{"product_id":"ai-augmented-operator","title":"AI Augmented Operator","description":"\u003cp\u003e\u003cstrong\u003eName of Training:\u003c\/strong\u003e AI Augmented Operator\u003cbr\u003e\u003cstrong\u003eTrainer(s):\u003c\/strong\u003e Robert Shala, Armend Gashi, Redon Gashi\u003cbr\u003e\u003cstrong\u003eDates:\u003c\/strong\u003e November 08-10, 2026\u003cbr\u003e\u003cstrong\u003eTime:\u003c\/strong\u003e 9:00 am - 5:00 pm\u003cbr\u003e\u003cstrong\u003eVenue:\u003c\/strong\u003e Exhibition World Bahrain\u003cbr\u003e\u003cstrong\u003eCost:\u003c\/strong\u003e 1200 BHD\u003c\/p\u003e\n\u003ch2\u003e1. Short Summary\u003c\/h2\u003e\n\u003cp\u003eAI Augmented Operator teaches security practitioners how to build and deploy reliable AI agents for real cybersecurity operations. Students leave with hands-on experience using AI to augment offensive, defensive, and intelligence operations.\u003c\/p\u003e\n\u003ch2\u003e2. Full Course Description\u003c\/h2\u003e\n\u003cp\u003eAI Augmented Operator is a hands-on course for security practitioners who want to move beyond AI hype and use these systems as a real force multiplier in operator workflows. You will learn how to design, build, and evaluate AI agents that can assist with offense, defense, and intelligence!\u003c\/p\u003e\n\u003cp\u003eAI is changing security operations, but turning it into something useful, reliable, and safe is still hard. AI Augmented Operator gives you a clear path: first, you will learn how modern AI systems and agent architectures actually work, including tools, retrieval, memory, alloys, evaluation, and failure modes. Across two days of guided training and one capstone project day, you will build and harden your own high-performance AI-augmented system for offense, defense, or intelligence operations, so you leave with practical skills and a project you can adapt to real security work.\u003c\/p\u003e\n\u003ch2\u003e3. Course Outline\u003c\/h2\u003e\n\u003ch3\u003eDay 1\u003c\/h3\u003e\n\u003ch3\u003e3.1 Morning: AI and Agent Foundations\u003c\/h3\u003e\n\u003cp\u003eStudents begin with the core mechanics needed to build AI-augmented security systems: how language models work, what next-token prediction means in practice, why models hallucinate, and where AI is reliable or unreliable in operator workflows.\u003c\/p\u003e\n\u003cp\u003eThe session covers tokenization, context windows, embeddings, retrieval, prompt structure, and model\/tool boundaries.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eEstimated timing:\u003c\/strong\u003e 35 minutes on model fundamentals, 35 minutes on tokenization and context design, 35 minutes on embeddings\/RAG, 35 minutes on reliability and hallucination controls, 50 minutes for a guided lab, and 20 minutes for breaks\/checkpoints.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTopics include:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.1.1\u003c\/strong\u003e How language models actually work\u003cbr\u003e\u003cstrong\u003e3.1.2\u003c\/strong\u003e Next-token prediction and the mechanics behind AI behavior\u003cbr\u003e\u003cstrong\u003e3.1.3\u003c\/strong\u003e Where models are strong, where they fail, and how to design around it\u003cbr\u003e\u003cstrong\u003e3.1.4\u003c\/strong\u003e Hallucinations, uncertainty, and reliability controls\u003cbr\u003e\u003cstrong\u003e3.1.5\u003c\/strong\u003e Tokenization, context windows, and prompt structure\u003cbr\u003e\u003cstrong\u003e3.1.6\u003c\/strong\u003e Embeddings, semantic search, and retrieval-augmented generation\u003cbr\u003e\u003cstrong\u003e3.1.7\u003c\/strong\u003e Model\/tool boundaries: when to ask the model and when to call a tool\u003cbr\u003e\u003cstrong\u003e3.1.8 Guided lab:\u003c\/strong\u003e build a first working security assistant\u003c\/p\u003e\n\u003ch3\u003e3.2 Agent Architecture and Hardening\u003c\/h3\u003e\n\u003cp\u003eStudents move from “using a model” to designing an agent. This block covers agent loops, tool use\/function calling, memory, retrieval pipelines, planning patterns, structured outputs, and human-in-the-loop checkpoints. Students then learn how to harden agents against prompt injection, unsafe tool use, bad outputs, and trust-boundary failures.