AI Agents for Vulnerability Finding and Exploitation.
This four-day training is built for experienced vulnerability researchers who want to bring the latest AI Agents, frontier models, Skills, Subagents, and Model Context Protocol (MCP) tooling into their workflow to accelerate reverse engineering, vulnerability finding, and exploit development. Through focused lectures and hands-on labs, you'll use agentic workflows to explore large codebases, surface high-impact bugs, speed up crash triage, and automate reversing and debugging tasks with MCP-enabled Ghidra, IDA Pro, and GDB.
You'll design and build a vulnerability-finding Multi-Agent System using Skills and Subagents, then use it to discover vulnerabilities in a real-world open-source USB stack. Later in the course, we'll put everything together in a separate end-to-end summary exercise based on a real-world VM escape vulnerability, where you'll map attack surfaces, analyze bugs, and develop a working exploit using AI-assisted workflows.
Students leave with practical checklists, repeatable automation patterns, and modern techniques that compress weeks of research into days. Cursor accounts and tooling are provided, though Claude Code users are also welcome. No prior AI experience is required.
Omri is a vulnerability researcher specializing in reverse engineering, binary exploitation, and low-level vulnerability analysis, with over a decade of experience working on IoT and embedded systems. He has presented his research at Black Hat USA, Black Hat Asia, and the RSA Conference. As part of his more academic research work, Omri will also be presenting at Black Hat USA 2026 on breaking ARM Hardware CFI protections in Linux and Android systems.
Vladimir is a Senior Vulnerability Researcher at Cyera with over 11 years of experience in the cybersecurity field. He specializes in vulnerability research across Windows, Linux, IoT, OT, and cloud environments. Vladimir has presented his research at leading industry conferences, including Black Hat USA 2023, Black Hat USA 2024, RSA Conference 2023, and DEF CON Recon Village 2025.
Together, Omri and Vladimir have extensively integrated AI agents, modern LLM tooling, and MCP-based workflows into their vulnerability research process. The techniques and workflows taught throughout this training are based on practical experience applying these tools to reverse engineering, vulnerability discovery, exploit development, and real-world offensive security research.
Sign up and we'll keep you posted when new dates are announced.
Over four days of hands-on labs, I watched Claude Opus 4.6 inside Cursor do things that normally require a worrying amount of coffee, terminal tabs, and muttering under your breath. Security researchers who know how to work with agents are going to move faster than those who do not.”
Bringing the training to your team or event, or just have a question? Reach out to either of us directly.