Palo Alto Networks at Black Hat USA 2026
Sep 
19th
–
Sep 
21st
Join Us
Text goes here
X
Link Text
Text goes here
X

10:30 AM – 10:45 AM

Unify code to cloud insights to accelerate secure development with Cortex Cloud & Semgrep 

Orion Cassetto + Semgrep SME

10:30 AM – 10:45 AM

Unify code to cloud insights to accelerate secure development with Cortex Cloud & Semgrep 

Orion Cassetto + Semgrep SME

Palo Alto Networks NextGen Summit
Register
Text goes here
X
Register
Text goes here
X
Overview
2024 Recap
Agenda
Hosts
Entertainment
Venue

Palo Alto Networks at
Black Hat USA 2026

August 4 - 6 | Las Vegas, NV

Mandalay Bay Convention Center | Azure Ballroom 

Request a meeting
Text goes here
X

We've got next: 

Experience AI-powered security at Black Hat.

Frontier AI: 

Breaking the attacker's playbook

We are elevating our presence at Black Hat this year, and you’re invited. We have secured the Azure at Mandalay Bay, just steps away from the convention center designed entirely around hosting you, our valued customers and partners.


Think of this dedicated space as your ultimate Black Hat hub: a sophisticated environment to escape the crowded floor, connect with industry leaders, experience live technology demonstrations, and drive your strategic goals forward.


Join us for networking, demos and deep dive sessions:


Tuesday, Aug 4: 4:00 PM – 7:00 PM
Wednesday, Aug 5: 10:00 AM – 6:00 PM
Thursday, Aug 6: 10:00 AM – 4:00 PM


Mark your calendar
Text goes here
X

Use code PAN to save $200 on a briefing pass or $100 on a business hall pass.

Palo Alto Networks Sessions

COMING SOON

Palo AlTo Networks Session

Inside Adversarial AI: Real-World Attacks and How to Stop Them 

Wednesday, August 6 | 10:15 AM – 11:05 AM PT

Mandalay Ballroom – J

Adversarial AI has super-charged cybercrime, letting even low-skill actors craft convincing deepfakes and run end-to-end campaigns at machine speed—often 10× faster than traditional methods. Drawing on insights from hundreds of Unit 42 incident-response engagements, our experts will unpack the latest AI-driven tactics across the attack chain and deliver field-tested defenses you can deploy now to stay ahead of accelerated threats.

More info
Text goes here
X

Michael Sikorski

CTO & VP Engineering Palo Alto Networks

Palo AlTo Networks Session

SHELLSILO

Thursday, August 7 | 10:00 AM – 10:55 AM PT

Business Hall, Arsenal Station 7

 While Windows System Calls have become a popular method for evading antivirus detection, they present considerable challenges beyond simple shellcode encryption/decryption. Unlike Linux, executing Windows System Calls often necessitates extensive setup, due to the need for specific C structures, which makes the code more complex and prone to errors compared to typical API calls. As a result, many developers turn to high-level languages like C to avoid the complexities of Assembly, particularly in malware development.

 

SHELLSILO addresses these challenges by offering an innovative solution for System Call shellcode generation.


More info
Text goes here
X

Tarek Ahmed

Staff Red Team Engineer

Palo Alto Networks

Palo AlTo Networks Session

Cloud Offensive Breach and Risk Assessment (COBRA)

Thursday, August 7 | 12:00 PM – 12:55 PM PT

Business Hall, Arsenal Station 8

Cloud Offensive Breach and Risk Assessment (COBRA) is an open-source tool designed to empower users to simulate attacks within multi-cloud environments, offering a comprehensive evaluation of security controls. By automating the testing of various threat vectors including external and insider threats, lateral movement, and data exfiltration, COBRA enables organizations to gain insights into their security posture vulnerabilities. COBRA is designed to conduct simulated attacks to assess an organization's ability to detect and respond to security threats effectively.