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eEstimated timing:\u003c\/strong\u003e 40 minutes on agent architecture, 35 minutes on tool use and function calling, 35 minutes on RAG\/memory design, 40 minutes on agent security and guardrails, 40 minutes for a hardening lab, and 20 minutes for breaks\/checkpoints.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTopics include:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.2.1\u003c\/strong\u003e How agent loops work\u003cbr\u003e\u003cstrong\u003e3.2.2\u003c\/strong\u003e Tool use, function calling, and structured outputs\u003cbr\u003e\u003cstrong\u003e3.2.3\u003c\/strong\u003e Memory, retrieval pipelines, and context management\u003cbr\u003e\u003cstrong\u003e3.2.4\u003c\/strong\u003e Planning patterns for multi-step security tasks\u003cbr\u003e\u003cstrong\u003e3.2.5\u003c\/strong\u003e Human-in-the-loop checkpoints and approval gates\u003cbr\u003e\u003cstrong\u003e3.2.6\u003c\/strong\u003e Prompt injection and indirect prompt injection\u003cbr\u003e\u003cstrong\u003e3.2.7\u003c\/strong\u003e Trust boundaries between model, tools, data, and user input\u003cbr\u003e\u003cstrong\u003e3.2.8\u003c\/strong\u003e Output validation, guardrails, and safe execution patterns\u003cbr\u003e\u003cstrong\u003e3.2.9 Guided lab:\u003c\/strong\u003e harden a working security agent\u003c\/p\u003e\n\u003ch3\u003eDay 2\u003c\/h3\u003e\n\u003ch3\u003e3.3 Applied Security Workflows\u003c\/h3\u003e\n\u003cp\u003eStudents apply agent patterns to real security workflows across intelligence and defense. Topics include OSINT collection, IOC extraction and correlation, threat intelligence summarization, alert triage, log analysis, investigation workflows, and SIEM\/detection stack integration. The flavor is defensive in the morning.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eEstimated timing:\u003c\/strong\u003e 40 minutes on threat intelligence agents, 35 minutes on IOC extraction\/correlation, 40 minutes on SOC triage and log analysis, 30 minutes on SIEM\/detection integration patterns, 45 minutes for a guided applied lab, and 20 minutes for breaks\/checkpoints.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTopics include:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.3.1\u003c\/strong\u003e AI agents for threat intelligence workflows\u003cbr\u003e\u003cstrong\u003e3.3.2\u003c\/strong\u003e OSINT collection and enrichment\u003cbr\u003e\u003cstrong\u003e3.3.3\u003c\/strong\u003e IOC extraction, normalization, and correlation\u003cbr\u003e\u003cstrong\u003e3.3.4\u003c\/strong\u003e Threat report summarization and analyst-ready outputs\u003cbr\u003e\u003cstrong\u003e3.3.5\u003c\/strong\u003e SOC alert triage and prioritization\u003cbr\u003e\u003cstrong\u003e3.3.6\u003c\/strong\u003e Log analysis and investigation workflows\u003cbr\u003e\u003cstrong\u003e3.3.7\u003c\/strong\u003e SIEM and detection stack integration patterns\u003cbr\u003e\u003cstrong\u003e3.3.8\u003c\/strong\u003e Keeping analysts in control of defensive automation\u003cbr\u003e\u003cstrong\u003e3.3.9 Guided lab:\u003c\/strong\u003e build an applied intelligence or triage workflow\u003c\/p\u003e\n\u003ch3\u003e3.4 Offensive, Research, and Operations\u003c\/h3\u003e\n\u003cp\u003eStudents examine AI augmentation for offensive security and vulnerability research in a controlled lab context. Topics include recon automation, vulnerability research support, exploit-chain reasoning, code review agents, patch diffing, and responsible boundaries for offensive agent use. The day closes with operational concerns: evaluation, observability, cost, drift, governance, and preparing for the capstone.