AWS at Black Hat 2026
August 3-6 | Las Vegas | Booth Number 1648
Security at machine speed
Join Amazon Web Services (AWS) at Black Hat USA 2026 to see how AI-powered security is compressing remediation from days to minutes. Visit the AWS booth for live demos of AWS Continuum, Security Hub Extended, and purpose-built AI workload security. Connect with AWS experts for one-on-one deep dives to experience how AWS can help your security teams stay ahead of AI-accelerated threats.
Hear from AWS Experts
Join us to learn and interact directly with AWS executives.
Machine-Speed Defense: Building an Autonomous Security Operations Loop for the AI Era
Wednesday, August 5 | 10:15 am - 10:35 am PDT
Pulse Stage 2
Frontier foundation models have given adversaries the ability to discover and exploit vulnerabilities at machine speed. This presents new challenges, but also new opportunities for security organizations. By leveraging the same AI-powered reasoning capabilities that accelerate offensive techniques, organizations can also enable security teams to discover, correlate, validate, and remediate exposures. This session demonstrates how a continuous security loop turns this moment into operational advantage. We'll show how a business-context graph can rank findings by real exploitability and how defenders can validate attack paths in isolated and sandboxes to implement an autonomous security operations loop. Practitioners will leave with a blueprint for transforming their enterprise security by unlocking machine-speed defense as a durable competitive edge.
Learn more
Autonomous Defense at Cloud Scale: Critical Choices for Security Leaders Today
Wednesday, August 5 at 11:00 am - 12:00 pm PDT
Breakers F
The rise of agentic AI and frontier models has created an opportunity for security leaders to rethink how they protect and operate at cloud scale. However, foundational security remains table stakes even as the landscape evolves. Organizations that extend these fundamentals with autonomous workload governance will turn AI into a security force multiplier. This roundtable brings together security leaders to explore what stays constant, what's new, and how to navigate the intersection. We'll discuss how frontier models serve as force multipliers for both attackers and defenders, what architectural patterns build resilience into AI infrastructure, and the real economics of running AI-powered defense. Most critically, we'll tackle how enterprises can build a durable security harness, one designed to adapt as models and techniques continue to evolve.
Learn more
ThreatForest: Automated Attack Trees from Source Code Abstract
Thursday, August 6 at 2:35 pm - 3:15 pm PDT
Jasmine, Level 3
Threat modeling is critical but rarely done. Manual processes take days, go stale after every deployment, and can't keep pace with cloud-native architectures. In this session, learn how ThreatForest uses six specialized AI agents to automatically analyze your source code repositories and produce structured attack trees mapped to MITRE ATT&CK techniques with actionable mitigations. Unlike single-shot AI tools that generate unverified output, ThreatForest's multi-agent pipeline validates findings at every stage, ensuring threats are grounded in your actual code and mapped to real ATT&CK techniques. Walk away with an open-source tool you can point at your own repos, a reusable multi-agent architecture pattern, and a framework for measuring threat model quality programmatically.
Learn more
Tuesday, August 4
Booth theater sessions
Join us at the AWS booth theater for curated topics delivered in 15-minute AWS and partner-led sessions
|
TIME
|
TITLE
|
SPEAKER
|
SUMMARY
|
|---|---|---|---|
|
4:30 — 5:00 PM PT
|
Defense in Depth for the AI Era |
Matt Saner, AWS, Sr. Manager, Security Specialist SAs |
AI agents cross every boundary in your environment. This talk introduces a layered framework securing infrastructure, identity, and application layers with practical approaches to address prompt injection, agent compromise, and data exfiltration. |
|
5:00 — 5:30 PM PT
|
Multi-Agent Threat Modeling with Deterministic Verification |
Daniel Begimher, AWS, Sr Security Engineer
|
Manual threat modeling takes days and goes stale with each deployment. This session covers how ThreatForest automates it with structured attack trees mapped to MITRE ATT&CK. |
|
5:30 — 6:00 PM PT
|
From Discovery to Remediation: AWS Continuum in 20 Minutes |