More info
Text goes here
X

Anand Tiwari

Manager, Product Management

Palo Alto Networks

Harsha Koushik

Technical Product Manager

Palo Alto Networks

Palo AlTo Networks Session

GDIOCSpider - Extracting and Identifying IOCs from the GDriveverse

Thursday, August 7 | 1:00 PM – 1:55 PM PT

Business Hall, Arsenal Station 2

Google Drive in recent years has become one of the most abused platforms for threat actors to conduct illegal and malicious activity. Threat actors use Google accounts to launch, store, and log malware, effectively turning Drive into a command and control center. On the side of legal and ethical activity, Google Drive remains a popular platform for security researchers to store these artifacts in summarized write-ups and spreadsheets of malicious and illegal activity observed. Much like an archaeologist looks for artifacts providing clues of the history of civilization, security researchers look for Indicators of Compromise (IOCs), which are clues to what a threat actor has done. Security engineers have worked across decades to build out tooling to analyze hard drives and network resources; however, similar advances to analyze Google Drive resources have remained underdeveloped. Along the same line, tools that aggregate and summarize collections of records on IOCs stored in Google Drive by researchers are also lacking.


The GDIOCSpider (Google Drive IOC Spider) provides a tool for both of these use cases. 

More info
Text goes here
X

Noah Dunn

Senior Security Automation Engineer 

Palo Alto Networks

Palo AlTo Networks Session

NOC Briefing Schedule

NOC Briefing #1 - Open to All Attendees

Wednesday, August 6 | 11:30 AM – 12:00 PM PT

Lagoon H, Level 2, MBCC

Wednesday, August 6⋅11:30 – 12:00

Lagoon H, Level 2, MBCC

NOC Briefing #2 - Open to All Attendees

Wednesday, August 6 | 5:35 PM – 5:55 PM PT

Business Hall Theater B, Business Hall, MBCC

Wednesday, August 6⋅17:35 – 17:55

Business Hall Theater B, Business Hall, MBCC

NOC Briefing #3 - Open to All Attendees

Thursday, August 7 | 11:30 AM – 12:00 PM PT

Lagoon H, Level 2, MBCC

Thursday, August 7⋅11:30 – 12:00

Lagoon H, Level 2, MBCC

NOC Briefing #4 - Open to All Attendees

Thursday, August 7 | 2:40 PM – 3:00 PM PT

Business Hall Theater B, Business Hall, MBCC

Thursday, August 7⋅15:15 – 15:35

Business Hall Theater B, Business Hall, MBCC

More info
Text goes here
X

James Holland

Sr Principal Engineer

Palo Alto Networks

Jason Reverri

Manager, Technical Product Engineer

Palo Alto Networks

Palo ALto Networks Hub

Sessions

Wednesday, August 5

10:15 AM – 11:00 AM

Unit 42 Threat Briefing: Combat Risks from Frontier AI Models

Orion Cassetto + Semgrep SME

11:15 AM – 12:00 PM

The Race Against Frontier AI for SecOps

Brian Chew

12:15 PM – 1:00 PM

Why Defenders Can't Wait: Pre-Disclosure Prevention Against Frontier AI-Accelerated Exposure

Salina Wuttke

1:15 PM – 2:00 PM

Every Identity Is Privileged: Securing the Workforce of the AI Enterprise

Orion Cassetto + Semgrep SME

3:15 PM – 4:00 PM

Atypical Network Traffic Evasion: Why Prevention Begins with Monitoring Attacker Infrastructure

