Palo Alto Networks at Black Hat USA 2026
Sep 
19th
–
Sep 
21st
RSVPs Closed
Text goes here
X
Link Text
Text goes here
X

10:30 AM – 10:45 AM

Unify code to cloud insights to accelerate secure development with Cortex Cloud & Semgrep 

Orion Cassetto + Semgrep SME

10:30 AM – 10:45 AM

Unify code to cloud insights to accelerate secure development with Cortex Cloud & Semgrep 

Orion Cassetto + Semgrep SME

Palo Alto Networks NextGen Summit
Event Gallery
Text goes here
X
Register
Text goes here
X
Overview
2024 Recap
Agenda
Hosts
Entertainment
Venue

Palo Alto Networks at
Black Hat USA 2026

August 4 - 6 | Las Vegas, NV

Mandalay Bay Convention Center | Azure Ballroom 

Request a meeting
Text goes here
X

We've got next: 

Experience AI-powered security at Black Hat.

Frontier AI: 

Breaking the attacker's playbook

We are elevating our presence at Black Hat this year, and you’re invited. We have secured the Azure at Mandalay Bay, just steps away from the convention center designed entirely around hosting you, our valued customers and partners.


Think of this dedicated space as your ultimate Black Hat hub: a sophisticated environment to escape the crowded floor, connect with industry leaders, experience live technology demonstrations, and drive your strategic goals forward.


Join us for networking, demos and deep dive sessions:


Tuesday, Aug 4: 4:00 PM – 7:00 PM
Wednesday, Aug 5: 10:00 AM – 6:00 PM
Thursday, Aug 6: 10:00 AM – 4:00 PM


Mark your calendar
Text goes here
X

Use code PAN to save $200 on a briefing pass or $100 on a business hall pass.

Palo Alto Networks Sessions

COMING SOON

Palo AlTo Networks Session

Inside Adversarial AI: Real-World Attacks and How to Stop Them 

Wednesday, August 6 | 10:15 AM – 11:05 AM PT

Mandalay Ballroom – J

Adversarial AI has super-charged cybercrime, letting even low-skill actors craft convincing deepfakes and run end-to-end campaigns at machine speed—often 10× faster than traditional methods. Drawing on insights from hundreds of Unit 42 incident-response engagements, our experts will unpack the latest AI-driven tactics across the attack chain and deliver field-tested defenses you can deploy now to stay ahead of accelerated threats.

More info
Text goes here
X

Michael Sikorski

CTO & VP Engineering Palo Alto Networks

Palo AlTo Networks Session

SHELLSILO

Thursday, August 7 | 10:00 AM – 10:55 AM PT

Business Hall, Arsenal Station 7

 While Windows System Calls have become a popular method for evading antivirus detection, they present considerable challenges beyond simple shellcode encryption/decryption. Unlike Linux, executing Windows System Calls often necessitates extensive setup, due to the need for specific C structures, which makes the code more complex and prone to errors compared to typical API calls. As a result, many developers turn to high-level languages like C to avoid the complexities of Assembly, particularly in malware development.

 

SHELLSILO addresses these challenges by offering an innovative solution for System Call shellcode generation.


More info
Text goes here
X

Tarek Ahmed

Staff Red Team Engineer

Palo Alto Networks

Palo AlTo Networks Session

Cloud Offensive Breach and Risk Assessment (COBRA)

Thursday, August 7 | 12:00 PM – 12:55 PM PT

Business Hall, Arsenal Station 8

Cloud Offensive Breach and Risk Assessment (COBRA) is an open-source tool designed to empower users to simulate attacks within multi-cloud environments, offering a comprehensive evaluation of security controls. By automating the testing of various threat vectors including external and insider threats, lateral movement, and data exfiltration, COBRA enables organizations to gain insights into their security posture vulnerabilities. COBRA is designed to conduct simulated attacks to assess an organization's ability to detect and respond to security threats effectively.

More info
Text goes here
X

Anand Tiwari

Manager, Product Management

Palo Alto Networks

Harsha Koushik

Technical Product Manager

Palo Alto Networks

Palo AlTo Networks Session

GDIOCSpider - Extracting and Identifying IOCs from the GDriveverse

Thursday, August 7 | 1:00 PM – 1:55 PM PT

Business Hall, Arsenal Station 2

Google Drive in recent years has become one of the most abused platforms for threat actors to conduct illegal and malicious activity. Threat actors use Google accounts to launch, store, and log malware, effectively turning Drive into a command and control center. On the side of legal and ethical activity, Google Drive remains a popular platform for security researchers to store these artifacts in summarized write-ups and spreadsheets of malicious and illegal activity observed. Much like an archaeologist looks for artifacts providing clues of the history of civilization, security researchers look for Indicators of Compromise (IOCs), which are clues to what a threat actor has done. Security engineers have worked across decades to build out tooling to analyze hard drives and network resources; however, similar advances to analyze Google Drive resources have remained underdeveloped. Along the same line, tools that aggregate and summarize collections of records on IOCs stored in Google Drive by researchers are also lacking.


