Cover Image for Agents & Exploits: Hacking OWASP VWAD
Cover Image for Agents & Exploits: Hacking OWASP VWAD
Avatar for OWASP x DEFCON 34
Presented by
OWASP x DEFCON 34
1 Going
Registration
Welcome! To join the event, please register below.
About Event

Large language models have rapidly evolved from chat interfaces into autonomous agents capable of interacting with real-world systems. In this hands-on workshop, participants will build an AI-powered security agent from the ground up and learn the core principles behind agentic penetration testing using intentionally vulnerable OWASP applications.

Rather than simply prompting an LLM, attendees will explore how to equip an agent with practical capabilities - including shell access, browser access, and orchestration to discover, exploit, and document vulnerabilities in one of the listed vulnerable applications in the OWASP Vulnerable Web Application Directory (VWAD). Along the way, we'll discuss the architecture of effective security agents, tool integration, memory, and safe execution practices.

The workshop also introduces an iterative evaluation workflow. Participants will analyze vulnerabilities the agent failed to identify, compare results against known findings, and use those gaps to refine prompts, tool selection, workflows, and evaluation criteria. This iterative approach demonstrates how modern AI security agents can continuously improve their effectiveness through systematic testing and feedback rather than relying on a single execution.

By the end of the session, attendees will have built a functional AI security agent, understand the fundamentals of agent tooling and orchestration, and leave with practical techniques for evaluating and improving AI-assisted security testing applications.

Location
Las Vegas Convention Center
3150 Paradise Rd, Las Vegas, NV 89109, USA
W4 / 1415 / Level 1
Avatar for OWASP x DEFCON 34
Presented by
OWASP x DEFCON 34
1 Going