Session

Build. Break. Defend. Repeat: Automating AppSec for .NET with AI

AI writes a lot of your code now, and some of it is vulnerable. Meanwhile, frontier models have started finding vulnerabilities autonomously and at scale. One recent run surfaced 23,000 of them across 1,000 open source projects, most absent from any CVE database. Attackers can now discover bugs at a speed no human AppSec team can match, so defence has to run at machine speed too. The catch: an LLM on its own hallucinates, and a rule-based security scanner on its own buries you in false positives. The useful combination is deterministic analysis for verifiable facts (call graphs, data flows, dependency trees, known CVEs) plus an LLM that understands what the code actually does. In this session we apply that combination to a real .NET application using AI agents with composable skills: threat modelling generated from the code itself, and CVE triage that checks whether vulnerable code is even reachable before you spend time on it. You'll see what works today, where it breaks, and how to fit it into your own workflow.

Niels Tanis

Security Researcher & Software Security Engineer @ Tidalis | Microsoft MVP | International Conference Speaker

Amersfoort, The Netherlands

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top