BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.bsidescbr.com.au//bsides-canberra-2026//talk//QWSKG
 N
BEGIN:VTIMEZONE
TZID:Australia/Sydney
BEGIN:STANDARD
DTSTART:20250924T000000
TZNAME:AEST
TZOFFSETFROM:+1000
TZOFFSETTO:+1000
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20251005T030000
RDATE:20261004T030000
TZNAME:AEDT
TZOFFSETFROM:+1000
TZOFFSETTO:+1100
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20260405T030000
RDATE:20270404T030000
TZNAME:AEST
TZOFFSETFROM:+1100
TZOFFSETTO:+1000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:From Copilot to Commander: Building Agentic AI for Security Invest
 igations - Sindre Breda
DTSTART;TZID=Australia/Sydney:20260924T100000
DTEND;TZID=Australia/Sydney:20260924T170000
DTSTAMP:20260727T191436Z
UID:pretalx-bsides-canberra-2026-QWSKGN@cfp.bsidescbr.com.au
DESCRIPTION:A hands-on 8-hour workshop on building AI systems that run rea
 l security investigations - not just isolated copilot tasks. Most teams ge
 t useful help from Claude or ChatGPT on single questions. Few can reliably
  run multi-step investigations across logs\, tools\, and incidents.\nTaugh
 t by instructors behind the most popular Black Hat 2025 AI training and th
 e team that built the first AI agent to autonomously solve the Splunk Boss
  of the SOC CTF.\nInvestigation agents fail not because of model quality\,
  but because investigations are multi-step\, ambiguous\, and tool-heavy - 
 small errors compound and there are no unit tests to keep things on track.
 \n\nFour labs:\nLab 1: Run an OSS LLM locally and watch it hallucinate on 
 SOC questions\nLab 2: Wrap it in an agent harness against Splunk BOTSv3\nL
 ab 3: Author a plan.md timelining skill\nLab 4: Score it\, error-analyze t
 races\, fix the skill\, watch the score move\n\nConcept blocks cover harne
 ss anatomy\, MCP and skills\, planning patterns\, evals\, agentic memory a
 nd RAG\, and securing agents against the lethal trifecta.\nYou leave with 
 a working agent\, a reusable skill\, an eval harness\, and a methodology.\
 n\nAudience: SOC\, IR\, threat hunters\, detection engineers\, architects\
 , technical leaders.\nPrereqs: Laptop\, terminal comfort\, optional Python
 . Pre-work to install harness + pull local model.\nWe bring: LLM API key f
 or attendees\, bring your own key if prefered.
LOCATION:Murray-Fitzroy Room
URL:https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/QWSKGN/
END:VEVENT
END:VCALENDAR
