AI Augmented Operator
Description
Name of Training: AI Augmented Operator
Trainer(s): Robert Shala, Armend Gashi, Redon Gashi
Dates: November 08-10, 2026
Time: 9:00 am - 5:00 pm
Venue: Exhibition World Bahrain
Cost: 1200 BHD
1. Short Summary
AI Augmented Operator teaches security practitioners how to build and deploy reliable AI agents for real cybersecurity operations. Students leave with hands-on experience using AI to augment offensive, defensive, and intelligence operations.
2. Full Course Description
AI Augmented Operator is a hands-on course for security practitioners who want to move beyond AI hype and use these systems as a real force multiplier in operator workflows. You will learn how to design, build, and evaluate AI agents that can assist with offense, defense, and intelligence!
AI is changing security operations, but turning it into something useful, reliable, and safe is still hard. AI Augmented Operator gives you a clear path: first, you will learn how modern AI systems and agent architectures actually work, including tools, retrieval, memory, alloys, evaluation, and failure modes. Across two days of guided training and one capstone project day, you will build and harden your own high-performance AI-augmented system for offense, defense, or intelligence operations, so you leave with practical skills and a project you can adapt to real security work.
3. Course Outline
Day 1
3.1 Morning: AI and Agent Foundations
Students begin with the core mechanics needed to build AI-augmented security systems: how language models work, what next-token prediction means in practice, why models hallucinate, and where AI is reliable or unreliable in operator workflows.
The session covers tokenization, context windows, embeddings, retrieval, prompt structure, and model/tool boundaries.
Estimated timing: 35 minutes on model fundamentals, 35 minutes on tokenization and context design, 35 minutes on embeddings/RAG, 35 minutes on reliability and hallucination controls, 50 minutes for a guided lab, and 20 minutes for breaks/checkpoints.
Topics include:
3.1.1 How language models actually work
3.1.2 Next-token prediction and the mechanics behind AI behavior
3.1.3 Where models are strong, where they fail, and how to design around it
3.1.4 Hallucinations, uncertainty, and reliability controls
3.1.5 Tokenization, context windows, and prompt structure
3.1.6 Embeddings, semantic search, and retrieval-augmented generation
3.1.7 Model/tool boundaries: when to ask the model and when to call a tool
3.1.8 Guided lab: build a first working security assistant
3.2 Agent Architecture and Hardening
Students move from “using a model” to designing an agent. This block covers agent loops, tool use/function calling, memory, retrieval pipelines, planning patterns, structured outputs, and human-in-the-loop checkpoints. Students then learn how to harden agents against prompt injection, unsafe tool use, bad outputs, and trust-boundary failures.
Estimated timing: 40 minutes on agent architecture, 35 minutes on tool use and function calling, 35 minutes on RAG/memory design, 40 minutes on agent security and guardrails, 40 minutes for a hardening lab, and 20 minutes for breaks/checkpoints.
Topics include:
3.2.1 How agent loops work
3.2.2 Tool use, function calling, and structured outputs
3.2.3 Memory, retrieval pipelines, and context management
3.2.4 Planning patterns for multi-step security tasks
3.2.5 Human-in-the-loop checkpoints and approval gates
3.2.6 Prompt injection and indirect prompt injection
3.2.7 Trust boundaries between model, tools, data, and user input
3.2.8 Output validation, guardrails, and safe execution patterns
3.2.9 Guided lab: harden a working security agent
Day 2
3.3 Applied Security Workflows
Students apply agent patterns to real security workflows across intelligence and defense. Topics include OSINT collection, IOC extraction and correlation, threat intelligence summarization, alert triage, log analysis, investigation workflows, and SIEM/detection stack integration. The flavor is defensive in the morning.
Estimated timing: 40 minutes on threat intelligence agents, 35 minutes on IOC extraction/correlation, 40 minutes on SOC triage and log analysis, 30 minutes on SIEM/detection integration patterns, 45 minutes for a guided applied lab, and 20 minutes for breaks/checkpoints.
Topics include:
3.3.1 AI agents for threat intelligence workflows
3.3.2 OSINT collection and enrichment
3.3.3 IOC extraction, normalization, and correlation
3.3.4 Threat report summarization and analyst-ready outputs
3.3.5 SOC alert triage and prioritization
3.3.6 Log analysis and investigation workflows
3.3.7 SIEM and detection stack integration patterns
3.3.8 Keeping analysts in control of defensive automation
3.3.9 Guided lab: build an applied intelligence or triage workflow
3.4 Offensive, Research, and Operations
Students examine AI augmentation for offensive security and vulnerability research in a controlled lab context. Topics include recon automation, vulnerability research support, exploit-chain reasoning, code review agents, patch diffing, and responsible boundaries for offensive agent use. The day closes with operational concerns: evaluation, observability, cost, drift, governance, and preparing for the capstone.
Estimated timing: 40 minutes on offensive workflow augmentation, 35 minutes on vulnerability research/code review agents, 35 minutes on evaluation and observability, 30 minutes on governance and human-in-the-loop design, 50 minutes for capstone planning/project scoping, and 20 minutes for breaks/checkpoints.