Christopher Rae, AWS, Prin. WW Security Specialist |
This session demonstrates how a continuous security loop can leverage frontier models for an operational advantage. We will cover how it combines a business-context graph for risk ranking, isolated sandbox validation, and autonomous remediation. |
|
6:00 — 6:30 PM PT
|
What's new with AWS Detection & Response |
Marshall Jones, AWS, Sr. WW Specialist SA Security |
What if your security team could detect threats faster and remediate automatically across multicloud? This session walks through enhanced threat detection, AI-powered security operations, and automated vulnerability management and how these capabilities work together to give you a clear integration path. |
Wednesday, August 5
Booth theater sessions
Join us at the AWS booth theater for curated topics delivered in 15-minute AWS and partner-led sessions
|
TIME
|
TITLE
|
SPEAKER
|
SUMMARY
|
|---|---|---|---|
|
10:00 — 10:30 AM PT
|
When Does a Practitioner Let Go? |
Xenia Tupitsyna, AWS, Senior UX Designer |
Help shape the future of agentic interfaces and answer the question: when should an AI agent be allowed to run fully autonomously? You'll take the controls during a live security incident, decide when to trust the agent to diagnose, act, or go autonomous — and see where your trust threshold falls in a 3-minute gamified exercise. |
|
10:30 — 11:00 AM PT
|
AI Governance at Scale |
Rodolfo Brenes, AWS, Principal SA - CloudOps Pal Patel, AWS, Sr. WW SA - Governance |
Organizations deploying AI at scale need governance controls to manage risk. This session introduces a layered approach, from scoping with AWS security matrices, through policy enforcement with AWS Organizations, to agentic controls with Bedrock AgentCore, providing a blueprint to address shadow AI and agentic sprawl. |
|
11:30 — 12:00 PM PT
|
Network Security Strategies for the Post-Mythos era |
Sofia Aluma, AWS, Senior WW Security Specialist |
Frontier AI models can now discover and weaponize zero-day vulnerabilities in hours, collapsing the assumption that human-reviewed supply chain dependencies are safe. This session covers architectural patterns and ingress/egress controls that break AI-assisted kill chains at multiple independent layers. |
|
1:30 — 2:00 PM PT
|
Beyond the Confused Deputy: Workload Identity Primitives for Autonomous AI Agents |
Pravin Nair, AWS, Sr. Security Strategy SA
|
AI agents act autonomously across trust domains, but identity standards were built for humans. This talk shows how the confused deputy problem resurfaces as privilege escalation in multi-agent architectures, and presents three cryptographic primitives that architecturally prevent lateral movement and delegation abuse. |
|
2:00 — 2:30 PM PT
|
Building the AI Hacker on your Side. |
Arnon Trabelsi, Tenzai, Lead Product Manager |
In this session, Tenzai shows the exploitability of critical vulnerabilities and demonstrates how AWS WAF rules are automatically generated to close the exposure gap. |
|
2:30 — 3:00 PM PT
|
Drata - What Do Your Agents Do When Nobody's Watching? |
Johnny Kinder, Drata, Member of technical staff |
In this session, Drata demonstrates how to discover, govern, and prove compliance for AI agents operating beyond the AWS perimeter addressing the governance gap that 90% of companies can't answer today. |
|
3:00 — 3:30 PM PT
|
One Console for unified Multi-Vendor Security |
Frank Schwarzenau, AWS, WW Specialist, Security |
What if you could activate endpoint, identity, data, and cloud security from 21 ISVs through a single AWS console? This session covers the architecture, economics, and operational model of Security Hub Extended, which provides full-stack coverage with zero procurement friction. |
|
3:30 — 4:00 PM PT
|
Enable AI at scale, with data secured everywhere |
Yuri Duchovny, Cyera, Global Field CTO |
Join Cyera to watch how how AI-native data classification powered by Amazon Bedrock discovers and governs the sensitive data fueling your AI workloads, reducing attack surface while enabling confident AI adoption at scale. |
|
4:00 — 4:30 PM PT
|
What's new with AWS Detection & Response |
Marshall Jones, AWS, Sr. WW Specialist SA Security |
What if your security team could detect threats faster and remediate automatically across multicloud? This session walks through enhanced threat detection, AI-powered security operations, and automated vulnerability management and how these capabilities work together to give you a clear integration path. |