The GDIOCSpider (Google Drive IOC Spider) provides a tool for both of these use cases. 

More info
Text goes here
X

Noah Dunn

Senior Security Automation Engineer 

Palo Alto Networks

Palo AlTo Networks Session

NOC Briefing Schedule

NOC Briefing #1 - Open to All Attendees

Wednesday, August 6 | 11:30 AM – 12:00 PM PT

Lagoon H, Level 2, MBCC

Wednesday, August 6⋅11:30 – 12:00

Lagoon H, Level 2, MBCC

NOC Briefing #2 - Open to All Attendees

Wednesday, August 6 | 5:35 PM – 5:55 PM PT

Business Hall Theater B, Business Hall, MBCC

Wednesday, August 6⋅17:35 – 17:55

Business Hall Theater B, Business Hall, MBCC

NOC Briefing #3 - Open to All Attendees

Thursday, August 7 | 11:30 AM – 12:00 PM PT

Lagoon H, Level 2, MBCC

Thursday, August 7⋅11:30 – 12:00

Lagoon H, Level 2, MBCC

NOC Briefing #4 - Open to All Attendees

Thursday, August 7 | 2:40 PM – 3:00 PM PT

Business Hall Theater B, Business Hall, MBCC

Thursday, August 7⋅15:15 – 15:35

Business Hall Theater B, Business Hall, MBCC

More info
Text goes here
X

James Holland

Sr Principal Engineer

Palo Alto Networks

Jason Reverri

Manager, Technical Product Engineer

Palo Alto Networks

Experiences with us onsite

Executive Welcome & Social 

 

 

Join us on Tuesday evening for an intimate gathering with Unit 42 threat researchers, incident responders and security consultants and Palo Alto Networks product leaders. Enjoy great food, drinks, and music from our live DJ as we kick off the week.


Date: Tuesday, August 4, 2026

Time: 4:00 PM - 7:00 PM 

Location: Azure at Mandalay Bay 


RSVP
Text goes here
X

SOC Transformation

Capture the Flag Challenge

 

The clock is ticking. Do you have what it takes?

 

Step into the arena at Black Hat and test your threat-hunting and incident response skills in our interactive SOC Transformation Capture the Flag (CTF) challenge.

Go head-to-head with your peers and fight AI-powered threats with AI-driven security. Use the intelligence and automation of Cortex XSIAM® to detect, investigate, and respond to complex attacks and secure your spot at the top of the leaderboard.  

 

 

Dates:

Wednesday, August 5, 2026

Thursday, August 6, 2026

Time: 11:15 AM – 4:00 PM 

Location: Azure at Mandalay Bay

 

Space is limited per session claim your spot and accept your mission!


Register
Text goes here
X

Hack the AI. Claim the Prize.

 

Understanding AI vulnerabilities requires seeing them in action. That’s why we’re sponsoring a special event with Huntr , the AI security platform driven by 19,000+ ethical hackers—to bring a live, interactive AI hacking competition to Black Hat launching August 1. Through a simulated chat interface, you’ll get hands-on experience attempting to bypass AI agent guardrails. 


How to play.


- Head to the Comprehensive AI Security demo station.
- Pick Your Target: Launch the simulated chat interface on the Huntr platform on your personal device.
- Hack the Bot: Force the system to bypass safety controls or leak restricted data.


$15,000 Global Prize Pool: Compete live at the booth or online—competition remains open through late August / mid-September.