AT&T

4:15 PM – 5:00 PM

Fight AI with AI in the Modern Workspace

Adrian Diaz

Thursday, August 6

10:15 AM – 11:00 AM

Unit 42 Threat Briefing: Combat Risks from Frontier AI Models

Kathi Whitbey

11:15 AM – 12:00 PM

Poisoned Packages & Broken Pipelines: Defending the Modern Supply Chain

Orion Cassetto + Semgrep SME

12:15 PM – 1:00 PM

When Al Agents Act: Rethinking Security for the Al Enterprise

Erick Moore

2:15 PM – 3:00 PM

Every Identity Is Privileged: Securing the Workforce of the AI Enterprise

Orion Cassetto + Semgrep SME

3:15 PM – 4:00 PM

Closing The 25-Minute Cloud Attack Window

Orion Cassetto + Semgrep SME

Learn More
Text goes here
X
Register for Sessions
Text goes here
X

Palo Alto Networks Sessions

COMING SOON

Palo AlTo Networks Session

Inside Adversarial AI: Real-World Attacks and How to Stop Them 

Wednesday, August 6 | 10:15 AM – 11:05 AM PT

Mandalay Ballroom – J

Adversarial AI has super-charged cybercrime, letting even low-skill actors craft convincing deepfakes and run end-to-end campaigns at machine speed—often 10× faster than traditional methods. Drawing on insights from hundreds of Unit 42 incident-response engagements, our experts will unpack the latest AI-driven tactics across the attack chain and deliver field-tested defenses you can deploy now to stay ahead of accelerated threats.

More info
Text goes here
X

Michael Sikorski

CTO & VP Engineering Palo Alto Networks

Palo AlTo Networks Session

SHELLSILO

Thursday, August 7 | 10:00 AM – 10:55 AM PT

Business Hall, Arsenal Station 7

 While Windows System Calls have become a popular method for evading antivirus detection, they present considerable challenges beyond simple shellcode encryption/decryption. Unlike Linux, executing Windows System Calls often necessitates extensive setup, due to the need for specific C structures, which makes the code more complex and prone to errors compared to typical API calls. As a result, many developers turn to high-level languages like C to avoid the complexities of Assembly, particularly in malware development.

 

SHELLSILO addresses these challenges by offering an innovative solution for System Call shellcode generation.


More info
Text goes here
X

Tarek Ahmed

Staff Red Team Engineer

Palo Alto Networks

Palo AlTo Networks Session

Cloud Offensive Breach and Risk Assessment (COBRA)

Thursday, August 7 | 12:00 PM – 12:55 PM PT

Business Hall, Arsenal Station 8

Cloud Offensive Breach and Risk Assessment (COBRA) is an open-source tool designed to empower users to simulate attacks within multi-cloud environments, offering a comprehensive evaluation of security controls. By automating the testing of various threat vectors including external and insider threats, lateral movement, and data exfiltration, COBRA enables organizations to gain insights into their security posture vulnerabilities. COBRA is designed to conduct simulated attacks to assess an organization's ability to detect and respond to security threats effectively.

More info
Text goes here
X

Anand Tiwari

Manager, Product Management

Palo Alto Networks

Harsha Koushik

Technical Product Manager

Palo Alto Networks

Palo AlTo Networks Session

GDIOCSpider - Extracting and Identifying IOCs from the GDriveverse

Thursday, August 7 | 1:00 PM – 1:55 PM PT

Business Hall, Arsenal Station 2

Google Drive in recent years has become one of the most abused platforms for threat actors to conduct illegal and malicious activity. Threat actors use Google accounts to launch, store, and log malware, effectively turning Drive into a command and control center. On the side of legal and ethical activity, Google Drive remains a popular platform for security researchers to store these artifacts in summarized write-ups and spreadsheets of malicious and illegal activity observed. Much like an archaeologist looks for artifacts providing clues of the history of civilization, security researchers look for Indicators of Compromise (IOCs), which are clues to what a threat actor has done. Security engineers have worked across decades to build out tooling to analyze hard drives and network resources; however, similar advances to analyze Google Drive resources have remained underdeveloped. Along the same line, tools that aggregate and summarize collections of records on IOCs stored in Google Drive by researchers are also lacking.


The GDIOCSpider (Google Drive IOC Spider) provides a tool for both of these use cases. 

