Cover Image for RSAC: AI + CYBERSECURITY HANDS-ON WORKSHOP (With a Certificate of Completion)
Cover Image for RSAC: AI + CYBERSECURITY HANDS-ON WORKSHOP (With a Certificate of Completion)
Avatar for AI Start Academy
Presented by
AI Start Academy
Hosted By

RSAC: AI + CYBERSECURITY HANDS-ON WORKSHOP (With a Certificate of Completion)

Get Tickets
Past Event
Welcome! Please choose your desired ticket type:
About Event

POST-RSAC AI CYBERSECURITY HANDS-ON

2-Evening Intensive · San Francisco · Presented by AI Start Academy & Threatbreaker · Instructor: Top Silicon Valley Cybersecurity Expert (Bogdan Red) · Certificate of Completion Provided · Recordings Provided

March 25 - 26 // 6-9pm PST


You just spent the day at RSA.

Keynotes. Vendor booths. Panels about AI transforming security.

Now come actually use it.

Post-RSAC AI Cybersecurity Hands-On is a practitioner-first evening workshop running two nights last 2 days of the conference. No slides-only sessions. No vendor pitches. Just 6 hours of hands-on labs, real tooling, and skills you can apply immediately — with a Certificate of Completion issued at the end.

Attend in-person in SF (1769 15th St) or join live online — both formats receive full access and recordings afterwards.

Led by Bogdan Red — one of the top cybersecurity experts in the San Francisco Bay Area, IEEE-published author on AI in cybersecurity, CVE researcher, CryEye creator, and speaker at RSA, DEF CON, and Black Hat — in collaboration with Threatbreaker and AI Start Academy SF.


Who This Is For

Security engineers, pentesters, AppSec practitioners, DevSecOps engineers, and technical founders who want to put AI to work in real security wocrkflows — not in theory.

You should be comfortable with CLI and have some prior exposure to security tooling. This is not for beginners.


The Certificate Difference

Most RSAC side events offer networking and panels. This one issues a verified Certificate of Completion from AI Start Academy SF — documenting 6 hours of hands-on, lab-based training in AI-driven cybersecurity, penetration testing, SAST/DAST, and security automation.

Something to show. Something that lasts past the conference.


Curriculum

Evening 1 — AI Meets Offense: CVEs, Threat Modeling & SAST
6:00 PM – 9:00 PM · SF Mission District + Live Online

6:00 – 6:30 PM | RSAC Debrief: AI in Security — Hype vs. What's Actually Dangerous

Everyone just left the conference floor. This session cuts through it.

→ AI-native security products that actually matter from RSA 2025 — and the ones that don't → LLM-powered attack tooling: what red teams are quietly building right now → Agentic AI in offense — autonomous recon, analysis, and exploitation chains → AI supply chain threats and model poisoning vectors defenders aren't ready for → Where defenders are winning — and the gaps that are widening

You leave with a clear mental model of where AI is being deployed offensively and defensively — before it shows up in your environment.


6:30 – 7:30 PM | CVE Deep Dive: 2024–2025 Critical Vulnerabilities + AI-Accelerated Analysis

The most exploited vulnerabilities from the past 12 months — dissected for root cause patterns, exploitation logic, and detection.

Featured CVEs:

  • CVE-2024-3400 · CRITICAL · PAN-OS GlobalProtect — command injection via crafted cookie

  • CVE-2024-21762 · CRITICAL · Fortinet FortiOS SSL-VPN — out-of-bounds write, RCE

  • CVE-2025-0282 · CRITICAL · Ivanti Connect Secure — stack overflow zero-day, in the wild

  • CVE-2024-47575 · CRITICAL · Fortinet FortiManager — missing auth in fgfmd daemon (SuperBlast)

  • CVE-2024-38094 · HIGH · Microsoft SharePoint — RCE via malicious site deserialization

For each: root cause pattern → patch diff logic → exploitation prerequisites → detection signatures and IOCs

Lab: Structured CVE analysis using AI to accelerate patch diffing, map exploitation chains, and produce Sigma detection rules — the same workflow practitioners use on day one of a real engagement.

Tools: NVD NIST, Shodan, GitHub PoC, Claude GPT-4o, Sigma Rules, MITRE ATT&CK


7:30 – 7:40 PM | Break


7:40 – 9:00 PM | SAST Deep Dive: Find What Scanners Miss

The session other workshops skip because it requires actual code fluency.

