Palo Alto Networks at Black Hat USA 2025
Sep 
19th
–
Sep 
21st
Join Us
Text goes here
X
Link Text
Text goes here
X

10:30 AM – 10:45 AM

Unify code to cloud insights to accelerate secure development with Cortex Cloud & Semgrep 

Orion Cassetto + Semgrep SME

10:30 AM – 10:45 AM

Unify code to cloud insights to accelerate secure development with Cortex Cloud & Semgrep 

Orion Cassetto + Semgrep SME

Palo Alto Networks NextGen Summit
Register here
Text goes here
X
Register
Text goes here
X
Overview
2024 Recap
Agenda
Hosts
Entertainment
Venue

Palo Alto Networks at
Black Hat USA 2025

August 6 - 7 | Mandalay Bay Convention Center | Las Vegas, NV

Request a meeting
Text goes here
X

We've got next: 

Experience AI-powered security at Black Hat.

We've got next: 

Experience AI-powered security at Black Hat.

At Palo Alto Networks, innovation is behind everything we do. We’re committed to pushing boundaries to relentlessly deliver what’s next in cybersecurity, especially when it comes to AI. And there's no better place than Black Hat to unveil our latest AI-powered advancements and industry-leading solutions.


Get your pass and connect with us.

Register for Black Hat
Text goes here
X

Use code PAN to save $200 on a briefing pass or $100 on a business hall pass.

Palo Alto Networks Sessions

Palo AlTo Networks Session

Inside Adversarial AI: Real-World Attacks and How to Stop Them 

Wednesday, August 6 | 10:15 AM – 11:05 AM PT

Mandalay Ballroom – J

Adversarial AI has super-charged cybercrime, letting even low-skill actors craft convincing deepfakes and run end-to-end campaigns at machine speed—often 10× faster than traditional methods. Drawing on insights from hundreds of Unit 42 incident-response engagements, our experts will unpack the latest AI-driven tactics across the attack chain and deliver field-tested defenses you can deploy now to stay ahead of accelerated threats.

More info
Text goes here
X

Michael Sikorski

CTO & VP Engineering Palo Alto Networks

Palo AlTo Networks Session

SHELLSILO

Thursday, August 7 | 10:00 AM – 10:55 AM PT

Business Hall, Arsenal Station 7

 While Windows System Calls have become a popular method for evading antivirus detection, they present considerable challenges beyond simple shellcode encryption/decryption. Unlike Linux, executing Windows System Calls often necessitates extensive setup, due to the need for specific C structures, which makes the code more complex and prone to errors compared to typical API calls. As a result, many developers turn to high-level languages like C to avoid the complexities of Assembly, particularly in malware development.

 

SHELLSILO addresses these challenges by offering an innovative solution for System Call shellcode generation.


More info
Text goes here
X

Tarek Ahmed

Staff Red Team Engineer

Palo Alto Networks

Palo AlTo Networks Session

Cloud Offensive Breach and Risk Assessment (COBRA)

Thursday, August 7 | 12:00 PM – 12:55 PM PT

Business Hall, Arsenal Station 8

Cloud Offensive Breach and Risk Assessment (COBRA) is an open-source tool designed to empower users to simulate attacks within multi-cloud environments, offering a comprehensive evaluation of security controls. By automating the testing of various threat vectors including external and insider threats, lateral movement, and data exfiltration, COBRA enables organizations to gain insights into their security posture vulnerabilities. COBRA is designed to conduct simulated attacks to assess an organization's ability to detect and respond to security threats effectively.

More info
Text goes here
X

Anand Tiwari

Manager, Product Management

Palo Alto Networks

Harsha Koushik

Technical Product Manager

Palo Alto Networks

Palo AlTo Networks Session

GDIOCSpider - Extracting and Identifying IOCs from the GDriveverse

Thursday, August 7 | 1:00 PM – 1:55 PM PT

Business Hall, Arsenal Station 2

Google Drive in recent years has become one of the most abused platforms for threat actors to conduct illegal and malicious activity. Threat actors use Google accounts to launch, store, and log malware, effectively turning Drive into a command and control center. On the side of legal and ethical activity, Google Drive remains a popular platform for security researchers to store these artifacts in summarized write-ups and spreadsheets of malicious and illegal activity observed. Much like an archaeologist looks for artifacts providing clues of the history of civilization, security researchers look for Indicators of Compromise (IOCs), which are clues to what a threat actor has done. Security engineers have worked across decades to build out tooling to analyze hard drives and network resources; however, similar advances to analyze Google Drive resources have remained underdeveloped. Along the same line, tools that aggregate and summarize collections of records on IOCs stored in Google Drive by researchers are also lacking.


The GDIOCSpider (Google Drive IOC Spider) provides a tool for both of these use cases. 