Request a meeting
Text goes here
X

Palo ALto Networks Hub

Sessions

Wednesday, August 5

10:15 AM – 11:00 AM

Unit 42 Threat Briefing: Combat Risks from Frontier AI Models

Orion Cassetto + Semgrep SME

11:15 AM – 12:00 PM

The Race Against Frontier AI for SecOps

Brian Chew

12:15 PM – 1:00 PM

Why Defenders Can't Wait: Pre-Disclosure Prevention Against Frontier AI-Accelerated Exposure

Salina Wuttke

1:15 PM – 2:00 PM

Every Identity Is Privileged: Securing the Workforce of the AI Enterprise

Orion Cassetto + Semgrep SME

2:15 PM – 3:00 PM

Defending at Machine Speed: AI Agents, SASE, and Quantum Readiness

Orion Cassetto + Semgrep SME

3:15 PM – 4:00 PM

Atypical Network Traffic Evasion: Why Prevention Begins with Monitoring Attacker Infrastructure

AT&T

4:15 PM – 5:00 PM

Poisoned Packages & Broken Pipelines: Defending the Modern Supply Chain

Adrian Diaz

Thursday, August 6

10:15 AM – 11:00 AM

Unit 42 Threat Briefing: Combat Risks from Frontier AI Models

Kathi Whitbey

11:15 AM – 12:00 PM

Fight AI with AI in the Modern Workspace

Orion Cassetto + Semgrep SME

12:15 PM – 1:00 PM

When Al Agents Act: Rethinking Security for the Al Enterprise

Erick Moore

1:15 PM – 2:00 PM

Redefining the Human's Role in the Age of AI

Orion Cassetto + Semgrep SME

2:15 PM – 3:00 PM

Every Identity Is Privileged: Securing the Workforce of the AI Enterprise

Orion Cassetto + Semgrep SME

3:15 PM – 4:00 PM

Closing The 25-Minute Cloud Attack Window

Orion Cassetto + Semgrep SME

Learn More
Text goes here
X
Register for Sessions
Text goes here
X
Register for sessions
Text goes here
X

Palo Alto Networks Sessions

COMING SOON

Palo AlTo Networks Session

Inside Adversarial AI: Real-World Attacks and How to Stop Them 

Wednesday, August 6 | 10:15 AM – 11:05 AM PT

Mandalay Ballroom – J

Adversarial AI has super-charged cybercrime, letting even low-skill actors craft convincing deepfakes and run end-to-end campaigns at machine speed—often 10× faster than traditional methods. Drawing on insights from hundreds of Unit 42 incident-response engagements, our experts will unpack the latest AI-driven tactics across the attack chain and deliver field-tested defenses you can deploy now to stay ahead of accelerated threats.

More info
Text goes here
X

Michael Sikorski

CTO & VP Engineering Palo Alto Networks

Palo AlTo Networks Session

SHELLSILO

Thursday, August 7 | 10:00 AM – 10:55 AM PT

Business Hall, Arsenal Station 7

 While Windows System Calls have become a popular method for evading antivirus detection, they present considerable challenges beyond simple shellcode encryption/decryption. Unlike Linux, executing Windows System Calls often necessitates extensive setup, due to the need for specific C structures, which makes the code more complex and prone to errors compared to typical API calls. As a result, many developers turn to high-level languages like C to avoid the complexities of Assembly, particularly in malware development.

 

SHELLSILO addresses these challenges by offering an innovative solution for System Call shellcode generation.


More info
Text goes here
X

Tarek Ahmed

Staff Red Team Engineer

Palo Alto Networks

Palo AlTo Networks Session

Cloud Offensive Breach and Risk Assessment (COBRA)

Thursday, August 7 | 12:00 PM – 12:55 PM PT

Business Hall, Arsenal Station 8

Cloud Offensive Breach and Risk Assessment (COBRA) is an open-source tool designed to empower users to simulate attacks within multi-cloud environments, offering a comprehensive evaluation of security controls. By automating the testing of various threat vectors including external and insider threats, lateral movement, and data exfiltration, COBRA enables organizations to gain insights into their security posture vulnerabilities. COBRA is designed to conduct simulated attacks to assess an organization's ability to detect and respond to security threats effectively.

More info
Text goes here
X

Anand Tiwari

Manager, Product Management

Palo Alto Networks

Harsha Koushik

Technical Product Manager

Palo Alto Networks

Palo AlTo Networks Session

GDIOCSpider - Extracting and Identifying IOCs from the GDriveverse

Thursday, August 7 | 1:00 PM – 1:55 PM PT

Business Hall, Arsenal Station 2

Google Drive in recent years has become one of the most abused platforms for threat actors to conduct illegal and malicious activity. Threat actors use Google accounts to launch, store, and log malware, effectively turning Drive into a command and control center. On the side of legal and ethical activity, Google Drive remains a popular platform for security researchers to store these artifacts in summarized write-ups and spreadsheets of malicious and illegal activity observed. Much like an archaeologist looks for artifacts providing clues of the history of civilization, security researchers look for Indicators of Compromise (IOCs), which are clues to what a threat actor has done. Security engineers have worked across decades to build out tooling to analyze hard drives and network resources; however, similar advances to analyze Google Drive resources have remained underdeveloped. Along the same line, tools that aggregate and summarize collections of records on IOCs stored in Google Drive by researchers are also lacking.