→ Taint analysis, data flow, and control flow — how SAST actually works under the hood → Logic flaws and business logic vulnerabilities automated tools are blind to → Insecure deserialization, injection, broken auth — pattern recognition at speed → AI-assisted code review: where LLMs genuinely accelerate and where they confidently lie → Building custom Semgrep / CodeQL rules tuned for your actual targets

Lab: Analyze intentionally vulnerable code across Python, JS, and Go. Find the logic flaws automated scanners miss. Write the detection rules. Document findings in structured report format.

Tools: Semgrep, CodeQL, Snyk Code, CryEye SAST, Claude


Evening 2 — Modern Pentesting & Automated Security Ops 6:00 PM – 9:00 PM · SF Mission District + Live Online


6:00 – 7:15 PM | AI-Augmented Recon + Modern Pentesting Toolkit

What the 2025 red team toolkit actually looks like — not the conference slide version.

→ AI-powered OSINT and automated asset discovery pipelines → Nuclei custom templates — building vulnerability checks tailored to your targets → Caido vs Burp — why the proxy landscape is shifting and what it means for your workflow → AI payload generation for fuzzing and injection testing — adaptive wordlists at scale → DAST in practice: black-box vs grey-box, JWT/OAuth auth testing, GraphQL and gRPC attack surfaces → BOLA/IDOR at scale — the authorization flaw class that keeps winning

Lab: Build an AI-assisted recon pipeline from scratch — passive recon, asset enumeration, custom Nuclei templates fired against a target environment, chained into a full attack path. Then pivot directly into an API Security Assessment: attack a deliberately vulnerable API, hunt BOLA/BFLA issues, inject AI-generated fuzzing payloads, document findings in structured report format.

Tools: Nuclei, Caido, Burp Suite, Subfinder, FFUF, Amass, Shodan, httpx, jwt_tool, CryEye DAST, Claude API


7:15 – 7:25 PM | Break


7:25 – 8:15 PM | Automated Security Pipelines + AI in Security Ops

The session that separates practitioners from people who just run tools.

→ Building automated pentest pipelines with CI/CD security gates → AI agents for continuous security testing and monitoring → SIEM + AI: enrichment, correlation, and triage at scale — what's real and what's vendor fiction → Alert fatigue: how AI is actually solving it, and the cases where it's making it worse → From alert to root cause — AI-accelerated investigation chains that cut response time

Lab: Design a full automated security testing and response pipeline — select tooling, define triggers, build AI-enrichment steps, present findings to the group.

Tools: GitHub Actions, Nuclei CI, Wazuh, Elastic SIEM, n8n, Ollama


8:15 – 9:00 PM | Capstone + Certificate Ceremony

Teams work against a combined target environment — applying CVE knowledge, AI tools, DAST/SAST, and automation skills from both evenings to produce a prioritized findings report with remediation recommendations. Then present to the group.

→ Live capstone assessment on combined target → Group debrief and findings discussion → Open Q&A with Bogdan → Tool and resource pack distributed → Certificate of Completion issued to all participants → AI Start Academy SF community networking

You walk away with: Certificate of Completion, resource pack, custom tool configs, and a repeatable AI-augmented assessment methodology ready for real engagements.


Your Instructor

Bogdan Red — Founder & CEO, CQR Company

One of the most recognized cybersecurity practitioners in the San Francisco Bay Area. 20 years in offensive security. Published author in IEEE on cybersecurity and AI applications. Creator of CryEye, an enterprise cybersecurity platform used across Fortune 500 environments. 500+ security professionals trained. CVE researcher. Speaker at RSA, DEF CON, and Black Hat.

Built this specifically around what's happening in the threat landscape right now.


Format & Logistics

📅 2 evenings | 6:00 PM – 9:00 PM each night
📍 In-person: San Francisco Mission District — 1769 15th St, SF 94103
🚇 5-minute walk from BART 16th Street Station
💻 Online: live stream available for remote attendees
🎥 Full recordings provided to all registered participants after each session
🖥️ Bring your laptop (8GB+ RAM recommended, CLI-comfortable)

Includes: lab (hands-on) environment, CryEye platform access, 7-day post-workshop Q&A, session recordings, and your Certificate of Completion.


Presented By

AI Start Academy × Threatbreaker


Limited seats. Two evenings. One certificate. In-person or online.

Location
Ai Start Academy ©
1769 15th St, San Francisco, CA 94103, USA
Avatar for AI Start Academy
Presented by
AI Start Academy
Hosted By