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eEstimated timing:\u003c\/strong\u003e 40 minutes on offensive workflow augmentation, 35 minutes on vulnerability research\/code review agents, 35 minutes on evaluation and observability, 30 minutes on governance and human-in-the-loop design, 50 minutes for capstone planning\/project scoping, and 20 minutes for breaks\/checkpoints.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTopics include:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.4.1\u003c\/strong\u003e AI agents for offensive security workflows\u003cbr\u003e\u003cstrong\u003e3.4.2\u003c\/strong\u003e Recon automation and target understanding\u003cbr\u003e\u003cstrong\u003e3.4.3\u003c\/strong\u003e Vulnerability research support\u003cbr\u003e\u003cstrong\u003e3.4.4\u003c\/strong\u003e Exploit-chain reasoning in controlled lab environments\u003cbr\u003e\u003cstrong\u003e3.4.5\u003c\/strong\u003e Code review agents for security findings\u003cbr\u003e\u003cstrong\u003e3.4.6\u003c\/strong\u003e Patch diffing and CVE research workflows\u003cbr\u003e\u003cstrong\u003e3.4.7\u003c\/strong\u003e Responsible boundaries for offensive agent use\u003cbr\u003e\u003cstrong\u003e3.4.8\u003c\/strong\u003e Evaluation, observability, and failure analysis\u003cbr\u003e\u003cstrong\u003e3.4.9\u003c\/strong\u003e Cost, latency, drift, and operational readiness\u003cbr\u003e\u003cstrong\u003e3.4.10\u003c\/strong\u003e Capstone planning: choose offense, defense, or intelligence track\u003c\/p\u003e\n\u003ch3\u003eDay 3\u003c\/h3\u003e\n\u003ch3\u003e3.5 Capstone Project Build\u003c\/h3\u003e\n\u003cp\u003eStudents choose a capstone track: defense, offense, or intelligence. Working with instructors, they define a realistic security problem, scope a buildable agent system, identify required tools\/data, set success criteria, and begin implementation. Each project must include a working agent loop, tool use or retrieval, structured output, and basic safety controls.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eEstimated timing:\u003c\/strong\u003e 35 minutes for project selection and scoping, 35 minutes for architecture review with instructors, 120 minutes for the first build sprint, and 20 minutes for breaks\/checkpoints.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTopics include:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.5.1\u003c\/strong\u003e Choose a capstone track: defense, offense, or intelligence\u003cbr\u003e\u003cstrong\u003e3.5.2\u003c\/strong\u003e Define a realistic security problem to solve\u003cbr\u003e\u003cstrong\u003e3.5.3\u003c\/strong\u003e Scope an agent system that can be built and demonstrated\u003cbr\u003e\u003cstrong\u003e3.5.4\u003c\/strong\u003e Identify required tools, data sources, and APIs\u003cbr\u003e\u003cstrong\u003e3.5.5\u003c\/strong\u003e Set clear success criteria and evaluation goals\u003cbr\u003e\u003cstrong\u003e3.5.6\u003c\/strong\u003e Design the agent loop and system architecture\u003cbr\u003e\u003cstrong\u003e3.5.7\u003c\/strong\u003e Add tool use, retrieval, or structured data processing\u003cbr\u003e\u003cstrong\u003e3.5.8\u003c\/strong\u003e Build safety controls and human approval points\u003cbr\u003e\u003cstrong\u003e3.5.9\u003c\/strong\u003e Begin implementation with instructor support\u003c\/p\u003e\n\u003ch3\u003e3.6 Capstone Completion and Review\u003c\/h3\u003e\n\u003cp\u003eStudents continue building their capstone systems with instructor support, then test, evaluate, and prepare a short operational brief. Each student or team demonstrates a working AI-augmented security system and explains what it does, how it was tested, where human review is required, and how it could be adapted to a real environment.