|
4:30 — 5:00 PM PT
|
Proofpoint - Best-of-Breed Meets Best-in-Cloud: Proofpoint + AWS Security Hub |
Jason Chow, Proofpoint, Director - Product Marketing |
In this session, Proofpoint demonstrates how to secure the agentic workspace - protecting both humans and AI agents through unified collaboration, data, and AI security integrated with AWS Security Hub Extended. |
Thursday, August 6
Booth theater sessions
Join us at the AWS booth theater for curated topics delivered in 15-minute AWS and partner-led sessions
|
TIME
|
TITLE
|
SPEAKER
|
SUMMARY
|
|---|---|---|---|
|
10:00 — 10:30 AM PT
|
The Bot Arms Race: Detecting What Doesn't Want to Be Detected |
Justin Kurpius, AWS, Sr Edge GTM Specialist |
Sophisticated bots now use headless browsers, residential proxies, and coordinated low-rate attacks that blend with legitimate traffic. This session explores how multi-signal detection that combines browser interrogation, TLS fingerprinting, and ML-based behavioral analysis shifts the advantage back to defenders at the edge. |
|
10:30 — 11:00 AM PT
|
From Cloud Guardrails to AI Guardrails: Turning Security Intent into AWS Controls |
Gal Ordo, Native, CPO & Co-founder |
Native shows how to evolve cloud guardrails into AI guardrails, translating security intent into enforceable AWS controls across perimeter, segmentation, and baseline layers without manual policy authoring. |
|
11:30 — 12:00 PM PT
|
AI Security: Architecting Defense-in-Depth for AI Workloads |
Dan Krpata, AWS, Specialist Sr. Sales Rep
|
Dive into advanced security architectures for AI workloads. This session covers how to protect against sophisticated attack vectors using identity, fine-grained access policies, and secure foundation model deployment patterns implementing least-privilege controls for generative and agentic AI at scale. |
|
1:00 — 1:30 PM PT
|
Improve security response with AWS Security Incident Response |
Kyle Shields, AWS, Sr. WW Specialist SA Security |
Security events demand fast, effective response, but most teams struggle with preparation and recovery. This session introduces AWS Security Incident Response, covering common challenges, a reactive and proactive mental model, and how the service works to improve your response capabilities. |
|
1:30 — 2:00 PM PT
|
Securing AI Infrastructure on AWS
|
Adam Hunter, Trend Micro, Sr. Cloud Solutions Architect |
TrendAI presents a four-layer security blueprint for AI workloads on AWS covering data, application, workload, and infrastructure - to protect against the 255% surge in agentic AI vulnerabilities. |
|
2:30 — 3:00 PM PT
|
Say Yes to Agentic AI: Real-Time Guardrails with Amazon Bedrock AgentCore and Netskope |
Steve Riley, Netskope, VP and Field CTO |
This session shows how Amazon Bedrock AgentCore and Netskope AI Guardrails combine into a "dual-gate" architecture that enforces policy on agent actions, tool calls, and data flows in real time |
AWS Customer & Partner Appreciation Reception
Tuesday, August 4
7:00 - 10:00 pm PDT
Flanker Kitchen + Sports Bar | Shoppes at Mandalay Place
3950 Las Vegas Blvd S, # 215
Las Vegas, NV 89119
We invite AWS customers and partners to join your security peers for a welcome reception at Flanker restaurant.
Black Hat Global Startup Program Cocktail Reception
Monday, August 3
5:00 - 7:00 pm PDT
Flanker Kitchen + Sports Bar | Shoppes at Mandalay Place
3950 Las Vegas Blvd S, # 215
Las Vegas, NV 89119
This is a curated gathering limited to 70 attendees, an opportunity to strengthen relationships, exchange insights, and explore what's next in cloud security.
Black Hat Workshop: Network Security Strategies to Defend Against Emerging Threats
Monday, August 3
1:00 - 3:00 pm PDT
Mandalay Bay - Location TBD
3950 Las Vegas Blvd S, # 215
Las Vegas, NV 89119
This hands-on workshop dives into securing AI workload egress using Amazon Route 53 Resolver DNS Firewall and AWS Network Firewall and helps close the blind spot that enables C2 communications, data exfiltration, and ransomware.
AWS Partners
Explore AWS Partner security solutions at the AWS booth, featuring a dedicated demo pedestal and partner-led theater sessions throughout expo hours. You will hear directly from AWS Partners on how their solutions work alongside AWS to deliver unified visibility, response, and protection - all from a single console.
Did you find what you were looking for today?
Let us know so we can improve the quality of the content on our pages