Cover Image for Supercharging Your Pentesting With AI
Cover Image for Supercharging Your Pentesting With AI
Avatar for TryHackMe
Presented by
TryHackMe
Hosted By

Supercharging Your Pentesting With AI

Zoom
Get Tickets
Past Event
Welcome! Please choose your desired ticket type:
About Event

​Instructor

​

​Lucas Romano is the Manager of Security Operations at Cequence where he leads the SOC and also is a Security Researcher for the Synack Red Team. He's worked in every role from threat intelligence at the National Security Agency to naval cryptology to being the founding offensive security engineer of an agentic penetration testing company. He's passionate about teaching fellow practitioners the secrets of the trade and growing everyone to a higher level.

​

​"I've been doing offensive security work for nearly 6 years, and have found more vulnerabilities in the past year with agentic workflows than I have the prior 5 combined."" - Lucas

​

​Career highlights

  • ​Manager of the Security Operations Center at Cequence

  • ​Founding Offensive Security Engineer at Casco

  • ​Lead Threat Intelligence Analyst at National Security Agency

​Who this workshop is for

  • ​Penetration testers, bug bounty hunters, offensive/application security engineers, and security researchers looking to intertwine AI into their daily workflow

  • ​SOC analysts, threat researchers, and software engineers looking to understand in-depth and test the tools that will be employed against their systems

  • ​Technical managers wanting to stay sharp in this quickly evolving topic

​Prerequisites

  • ​Knowledge and experience performing security testing; you don't need to be a full-time penetration tester but you need to understand vulnerability classes like the OWASP top 10 and how to exploit them

  • ​Prior fundamental knowledge and use of AI tools, you don't need to be a pro but you'll be expected to know what a context window and token are

  • ​A desire to learn and grow - this is the most important one!

​What's included

​"You're getting knowledge and tooling to prevent burning through tokens like I have; no more wasted money on bad runs" - Lucas

​

  • ​Live hands-on teaching with an instructor who's put this theory into practice at the enterprise level

  • ​Custom made labs fully configured for the course, no need to bring your own tools

  • ​AI access for the duration of the course and labs to supercharge your learning

  • ​Closing live Q&A with the instructor

  • ​Recording included: a full session recording for everyone who registers

  • ​Certificate of participation with CPE Credits

​What makes this workshop different

  • ​Instruction from a real offensive security engineer who's built agentic pentesting at scale, not a theoretical lesson

  • ​All needed tools provided to you, no need to bring your own API key or budget for a new subscription

  • ​Lab access for one week, not just for the duration of the live course

  • ​Optional CTF to put what you just learned truly into practice, with a winners prize if 1hr personal coaching, custom challenge coin and a THM certification voucher

​What you'll learn

​It only takes one vulnerability to destroy a company's reputation; In the modern world this is exemplified by the fact that one hacker can replicate their skills 100x and launch more attacks faster than ever before. We need to fight fire with fire, and ensure all of our engineers, especially those testing security, 100x their skills as well.

​That's the goal of this workshop, to teach you how to 100x your work. Long gone are the days of manually fuzzing a web application, configuring Burp Suite's Intruder with a list of payloads, trying to read every request and response headers, naming your Repeater tabs. etc. The fruit is ready to be harvested fast by an AI model with the proper resources, but do you know how to give it to them? This is what you'll learn, how to arm AI with everything it needs to do in 2 hours what previously took a human 20. Some skills you'll learn are:

  • ​Real world examples of AI used in major attacks

  • ​The importance of tool access for an AI model, and how to provide tools to them

  • ​How to make and use a harness

  • ​Bypassing guardrails and bulletproofing your prompts

  • ​Troubleshooting and overcoming issues like rate-limits and account lockouts

  • ​The importance of AI in the modern security world through hands-on labs and an intense but very fun CTF

Avatar for TryHackMe
Presented by
TryHackMe
Hosted By