More info
Text goes here
X

Noah Dunn

Senior Security Automation Engineer 

Palo Alto Networks

Palo AlTo Networks Session

NOC Briefing Schedule

NOC Briefing #1 - Open to All Attendees

Wednesday, August 6 | 11:30 AM – 12:00 PM PT

Lagoon H, Level 2, MBCC

Wednesday, August 6⋅11:30 – 12:00

Lagoon H, Level 2, MBCC

NOC Briefing #2 - Open to All Attendees

Wednesday, August 6 | 5:35 PM – 5:55 PM PT

Business Hall Theater B, Business Hall, MBCC

Wednesday, August 6⋅17:35 – 17:55

Business Hall Theater B, Business Hall, MBCC

NOC Briefing #3 - Open to All Attendees

Thursday, August 7 | 11:30 AM – 12:00 PM PT

Lagoon H, Level 2, MBCC

Thursday, August 7⋅11:30 – 12:00

Lagoon H, Level 2, MBCC

NOC Briefing #4 - Open to All Attendees

Thursday, August 7 | 2:40 PM – 3:00 PM PT

Business Hall Theater B, Business Hall, MBCC

Thursday, August 7⋅15:15 – 15:35

Business Hall Theater B, Business Hall, MBCC

More info
Text goes here
X

James Holland

Sr Principal Engineer

Palo Alto Networks

Jason Reverri

Manager, Technical Product Engineer

Palo Alto Networks

NOC Briefing Schedule

Hours of Operation


NOC Visiting Hours (Surf EF, Level 2)


Saturday, August 1 – Thursday, August 6: 9:00 AM – 6:00 PM

 

NOC Presentations


Wednesday, August 5: 11:30 AM - 12:00 PM; 1:30 PM - 2:00 PM
Thursday, August 6: 10:30 AM - 11:00 AM; 1:30 PM - 2:00 PM

 

Live Stream Hours


The NOC will be streamed live via our Twitch channel too!

Saturday, August 1 – Thursday, August 6: 9:00 AM – 6:00 PM

Palo AlTo Networks Session

Inside Adversarial AI: Real-World Attacks and How to Stop Them 

Wednesday, August 6 | 10:15 AM – 11:05 AM PT

Mandalay Ballroom – J

Adversarial AI has super-charged cybercrime, letting even low-skill actors craft convincing deepfakes and run end-to-end campaigns at machine speed—often 10× faster than traditional methods. Drawing on insights from hundreds of Unit 42 incident-response engagements, our experts will unpack the latest AI-driven tactics across the attack chain and deliver field-tested defenses you can deploy now to stay ahead of accelerated threats.

More info
Text goes here
X

Michael Sikorski

CTO & VP Engineering Palo Alto Networks

Palo AlTo Networks Session

SHELLSILO

Thursday, August 7 | 10:00 AM – 10:55 AM PT

Business Hall, Arsenal Station 7

 While Windows System Calls have become a popular method for evading antivirus detection, they present considerable challenges beyond simple shellcode encryption/decryption. Unlike Linux, executing Windows System Calls often necessitates extensive setup, due to the need for specific C structures, which makes the code more complex and prone to errors compared to typical API calls. As a result, many developers turn to high-level languages like C to avoid the complexities of Assembly, particularly in malware development.

 

SHELLSILO addresses these challenges by offering an innovative solution for System Call shellcode generation.


More info
Text goes here
X

Tarek Ahmed

Staff Red Team Engineer

Palo Alto Networks

Palo AlTo Networks Session

Cloud Offensive Breach and Risk Assessment (COBRA)

Thursday, August 7 | 12:00 PM – 12:55 PM PT

Business Hall, Arsenal Station 8

Cloud Offensive Breach and Risk Assessment (COBRA) is an open-source tool designed to empower users to simulate attacks within multi-cloud environments, offering a comprehensive evaluation of security controls. By automating the testing of various threat vectors including external and insider threats, lateral movement, and data exfiltration, COBRA enables organizations to gain insights into their security posture vulnerabilities. COBRA is designed to conduct simulated attacks to assess an organization's ability to detect and respond to security threats effectively.

More info
Text goes here
X

Anand Tiwari

Manager, Product Management

Palo Alto Networks

Harsha Koushik

Technical Product Manager

Palo Alto Networks

Palo AlTo Networks Session

GDIOCSpider - Extracting and Identifying IOCs from the GDriveverse

Thursday, August 7 | 1:00 PM – 1:55 PM PT

Business Hall, Arsenal Station 2

Google Drive in recent years has become one of the most abused platforms for threat actors to conduct illegal and malicious activity. Threat actors use Google accounts to launch, store, and log malware, effectively turning Drive into a command and control center. On the side of legal and ethical activity, Google Drive remains a popular platform for security researchers to store these artifacts in summarized write-ups and spreadsheets of malicious and illegal activity observed. Much like an archaeologist looks for artifacts providing clues of the history of civilization, security researchers look for Indicators of Compromise (IOCs), which are clues to what a threat actor has done. Security engineers have worked across decades to build out tooling to analyze hard drives and network resources; however, similar advances to analyze Google Drive resources have remained underdeveloped. Along the same line, tools that aggregate and summarize collections of records on IOCs stored in Google Drive by researchers are also lacking.


