing and debugging tasks with MCP-enabled Ghidra, IDA Pro, and GDB.

You'll design and build a vulnerability-finding Multi-Agent System using Skills and Subagents, then use it to discover vulnerabilities in a real-world open-source USB stack. Later in the course, we'll put everything together in a separate end-to-end summary exercise based on a real-world VM escape vulnerability, where you'll map attack surfaces, analyze bugs, and develop a working exploit using AI-assisted workflows.

Students leave with practical checklists, repeatable automation patterns, and modern techniques that compress weeks of research into days. Cursor accounts and tooling are provided, though Claude Code users are also welcome. No prior AI experience is required.

Course details
01

AI-Assisted Reverse Engineering and Debugging

  • Introduction to AI agents, Skills, MCPs, and practical offensive security workflows
  • Automating reverse engineering and debugging tasks with Cursor, Ghidra or IDA Pro, and GDB
  • AI-assisted crash triage, binary analysis, and memory corruption debugging workflows
  • Short focused lectures combined with quick, hands-on exercises throughout the module
02

Multi-Agent Vulnerability Finding Harnesses

  • Designing and building Multi-Agent Systems (MAS) for automated vulnerability research
  • Using Skills and Subagents for code exploration, fuzzing harness generation, vulnerability finding, and automated triage
  • Hands-on exercises targeting a real-world open-source USB stack
03

AI-Assisted Exploit Reproduction and Research Environments

  • Building automated IoT vulnerability research lab environments with AI agents using Docker and QEMU
  • Reproducing and debugging a real-world embedded device exploit from public research
  • Using prompting strategies, context management, and Subagents to automate firmware extraction, environment setup, and exploit adaptation
  • Hands-on exercises focused on fixing incomplete PoCs and learning real-world offensive security research workflows
04

Automatic Exploit Generation with AI Agents

  • Full end-to-end exploit-generation exercise where you’ll use AI agents to develop an exploit from scratch against a real-world VirtualBox 1-day vulnerability
  • We’ll cover agent-driven vulnerability analysis, attack-surface mapping, VM escape concepts, exploit development workflows, and the background needed to complete the exercise successfully
  • Instructor walkthrough of the complete agent-assisted exploitation workflow, from initial analysis through exploit generation, testing, and refinement
Who we are

Your instructors

Omri Ben-Bassat

Omri Ben-Bassat

Omri is a vulnerability researcher specializing in reverse engineering, binary exploitation, and low-level vulnerability analysis, with over a decade of experience working on IoT and embedded systems. He has presented his research at Black Hat USA, Black Hat Asia, and the RSA Conference. As part of his more academic research work, Omri will also be presenting at Black Hat USA 2026 on breaking ARM Hardware CFI protections in Linux and Android systems.

Vladimir Tokarev

Vladimir Tokarev

Vladimir is a Senior Vulnerability Researcher at Cyera with over 11 years of experience in the cybersecurity field. He specializes in vulnerability research across Windows, Linux, IoT, OT, and cloud environments. Vladimir has presented his research at leading industry conferences, including Black Hat USA 2023, Black Hat USA 2024, RSA Conference 2023, and DEF CON Recon Village 2025.

Together, Omri and Vladimir have extensively integrated AI agents, modern LLM tooling, and MCP-based workflows into their vulnerability research process. The techniques and workflows taught throughout this training are based on practical experience applying these tools to reverse engineering, vulnerability discovery, exploit development, and real-world offensive security research.

Schedule
From an attendee
Over four days of hands-on labs, I watched Claude Opus 4.6 inside Cursor do things that normally require a worrying amount of coffee, terminal tabs, and muttering under your breath. Security researchers who know how to work with agents are going to move faster than those who do not.”
Mathscantor · Black Hat Asia 2026 attendee Read the full write-up →
Find us

Get in touch

Bringing the training to your team or event, or just have a question? Reach out to either of us directly.