Call For Paper - Presentations

Pentesting in the age of AI - where are we?
2026-09-10 , Großer Saal

This talk focuses on the opportunities, limitations, and practical results of using AI in penetration testing.

We will compare different approaches to application security testing, including static and dynamic analysis, and examine where AI can provide value in each of them. In particular, we will look at several modes of AI-assisted security testing:

  • AI-driven source code analysis
  • AI-assisted verification of static analysis tool findings
  • AI-driven runtime analysis using custom scripts
  • AI-assisted verification of results from established security tools

The effectiveness of these approaches varies significantly depending on the selected method, model, tooling, and target environment.

Instead of relying on idealized lab scenarios, this talk presents real-world results from practical security testing. Beyond classical web application penetration testing, an area where AI already performs comparatively well, we will also explore the use of AI in Active Directory and Windows environment exploitation.

The audience will leave with a realistic understanding of where AI can currently support penetration testers, where it still falls short, and which workflows are most promising in practice.


An AI agent for a few hundred euros doing the job of a highly skilled senior penetration tester? That sounds great. But are we actually there yet?

This talk explores different ways of using AI for static and dynamic security analysis. We will look at AI as the pentester, AI as an assistant for validating tool output, and AI as the convenient interface for people who are too lazy to read the manual.

Evaluating the results of today’s AI-based pentesting projects can feel familiar to anyone who has reviewed a junior tester’s first report: some valid findings, some interesting ideas, some missing context, and a few confidently incorrect conclusions.

So what is the real issue? Is AI still not good enough, or is the person in front of the prompt part of the problem?

Focusing on Static Application Security Testing and Dynamic Application Security Testing, this talk presents practical examples, real-world observations, and a sober assessment of where AI can support penetration testing today. We will discuss what works, what fails, and why blindly trusting AI-generated security results is still a bad idea.

With over a decade of experience in the field, Christian Biehler is a seasoned IT security expert who combines the perspectives of a hacker, penetration tester, consultant, and trainer. His technical focus lies in securing Windows infrastructures and the Microsoft Cloud stack, including Entra ID, Azure, and M365.

Christian holds a Master’s degree in IT Security and the CISSP certification. He has successfully delivered over 300 projects across diverse sectors, establishing deep expertise in security architecture, risk management, and penetration testing for web, mobile, and operating systems.

Since 2019, Christian has been the Managing Director of bi-sec GmbH, leading a firm dedicated to expert consulting, rigorous penetration testing, and specialized security training.