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eEstimated timing:\u003c\/strong\u003e 120 minutes for final build sprint, 20 minutes for preparing the operational brief\/demo, 50 minutes for demonstrations and peer review, and 20 minutes for breaks\/checkpoints.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eTopics include:\u003c\/strong\u003e\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e3.6.1\u003c\/strong\u003e Continue capstone implementation with instructor support\u003cbr\u003e\u003cstrong\u003e3.6.2\u003c\/strong\u003e Test the agent against realistic security inputs\u003cbr\u003e\u003cstrong\u003e3.6.3\u003c\/strong\u003e Evaluate accuracy, reliability, and failure modes\u003cbr\u003e\u003cstrong\u003e3.6.4\u003c\/strong\u003e Verify tool use, retrieval, structured output, and safety controls\u003cbr\u003e\u003cstrong\u003e3.6.5\u003c\/strong\u003e Prepare a short operational brief and demo narrative\u003cbr\u003e\u003cstrong\u003e3.6.6\u003c\/strong\u003e Explain what the system does and where human review is required\u003cbr\u003e\u003cstrong\u003e3.6.7\u003c\/strong\u003e Demonstrate a working AI-augmented security system\u003cbr\u003e\u003cstrong\u003e3.6.8\u003c\/strong\u003e Receive peer review and instructor feedback\u003cbr\u003e\u003cstrong\u003e3.6.9\u003c\/strong\u003e Discuss how the system could be adapted to real-world operations\u003c\/p\u003e\n\u003ch2\u003e4. Difficulty Level\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBeginner\u003c\/strong\u003e - The student has an interest in the topic presented and general technology knowledge that a power user or undergraduate student may have acquired.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003eIntermediate\u003c\/strong\u003e - The student has education and some experience in the field and familiarity with the topic being presented. The student has foundational knowledge that the course will leverage to provide practical skills on the topic.\u003c\/p\u003e\n\u003ch2\u003e5. Suggested Prerequisites\u003c\/h2\u003e\n\u003cp\u003eStudents should be comfortable with basic cybersecurity concepts and workflows. They do not need prior AI or machine learning experience. The course starts by explaining how LLMs and agents work and provides a strong foundation with which to work on.\u003c\/p\u003e\n\u003cp\u003eStudents should be able to read and write basic Python scripts, use the command line, install packages, work with JSON\/CSV\/text data, and make HTTP\/API requests. The course will use Python for agent logic, tool calling, data parsing, retrieval, and automation. Students should be comfortable using a code editor, terminal, Git, and Python virtual environments.\u003c\/p\u003e\n\u003cp\u003eStudents should be comfortable with basic cybersecurity concepts and workflows. They do not need prior AI or machine learning experience. The course starts by explaining how LLMs and agents work and provides a strong foundation with which to work on.\u003c\/p\u003e\n\u003cp\u003eStudents should be able to read and write basic Python scripts, use the command line, install packages, work with JSON\/CSV\/text data, and make HTTP\/API requests. The course will use Python for agent logic, tool calling, data parsing, retrieval, and automation. Students should be comfortable using a code editor, terminal, Git, and Python virtual environments.\u003c\/p\u003e\n\u003ch2\u003e6. What Students Should Bring\u003c\/h2\u003e\n\u003cp\u003eStudents should arrive with a laptop capable of running Python 3, Git, Docker or a similar local lab environment, and a modern code editor such as VS Code.\u003c\/p\u003e\n\u003ch2\u003e7. What the Trainer Will Provide\u003c\/h2\u003e\n\u003cp\u003eDuring the training, students will be provided with:\u003c\/p\u003e\n\u003cul\u003e\n\u003cli\u003eLLM API access will be provided by the instructors. Students will have access to an LLM API key before class.