Loading…

Thursday September 10, 2026 8:00am - Friday September 11, 2026 5:00pm CDT
Limited Capacity seats available
With the explosive adoption of AI agents, corporate networks are experiencing a massive influx of programmatic and shadow AI usage. Unfortunately, default audit capabilities provided by major AI vendors are notoriously sparse, leaving defenders with little to no visibility. Many providers only organize logging in a "billing forward" manner rather than focusing on cybersecurity. 


This 2-day, hands-on training workshop equips security teams with the practical skills needed to detect, audit, and secure AI usage within their environments. Attendees will learn how to identify shadow AI usage from existing network and endpoint logs (such as Zeek and Sysmon) without needing increased vendor visibility. Because AI tooling is ultimately just software, we will also explore how these tools can introduce vulnerabilities, such as unauthenticated servers allowing local execution.


Furthermore, the course will move beyond basic logs to explore advanced visibility techniques. Attendees will learn how to use OpenTelemetry to extract detailed insights from major AI providers that support it, and how to deploy LLM proxies to actively intercept and inspect AI activity and tool calls. Finally, we will dive deep into the Model Context Protocol (MCP), a protocol specifying how AI apps integrate with external tools, and demonstrate the severe risks of malicious integrations via the "Evil MCP" vector.

Prerequisites: Linux terminal or powershell
Trainers
avatar for Corey Thuen

Corey Thuen

Founder, Gravwell
Corey Thuen is the CEO and Co-Founder of Gravwell, an analytics platform built for massive-scale security telemetry. With over a decade of experience across IT, IoT, and ICS/OT security, he brings a unique, attacker-informed perspective to cyber defense. Previously, Corey was a vulnerability... Read More →
Thursday September 10, 2026 8:00am - Friday September 11, 2026 5:00pm CDT
Microsoft Technology Center (Aon Center)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link