The GDIOCSpider (Google Drive IOC Spider) provides a tool for both of these use cases. 

More info
Text goes here
X

Noah Dunn

Senior Security Automation Engineer 

Palo Alto Networks

Palo AlTo Networks Session

NOC Briefing Schedule

NOC Briefing #1 - Open to All Attendees

Wednesday, August 6 | 11:30 AM – 12:00 PM PT

Lagoon H, Level 2, MBCC

Wednesday, August 6⋅11:30 – 12:00

Lagoon H, Level 2, MBCC

NOC Briefing #2 - Open to All Attendees

Wednesday, August 6 | 5:35 PM – 5:55 PM PT

Business Hall Theater B, Business Hall, MBCC

Wednesday, August 6⋅17:35 – 17:55

Business Hall Theater B, Business Hall, MBCC

NOC Briefing #3 - Open to All Attendees

Thursday, August 7 | 11:30 AM – 12:00 PM PT

Lagoon H, Level 2, MBCC

Thursday, August 7⋅11:30 – 12:00

Lagoon H, Level 2, MBCC

NOC Briefing #4 - Open to All Attendees

Thursday, August 7 | 2:40 PM – 3:00 PM PT

Business Hall Theater B, Business Hall, MBCC

Thursday, August 7⋅15:15 – 15:35

Business Hall Theater B, Business Hall, MBCC

More info
Text goes here
X

James Holland

Sr Principal Engineer

Palo Alto Networks

Jason Reverri

Manager, Technical Product Engineer

Palo Alto Networks

Connect with us onsite

Experience a live demo:

Stop by the Palo Alto Networks Lounge at Azure right before you enter the Mandalay Bay Convention Center and learn more about the latest developments across the full Palo Alto Networks platform of security products.


Cortex: 

Autonomous Security Operations (XDR) & Real-Time Cloud Security (Cortex Cloud)


Unit 42:

Threat Intel, Incident Response, Cyber Risk Expertise, and Managed Services


NetSec:

Future of Frontier AI Network Security


Identity:

Next-Generation Identity Security


 

Schedule a meeting:

Want to take a deeper dive into what's next? Request a 1:1 meeting with one of our leaders or technical experts.


 

 

Here are a few topics our cybersecurity experts can cover, though we can tailor the conversation to any of your top security priorities:


- Preparing for Frontier AI-powered attacks

- The Future of Threat intelligence

- Understanding the Threat Landscape in the AI Era

- The New Unit 42 Threat Intelligence Services

- Modernizing the SOC

- Securing AI Across the Enterprise

- Building Cyber Resilience

- Protecting Identity in an AI-Driven World

- Reducing Cloud Risk

- Preparing For Your Next Cyber Crisis

 

Request a meeting
Text goes here
X

Location:


Azure Ballroom - Mandalay Bay

From the Casino: Head towards the convention center. Make your way down the hall. Once you past Border Grill, Azure Ballroom will be to the left side.


From the Convention Center: Head out past the food court. You will make your way towards the Casino. Azure Ballroom will be to the right side.

Copyright © 2026 Palo Alto Networks. All rights reserved.

Privacy
Text goes here
X
Contact Us
Text goes here
X
Terms of Use
Text goes here
X
Link Text
Text goes here
X
Share with Friends
Facebook
Twitter
LinkedIn
Link
CONTACT THE ORGANIZER
Google   Outlook   iCal   Yahoo

RSVP

Google Icon
Google
Outlook Icon
Outlook
Apple Icon
Apple
Yahoo Icon
Yahoo