

Supercharging Your Pentesting With AI
Instructor
Lucas Romano is the Manager of Security Operations at Cequence where he leads the SOC and also is a Security Researcher for the Synack Red Team. He's worked in every role from threat intelligence at the National Security Agency to naval cryptology to being the founding offensive security engineer of an agentic penetration testing company. He's passionate about teaching fellow practitioners the secrets of the trade and growing everyone to a higher level.
Career highlights
Manager of the Security Operations Center at Cequence
Founding Offensive Security Engineer at Casco
Lead Threat Intelligent Analyst at National Security Agency
Who this workshop is for
Penetration testers, bug bounty hunters, offensive/application security engineers, and security researchers looking to intertwine AI into their daily workflow
SOC analysts, threat researchers, and software engineers looking to understand in-depth and test the tools that will be employed against their systems
Technical managers wanting to stay sharp in this quickly evolving topic
Prerequisites
Knowledge and experience performing security testing; you don't need to be a full-time penetration tester but you need to understand vulnerability classes like the OWASP top 10 and how to exploit them
Prior fundamental knowledge and use of AI tools, you don't need to be a pro but you'll be expected to know what a context window and token are
A desire to learn and grow - this is the most important one!
What's included
Live hands-on teaching with an instructor who's put this theory into practice at the enterprise level
Custom made labs fully configured for the course, no need to bring your own tools
AI access for the duration of the course and labs to supercharge your learning
Closing live Q&A with the instructor
Recording included: a full session recording for everyone who registers
Certificate of participation with CEP Credits
What makes this workshop different
Instruction from a real offensive security engineer who's built agentic pentesting at scale, not a theoretical lesson
All needed tools provided to you, no need to bring your own API key or budget for a new subscription
Lab access for one week, not just for the duration of the live course
Optional CTF to put what you just learned truly into practice, with a special prize for the winner(s)
What you'll learn
It only takes one vulnerability to destroy a company's reputation; In the modern world this is exemplified by the fact that one hacker can replicate their skills 100x and launch more attacks faster than ever before. We need to fight fire with fire, and ensure all of ours engineers, especially those testing security, 100x their skills as well.
That's the goal of this workshop, to teach you how to 100x your work. Long gone are the days of manually fuzzing a web application, configuring Burp Suite's intruder with a list of payloads, trying to read every request and response headers, naming your repeater tabs. etc. The fruit is ready to be harvested fast by an AI model with the proper resources, but do you know how to give it them? This is what you'll learn, how to arm AI with everything it needs to do in 2 hours what previously took a human 20. Some skills you'll learn are:
Real world examples of AI used in major attacks
The importance of tool access for an AI model, and how to provide tools to them
How to make and use a harness
Bypassing guardrails and bulletproofing your prompts
Troubleshooting and overcoming issues like rate-limits and account lockouts
The importance of AI in the modern security world through hands-on labs and an intense but very fun CTF