The GDIOCSpider (Google Drive IOC Spider) provides a tool for both of these use cases. 

More info
Text goes here
X

Noah Dunn

Senior Security Automation Engineer 

Palo Alto Networks

Palo AlTo Networks Session

NOC Briefing Schedule

NOC Briefing #1 - Open to All Attendees

Wednesday, August 6 | 11:30 AM – 12:00 PM PT

Lagoon H, Level 2, MBCC

Wednesday, August 6⋅11:30 – 12:00

Lagoon H, Level 2, MBCC

NOC Briefing #2 - Open to All Attendees

Wednesday, August 6 | 5:35 PM – 5:55 PM PT

Business Hall Theater B, Business Hall, MBCC

Wednesday, August 6⋅17:35 – 17:55

Business Hall Theater B, Business Hall, MBCC

NOC Briefing #3 - Open to All Attendees

Thursday, August 7 | 11:30 AM – 12:00 PM PT

Lagoon H, Level 2, MBCC

Thursday, August 7⋅11:30 – 12:00

Lagoon H, Level 2, MBCC

NOC Briefing #4 - Open to All Attendees

Thursday, August 7 | 2:40 PM – 3:00 PM PT

Business Hall Theater B, Business Hall, MBCC

Thursday, August 7⋅15:15 – 15:35

Business Hall Theater B, Business Hall, MBCC

More info
Text goes here
X

James Holland

Sr Principal Engineer

Palo Alto Networks

Jason Reverri

Manager, Technical Product Engineer

Palo Alto Networks

NOC Briefing Schedule

Hours of Operation


NOC Visiting Hours (Surf EF, Level 2)


Saturday, August 1 – Thursday, August 6: 9:00 AM – 6:00 PM

 

NOC Presentations


Wednesday, August 5: 11:30 AM - 12:00 PM; 1:30 PM - 2:00 PM
Thursday, August 6: 10:30 AM - 11:00 AM; 1:30 PM - 2:00 PM

 

Live Stream Hours


The NOC will be streamed live via our Twitch channel too!

Saturday, August 1 – Thursday, August 6: 9:00 AM – 6:00 PM

Palo AlTo Networks Session

Inside Adversarial AI: Real-World Attacks and How to Stop Them 

Wednesday, August 6 | 10:15 AM – 11:05 AM PT

Mandalay Ballroom – J

Adversarial AI has super-charged cybercrime, letting even low-skill actors craft convincing deepfakes and run end-to-end campaigns at machine speed—often 10× faster than traditional methods. Drawing on insights from hundreds of Unit 42 incident-response engagements, our experts will unpack the latest AI-driven tactics across the attack chain and deliver field-tested defenses you can deploy now to stay ahead of accelerated threats.

More info
Text goes here
X

Michael Sikorski

CTO & VP Engineering Palo Alto Networks

Palo AlTo Networks Session

SHELLSILO

Thursday, August 7 | 10:00 AM – 10:55 AM PT

Business Hall, Arsenal Station 7

 While Windows System Calls have become a popular method for evading antivirus detection, they present considerable challenges beyond simple shellcode encryption/decryption. Unlike Linux, executing Windows System Calls often necessitates extensive setup, due to the need for specific C structures, which makes the code more complex and prone to errors compared to typical API calls. As a result, many developers turn to high-level languages like C to avoid the complexities of Assembly, particularly in malware development.

 

SHELLSILO addresses these challenges by offering an innovative solution for System Call shellcode generation.


More info
Text goes here
X

Tarek Ahmed

Staff Red Team Engineer

Palo Alto Networks

Palo AlTo Networks Session

Cloud Offensive Breach and Risk Assessment (COBRA)

Thursday, August 7 | 12:00 PM – 12:55 PM PT

Business Hall, Arsenal Station 8

Cloud Offensive Breach and Risk Assessment (COBRA) is an open-source tool designed to empower users to simulate attacks within multi-cloud environments, offering a comprehensive evaluation of security controls. By automating the testing of various threat vectors including external and insider threats, lateral movement, and data exfiltration, COBRA enables organizations to gain insights into their security posture vulnerabilities. COBRA is designed to conduct simulated attacks to assess an organization's ability to detect and respond to security threats effectively.

