Autonomous AI Agents for Zero-False-Positive Offensive Security
Black Hat
video
2026-04-05T00:00:00
Abstract
This talk explores the frontier of AI-driven offensive security, focusing on the architecture of Xbow, an autonomous pentesting platform. It demonstrates how AI "solvers" can be orchestrated by a central "coordinator" to perform complex, multi-step vulnerability research—such as identifying XXE via out-of-band (OOB) interactions and executing complex account takeover (ATO) chains—with near-zero false positives. Key takeaways include the mechanics of AI reasoning in pentesting, the integration of OOB interaction servers for validation, and the technical nuances of chaining API downgrades, JSONP, and XSS.
Loading executive summary...
Loading full markdown...
Match Rate:
10.00/10
(Relevance to core cybersecurity goals)