More info
Text goes here
X

Noah Dunn

Senior Security Automation Engineer 

Palo Alto Networks

Palo AlTo Networks Session

NOC Briefing Schedule

NOC Briefing #1 - Open to All Attendees

Wednesday, August 6 | 11:30 AM – 12:00 PM PT

Lagoon H, Level 2, MBCC

Wednesday, August 6⋅11:30 – 12:00

Lagoon H, Level 2, MBCC

NOC Briefing #2 - Open to All Attendees

Wednesday, August 6 | 5:35 PM – 5:55 PM PT

Business Hall Theater B, Business Hall, MBCC

Wednesday, August 6⋅17:35 – 17:55

Business Hall Theater B, Business Hall, MBCC

NOC Briefing #3 - Open to All Attendees

Thursday, August 7 | 11:30 AM – 12:00 PM PT

Lagoon H, Level 2, MBCC

Thursday, August 7⋅11:30 – 12:00

Lagoon H, Level 2, MBCC

NOC Briefing #4 - Open to All Attendees

Thursday, August 7 | 2:40 PM – 3:00 PM PT

Business Hall Theater B, Business Hall, MBCC

Thursday, August 7⋅15:15 – 15:35

Business Hall Theater B, Business Hall, MBCC

More info
Text goes here
X

James Holland

Sr Principal Engineer

Palo Alto Networks

Jason Reverri

Manager, Technical Product Engineer

Palo Alto Networks

Booth #3240

Theater Sessions

Wednesday, August 6

10:30 AM – 10:45 AM

Unify code to cloud insights to accelerate secure development with Cortex Cloud & Semgrep

Orion Cassetto + Semgrep SME

11:15 AM – 11:30 AM

Break Through SIEM Limits—Reimagine Your SOC with AI

Brian Chew

11:30 AM – 11:45 AM

2025 Global IR Report: What Attackers Are Doing and How to Stop Them

Salina Wuttke

12:30 PM – 12:45 PM

Break Through SIEM Limits - Reimagine Your SOC with AI

Brendan Powers

1:00 PM – 1:15 PM

Deloitte Partner Session: AI Factory as a Service

 

Paul Sukhu, Managing Director, Deloitte

1:30 PM – 1:45 PM

AT&T Partner Session: AT&T Dynamic Defense with Palo Alto Networks

 

AT&T

2:00 PM – 2:15 PM

2025 Global IR Report: What Attackers Are Doing and How to Stop Them

Adrian Diaz

2:45 PM – 3:00 PM

Break Through SIEM Limits—Reimagine Your SOC with AI

Brendan Powers

3:00 PM – 3:15 PM

Secure the Future of Work

TBD

3:30 PM – 3:45 PM

Break Through SIEM Limits—Reimagine Your SOC with AI

Orion Cassetto + Semgrep SME

4:00 PM – 4:15 PM

Unifying Code, Cloud, and SOC for Real-time Cloud Security

Todd Walker

4:45 PM – 5:00 PM

Stop Zero Day Threats with Precision AI Technology

Akhil Nune

5:00 PM – 5:15 PM

Map the Cyber Galaxy with Unit 42

Kathi Whitbey

5:15 PM – 5:30 PM

Introducing CLARA: Cloud Network & AI Risk Assessment

TBD

Thursday, August 7

10:30 AM – 10:45 AM

Map the Cyber Galaxy with Unit 42

Kathi Whitbey

11:00 AM – 11:15 AM

Securing the Industrial Edge with Palo Alto Networks Prisma AIRS on NVIDIA BlueField & Siemens Industrial Automation DataCenter

TBD

11:30 AM – 11:45 AM

Unifying Code, Cloud, and SOC for Real-time Cloud Security

Erick Moore

12:30 PM – 12:45 PM

2025 Global IR Report: What Attackers Are Doing and How to Stop Them

Salina Wuttke

1:00 PM – 1:15 PM

IBM Partner Session: Accelerating SOC operations with Agentic AI

Orion Cassetto + Semgrep SME

1:30 PM – 1:45 PM

Zero Networks Partner Session: Layered Defense with Palo Alto Networks and Zero Networks: From Gateway to Workload

Kyndryl

2:00 PM – 2:15 PM

Zero Networks Partner Session: Layered Defense with Palo Alto Networks and Zero Networks: From Gateway to Workload

Partner/Net/Sec: Zero Networks

2:45 PM – 3:00 PM

2025 Global IR Report: What Attackers Are Doing and How to Stop Them

Adrian Diaz

3:00 PM – 3:15 PM

Break Through SIEM Limits—Reimagine Your SOC with AI

Emily Duncan

3:15 PM – 3:30 PM

T-Mobile Partner Session: Zero Trust, Zero Gaps: SIM-Based SASE for the Next Generation T-Mobile Network

Orion Cassetto + Semgrep SME

Connect with us onsite

Experience a live demo:

Stop by booth #3240 and learn more about the latest developments across the full Palo Alto Networks platform of security products.

Schedule a meeting:

Want to take a deeper dive into what's next? Request a 1:1 meeting with one of our leaders or technical experts.

Request a meeting
Text goes here
X

Copyright © 2026 Palo Alto Networks. All rights reserved.

Privacy
Text goes here
X
Contact Us
Text goes here
X
Terms of Use
Text goes here
X
Link Text
Text goes here
X
Share with Friends
Facebook
Twitter
LinkedIn
Link
CONTACT THE ORGANIZER
Google   Outlook   iCal   Yahoo

RSVP

Google Icon
Google
Outlook Icon
Outlook
Apple Icon
Apple
Yahoo Icon
Yahoo