BSides Toronto 2025

AI Agents: Your New Security Team Members or Biggest Threat?
2025-10-04 , ENG 103

AI agents are revolutionizing cybersecurity - but are they friend or foe? These autonomous systems can detect threats faster than human analysts, but they're also being weaponized by attackers for sophisticated social engineering and automated exploitation. This talk examines both sides of the AI agent coin through real-world examples and live demonstrations.

You'll see how AI agents can enhance your security operations, automate incident response, and improve threat hunting. But we'll also explore how adversaries are using AI agents for targeted phishing, automated vulnerability exploitation, and bypassing traditional security controls. We'll cover practical implementation strategies for defensive AI agents and detection techniques for malicious ones.

No theoretical frameworks or vendor pitches - just actionable insights from implementing AI agents in enterprise security programs and defending against AI-powered attacks. You'll leave with practical knowledge to either deploy AI agents in your security operations or better defend against them.


This presentation draws from hands-on experience implementing AI agents in enterprise security environments and analyzing emerging AI-powered attack techniques. The talk addresses the growing reality that AI agents are becoming standard tools in both offensive and defensive cybersecurity operations.

The presentation is structured around the dual nature of AI agents in cybersecurity, providing practical examples of both beneficial and malicious applications. All content is based on real-world implementations, actual attack scenarios, and lessons learned from deploying AI agents in production security environments.

The defensive portion covers successful AI agent implementations for threat detection, incident response automation, and security operations enhancement. The offensive analysis examines documented AI-powered attack techniques, including automated social engineering campaigns, adaptive malware, and AI-driven reconnaissance tools.

Live demonstrations will include setting up a basic security AI agent, analyzing AI-generated phishing attempts, and showing detection techniques for identifying AI-powered attacks. All tools and techniques demonstrated are open-source or freely available, ensuring attendees can experiment with the concepts immediately.

A Solutions Engineer specializing in Cybersecurity, Cloud and DevOps Engineering. Always looking to learn, share knowledge and impact positively via Information Technology.