3 Black Hat USA 2026 Sessions Every Threat Intelligence Professional Should Attend


Black Hat USA isn't just where the cybersecurity industry gathers. It's where many of the ideas shaping tomorrow's security operations are first shared.
With hundreds of briefings, Arsenal demonstrations, and technical sessions packed into a single week, deciding what deserves your time can be challenging.
If you're a threat intelligence analyst, threat hunter, SOC leader, or detection engineer, we've narrowed it down to three sessions worth adding to your schedule. Together, they highlight one of the biggest shifts happening in cybersecurity today: using AI to help security teams investigate faster, build better detections, and understand attacks with greater context.
1. CrowdSentinel: AI-Orchestrated Threat Hunting Across Unified Security Data Sources
Wednesday, August 5 | 12:30 PM to 1:00 PM | Arsenal Station 5
Security teams aren't struggling because they lack data. They're struggling because the data lives in too many places.
Threat hunters routinely jump between SIEMs, packet captures, endpoint logs, and detection libraries while trying to piece together a single investigation. Every context switch adds time, and every manual query increases the risk of missing something important.
CrowdSentinel tackles this challenge by using AI orchestration and the Model Context Protocol (MCP) to bring multiple investigation tools together behind a natural language interface.
Instead of manually querying different platforms, analysts can ask a single question that simultaneously searches logs, correlates network traffic, and evaluates thousands of detection rules.
During this live Arsenal demonstration, Thomas Xuan Meng will showcase threat hunting against real APT datasets, explain the MCP architecture behind the platform, and provide attendees with a CI/CD-ready deployment.
Why attend
If you're interested in how AI agents can reduce investigation time while keeping analysts in control, this is one of the most practical demonstrations to attend at Black Hat.
2. From Prompts to Pipelines: Building Agentic Detection Engineering and Threat Hunting
Wednesday, August 5 | 11:05 AM to 11:45 AM | Oceanside B, Level 2
Many security teams have experimented with generative AI to write detection rules.
The problem is that prompting alone rarely produces production-ready detections. Outputs can be inconsistent, hallucinate logic, or fail to reflect an organization's environment, leaving analysts to spend valuable time reviewing and correcting AI-generated code.
This session explores what comes after prompt engineering.
Roblox engineers Shoufu Luo and Zhenda Hu will demonstrate how they evolved from simple prompting to agentic workflows with structured orchestration, deterministic control planes, and human approval built into every stage.
Attendees will learn how to:
Break detection engineering into specialized AI agents.
Build feedback loops that improve detection quality.
Apply branching and scoring strategies to detection design and threat hunting.
Design reliable LangGraph-based agent workflows with governance and oversight.
Why attend
If you're evaluating how AI fits into detection engineering beyond the hype, this session offers a practical blueprint grounded in real-world implementation.
3. Command Line Threat Analyzer
Thursday, August 6 | 12:30 PM to 1:30 PM | Arsenal Station 7
Attackers rarely rely on a single malicious command.
Modern intrusions often unfold through long sequences of seemingly legitimate commands that, when viewed individually, appear harmless. Traditional detection tools frequently miss the broader attack narrative because they evaluate commands in isolation.
Command Line Threat Analyzer (CLTA) takes a different approach.
Instead of analyzing commands one at a time, it reconstructs the sequence of activity, correlates related behavior over time, and visualizes how individual actions fit into a larger attack chain.
During this session, Rohit Mukherjee will demonstrate how analysts can use behavioral context and command relationships to uncover attack patterns that conventional command-level detection often misses.
Why attend
Understanding attacker behavior, not just individual alerts, is becoming increasingly important as threat actors adopt stealthier techniques. This session offers a practical look at contextual analysis in action.
A Common Theme Across All Three Sessions
Although these sessions cover different areas of security operations, they all point to the same industry shift.
AI is moving beyond being a productivity assistant. It's becoming an operational layer that helps security teams investigate faster, build detections more efficiently, and connect fragmented intelligence to meaningful decisions.
For threat intelligence professionals, the opportunity isn't simply adopting AI. It's understanding where AI genuinely improves analyst workflows while ensuring human expertise remains central to decision-making. These three sessions offer an excellent glimpse into what the future of AI-powered security operations may look like.
Connect with Cyware at Black Hat USA
If you're attending Black Hat USA 2026, we'd love to meet you.
Connect with the Cyware team to discuss how AI-powered threat intelligence, contextualization, and operationalization can help security teams move from collecting intelligence to taking action faster.
Book a meeting with Cyware today.
About the Author