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch2\u003e8. Trainer(s) Bio\u003c\/h2\u003e\n\u003ch3\u003eRobert Shala\u003c\/h3\u003e\n\u003cp\u003eRobert Shala is co-founder of Sentry, where he leads 50 security consultants and has delivered 3000-plus security engagements for some of the world largest organizatons. He was also part of OpenAI's External AI Red Team probing frontier models for safety and security flaws. He has presented at DEF CON AI Village and AppSec Village on novel attack classes targeting AI inference infrastructure. Robert holds an M.S. in Security Studies from Georgetown University, a B.S. from Rochester Institute of Technology, and has a passion for wargaming.\u003c\/p\u003e\n\u003ch3\u003eArmend Gashi\u003c\/h3\u003e\n\u003cp\u003eArmend Gashi is a Managing Security Consultant at Sentry. He specializes in AI and multi-agent systems engineering. Armend has built multi-agent systems to perform security-focused operations in vulnerability research and exploit development as well as model steering and technical alignment. Armend was part of of Anthropic’s external AI Red Team through HackerOne. He has presented at DEF CON AI Village and AppSec Village on Special Token Injection.\u003c\/p\u003e\n\u003ch2\u003e9. Registration Terms and Conditions\u003c\/h2\u003e\n\u003cp\u003e\u003cstrong\u003e9.1\u003c\/strong\u003e Trainings are refundable before September 21, 2026, minus a non-refundable processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.2\u003c\/strong\u003e Between September 21, 2026 and October 21, 2026 partial refunds will be granted, equal to 50% of the course fee minus a processing fee of 100 BHD.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.3\u003c\/strong\u003e All trainings are non-refundable after October 21, 2026.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.4\u003c\/strong\u003e Training tickets may be transferred to another student. Please email us at \u003ca href=\"mailto:training@defcon.org\"\u003etraining@defcon.org\u003c\/a\u003e for specifics.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.5\u003c\/strong\u003e If a training does not reach the minimum registration requirement, it may be cancelled. In the event the training you choose is cancelled, you will be provided the option of receiving a full refund or transferring to another training (subject to availability).\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.6\u003c\/strong\u003e Failure to attend the training without prior written notification will be considered a no-show. No refund will be given.\u003c\/p\u003e\n\u003cp\u003e\u003cstrong\u003e9.7\u003c\/strong\u003e DEF CON Training may share student contact information, including names and emails, with the course instructor(s) to facilitate sharing of pre-work and course instructions. Instructors are required to safeguard this information and provide appropriate protection so that it is kept private. Instructors may not use student information outside the delivery of this course without the permission of the student.\u003c\/p\u003e\n\u003cp\u003e\u003cspan\u003e\u003cstrong\u003e9.8\u003c\/strong\u003e By purchasing this ticket you agree to abide by the \u003c\/span\u003e\u003ca href=\"https:\/\/defcon.org\/html\/links\/dc-code-of-conduct.html\"\u003e\u003cspan\u003eDEF CON Training Code of Conduct\u003c\/span\u003e\u003c\/a\u003e\u003cspan\u003e and the registration terms and conditions listed above.\u003c\/span\u003e\u003cspan\u003e\u003cb\u003e\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e \u003c\/p\u003e\n\u003cp dir=\"ltr\"\u003e\u003cbr\u003e\u003c\/p\u003e","brand":"DEFCON MIDDLE EAST","offers":[{"title":"Course only","offer_id":49942347776243,"sku":null,"price":1200.0,"currency_code":"BHD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0841\/4815\/8707\/files\/default_DCT_photo.webp?v=1786559556","url":"https:\/\/me.shop.defcon.org\/products\/ai-augmented-operator","provider":"DEF CON MIDDLE EAST","version":"1.0","type":"link"}