<<39C3 Power Cycles
  • <<39C3Power Cycles
  • Schedule Calendar
  • Schedule List
  • Speakers
  • Help
  • Legal
  • <<39C3Power Cycles
  • Schedule Calendar
  • Schedule List
  • Speakers
  • Help
  • Legal

Sindre Breda

This speaker has not yet provided information about themselves.

Events with this speaker

Day 4
13:50
40m
Breaking BOTS: Cheating at Blue Team CTFs with AI Speed-Runs

After we announced our results, CTFs like Splunk's Boss of the SOC (BOTS) started prohibiting AI agents. For science & profit, we keep doing it anyways. In BOTS, the AIs solve most of it in under 10 minutes instead of taking the full day. Our recipe was surprisingly simple: Teach AI agents to self-plan their investigation steps, adapt their plans to new information, work with the SIEM DB, and reason about log dumps. No exotic models, no massive lab budgets - just publicly available LLMs mixed with a bit of science and perseverance. We'll walk through how that works, including videos of the many ways AI trips itself up that marketers would rather hide, and how to do it at home with free and open-source tools. CTF organizers can't detect this - the arms race is probably over before it really began. But the real question isn't "can we cheat at CTFs?" It's what happens when investigations evolve from analysts-who-investigate to analysts-who-manage-AI-investigators. We'll show you what that transition already looks like today and peek into some uncomfortable questions about what comes next.

SecurityOne