Research presented at SAINTCON in Provo Utah on Friday Oct 22nd 2024.
Session Name: "Bypassing the Gatekeepers: LLM Enabled Techniques for Circumventing WAFs at Scale"
Web Application Firewalls (WAFs) have become ubiquitous in modern enterprise environments, presenting a significant challenge for security researchers and bug bounty hunters. This talk delves into cutting-edge techniques for bypassing WAFs on large-scale attack surfaces, empowering attendees to uncover critical vulnerabilities even in heavily protected environments.
We'll explore how innovations in Large Language Models (LLMs) can revolutionize penetration testing processes, focusing on their application in WAF circumvention. From crafting sophisticated payloads to automating reconnaissance, we'll demonstrate how AI can augment human creativity in offensive security.
This presentation will showcase real-world case studies, practical tools, and live demonstrations of AI-assisted WAF bypasses. We'll also discuss the ethical implications and potential defensive countermeasures, providing a balanced view of this rapidly evolving field.
Attendees will gain hands-on knowledge of implementing LLM-driven techniques, understanding both their power and limitations. Join us to glimpse the future of AI-driven offensive security and its critical role in shaping the cybersecurity landscape.