Yet Another AI Talk — The Good, The Bad, The Ugly: AI for Pentesters
AI is a force multiplier for pentesters — and a liability if you don't know where it breaks. This talk cuts through the hype with real engagement stories: what works (triage, wordlists, report drafts), what fails (hallucinated CVEs, dangerous tool flags, false confidence in code review), and what gets dangerous (data leakage, scope violations, DoS by accident, agentic AI with no guardrails). Practical techniques, honest failures, no vendor spin.
AI is reshaping how pentesters work — but most guidance skips the failures. This talk delivers the unfiltered practitioner view: real wins, real mistakes, and real near-misses from live engagements. Walk away with techniques you can use tomorrow and a clear framework for keeping AI as a tool, not a liability.
Brian Lowe is the Team Lead for Penetration Testing at KirkpatrickPrice, where he conducts external, internal, web application, cloud, and red team assessments for organizations across regulated industries. Before moving into offensive security, he served 23 years in the United States Air Force, retiring as a Senior Master Sergeant (E-8). His military career included deployments to Iraq, Afghanistan, the UAE, Kuwait, Saudi Arabia, and Turkey, with collaborative work alongside the FBI, U.S. Secret Service, State Department, and Department of Energy. He holds industry certifications including CRTO, GWAPT, PNPT, eCPPTv2, GCIH, and CEH, and has been credited with CVE-2025-55817, CVE-2021-40492, and CVE-2021-40353. Outside of work, Brian is a Brazilian Jiu-Jitsu black belt under Gustavo Machado, a father of six, and a PopPop of four. His kids think hacking is cool — which, honestly, is reason enough. github.com/5qu1n7