Topics include:
3.4.1 AI agents for offensive security workflows
3.4.2 Recon automation and target understanding
3.4.3 Vulnerability research support
3.4.4 Exploit-chain reasoning in controlled lab environments
3.4.5 Code review agents for security findings
3.4.6 Patch diffing and CVE research workflows
3.4.7 Responsible boundaries for offensive agent use
3.4.8 Evaluation, observability, and failure analysis
3.4.9 Cost, latency, drift, and operational readiness
3.4.10 Capstone planning: choose offense, defense, or intelligence track
Day 3
3.5 Capstone Project Build
Students choose a capstone track: defense, offense, or intelligence. Working with instructors, they define a realistic security problem, scope a buildable agent system, identify required tools/data, set success criteria, and begin implementation. Each project must include a working agent loop, tool use or retrieval, structured output, and basic safety controls.
Estimated timing: 35 minutes for project selection and scoping, 35 minutes for architecture review with instructors, 120 minutes for the first build sprint, and 20 minutes for breaks/checkpoints.
Topics include:
3.5.1 Choose a capstone track: defense, offense, or intelligence
3.5.2 Define a realistic security problem to solve
3.5.3 Scope an agent system that can be built and demonstrated
3.5.4 Identify required tools, data sources, and APIs
3.5.5 Set clear success criteria and evaluation goals
3.5.6 Design the agent loop and system architecture
3.5.7 Add tool use, retrieval, or structured data processing
3.5.8 Build safety controls and human approval points
3.5.9 Begin implementation with instructor support
3.6 Capstone Completion and Review
Students continue building their capstone systems with instructor support, then test, evaluate, and prepare a short operational brief. Each student or team demonstrates a working AI-augmented security system and explains what it does, how it was tested, where human review is required, and how it could be adapted to a real environment.
Estimated timing: 120 minutes for final build sprint, 20 minutes for preparing the operational brief/demo, 50 minutes for demonstrations and peer review, and 20 minutes for breaks/checkpoints.
Topics include:
3.6.1 Continue capstone implementation with instructor support
3.6.2 Test the agent against realistic security inputs
3.6.3 Evaluate accuracy, reliability, and failure modes
3.6.4 Verify tool use, retrieval, structured output, and safety controls
3.6.5 Prepare a short operational brief and demo narrative
3.6.6 Explain what the system does and where human review is required
3.6.7 Demonstrate a working AI-augmented security system
3.6.8 Receive peer review and instructor feedback
3.6.9 Discuss how the system could be adapted to real-world operations
4. Difficulty Level
Beginner - The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.
Intermediate - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.
5. Suggested Prerequisites
Students should be comfortable with basic cybersecurity concepts and workflows. They do not need prior AI or machine learning experience. The course starts by explaining how LLMs and agents work and provides a strong foundation with which to work on.
Students should be able to read and write basic Python scripts, use the command line, install packages, work with JSON/CSV/text data, and make HTTP/API requests. The course will use Python for agent logic, tool calling, data parsing, retrieval, and automation. Students should be comfortable using a code editor, terminal, Git, and Python virtual environments.
Students should be comfortable with basic cybersecurity concepts and workflows. They do not need prior AI or machine learning experience. The course starts by explaining how LLMs and agents work and provides a strong foundation with which to work on.
Students should be able to read and write basic Python scripts, use the command line, install packages, work with JSON/CSV/text data, and make HTTP/API requests. The course will use Python for agent logic, tool calling, data parsing, retrieval, and automation. Students should be comfortable using a code editor, terminal, Git, and Python virtual environments.
6. What Students Should Bring
Students should arrive with a laptop capable of running Python 3, Git, Docker or a similar local lab environment, and a modern code editor such as VS Code.
7. What the Trainer Will Provide
During the training, students will be provided with:
- LLM API access will be provided by the instructors. Students will have access to an LLM API key before class.
8. Trainer(s) Bio
Robert Shala
Robert Shala is co-founder of Sentry, where he leads 50 security consultants and has delivered 3000-plus security engagements for some of the world largest organizatons. He was also part of OpenAI's External AI Red Team probing frontier models for safety and security flaws. He has presented at DEF CON AI Village and AppSec Village on novel attack classes targeting AI inference infrastructure. Robert holds an M.S. in Security Studies from Georgetown University, a B.S. from Rochester Institute of Technology, and has a passion for wargaming.
Armend Gashi
Armend Gashi is a Managing Security Consultant at Sentry. He specializes in AI and multi-agent systems engineering. Armend has built multi-agent systems to perform security-focused operations in vulnerability research and exploit development as well as model steering and technical alignment. Armend was part of of Anthropic’s external AI Red Team through HackerOne. He has presented at DEF CON AI Village and AppSec Village on Special Token Injection.
9. Registration Terms and Conditions
9.1 Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.
9.2 Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.
9.3 All trainings are non-refundable after October 21, 2026.
9.4 Training tickets may be transferred to another student. Please email us at training@defcon.org for specifics.
9.5 If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).
9.6 Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.
9.7 DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.
9.8 By purchasing this ticket you agree to abide by the DEF CON Training Code of Conduct and the registration terms and conditions listed above.