More info
Text goes here
X

Anand Tiwari

Manager, Product Management

Palo Alto Networks

Harsha Koushik

Technical Product Manager

Palo Alto Networks

Palo AlTo Networks Session

GDIOCSpider - Extracting and Identifying IOCs from the GDriveverse

Thursday, August 7 | 1:00 PM – 1:55 PM PT

Business Hall, Arsenal Station 2

Google Drive in recent years has become one of the most abused platforms for threat actors to conduct illegal and malicious activity. Threat actors use Google accounts to launch, store, and log malware, effectively turning Drive into a command and control center. On the side of legal and ethical activity, Google Drive remains a popular platform for security researchers to store these artifacts in summarized write-ups and spreadsheets of malicious and illegal activity observed. Much like an archaeologist looks for artifacts providing clues of the history of civilization, security researchers look for Indicators of Compromise (IOCs), which are clues to what a threat actor has done. Security engineers have worked across decades to build out tooling to analyze hard drives and network resources; however, similar advances to analyze Google Drive resources have remained underdeveloped. Along the same line, tools that aggregate and summarize collections of records on IOCs stored in Google Drive by researchers are also lacking.


The GDIOCSpider (Google Drive IOC Spider) provides a tool for both of these use cases. 

More info
Text goes here
X

Noah Dunn

Senior Security Automation Engineer 

Palo Alto Networks

Palo AlTo Networks Session

NOC Briefing Schedule

NOC Briefing #1 - Open to All Attendees

Wednesday, August 6 | 11:30 AM – 12:00 PM PT

Lagoon H, Level 2, MBCC

Wednesday, August 6⋅11:30 – 12:00

Lagoon H, Level 2, MBCC

NOC Briefing #2 - Open to All Attendees

Wednesday, August 6 | 5:35 PM – 5:55 PM PT

Business Hall Theater B, Business Hall, MBCC

Wednesday, August 6⋅17:35 – 17:55

Business Hall Theater B, Business Hall, MBCC

NOC Briefing #3 - Open to All Attendees

Thursday, August 7 | 11:30 AM – 12:00 PM PT

Lagoon H, Level 2, MBCC

Thursday, August 7⋅11:30 – 12:00

Lagoon H, Level 2, MBCC

NOC Briefing #4 - Open to All Attendees

Thursday, August 7 | 2:40 PM – 3:00 PM PT

Business Hall Theater B, Business Hall, MBCC

Thursday, August 7⋅15:15 – 15:35

Business Hall Theater B, Business Hall, MBCC

More info
Text goes here
X

James Holland

Sr Principal Engineer

Palo Alto Networks

Jason Reverri

Manager, Technical Product Engineer

Palo Alto Networks

More Info
Text goes here
X

Connect with us onsite

Experience a live demo:

Stop by the Palo Alto Networks Lounge at Azure right before you enter the Mandalay Bay Convention Center and learn more about the latest developments across the full Palo Alto Networks platform of security products.


Cortex: 

Autonomous Security Operations (XDR) & Real-Time Cloud Security (Cortex Cloud)


Unit 42:

Threat Intel, Incident Response, Cyber Risk Expertise, and Managed Services


NetSec:

Future of Frontier AI Network Security


Identity:

Next-Generation Identity Security


 

Schedule a meeting:

Want to take a deeper dive into what's next? Request a 1:1 meeting with one of our leaders or technical experts.


 

 

Here are a few topics our cybersecurity experts can cover, though we can tailor the conversation to any of your top security priorities:


- Preparing for Frontier AI-powered attacks

- The Future of Threat intelligence

- Understanding the Threat Landscape in the AI Era

- The New Unit 42 Threat Intelligence Services

- Modernizing the SOC

- Securing AI Across the Enterprise

- Building Cyber Resilience

- Protecting Identity in an AI-Driven World

- Reducing Cloud Risk

- Preparing For Your Next Cyber Crisis

 

Request a meeting
Text goes here
X

Location:

Azure at Mandalay Bay

From the Casino: Head towards the convention center. Make your way down the hall. Once you past Border Grill, Azure will be to the left side.


From the Convention Center: Head out past the food court. You will make your way towards the Casino. Azure will be to the right side.

Copyright © 2026 Palo Alto Networks. All rights reserved.

Privacy
Text goes here
X
Contact Us
Text goes here
X
Terms of Use
Text goes here
X
Link Text
Text goes here
X
Share with Friends
Facebook
Twitter
LinkedIn
CONTACT THE ORGANIZER
Google   Outlook   iCal   Yahoo
Sorry, RSVPs have closed.