Loading…
OWASP 25th Anniversary Virtual Conference (September)
Audience: Advanced clear filter
Tuesday, September 22
 

1:15pm PDT

Rethinking how we evaluate security agents for real-world use
Tuesday September 22, 2026 1:15pm - 2:00pm PDT
Security agents are gaining momentum across industry, but the way we evaluate them remains rooted in narrow, outcome-only benchmarks. These evaluations tell us whether an agent produced a correct answer, but not “how” it arrived there or whether that behavior will remain stable once deployed.

In practice, enterprise security is not a sequence of isolated tasks. It is a connected, end-to-end workflow that follows a find → confirm exploit → patch → validate loop. Agents that perform well on task-specific benchmarks often fail in these multi-stage settings due to contextual loss and brittle transitions across steps.

This talk introduces a practical framework for evaluating security agents by mapping agentic capabilities (planning, reasoning, memory, perception, tool use) to security functions (reconnaissance, exploit confirmation, root-cause analysis, patching, validation) across the full lifecycle. We also share insights from our large-scale survey of existing agentic systems, highlighting which capabilities consistently drive success at each stage. Finally, we present a lightweight, unified end-to-end scoring perspective that teams can use to assess an agent’s readiness for real operational environments.
Speakers
avatar for Mudita Khurana

Mudita Khurana

Staff Security Engineer, Airbnb
Mudita Khurana is a Tech Lead at Airbnb, where she builds scalable security tooling and automation across the software development lifecycle. Previously at Meta, she drove key initiatives in product security, including bug bounty strategy, privacy-focused reviews, and automated vulnerability... Read More →
Tuesday September 22, 2026 1:15pm - 2:00pm PDT
  Testing

2:45pm PDT

The Sentinel-Aura Architecture: Orchestrating Agentic AI for Autonomous Endpoint Remediation
Tuesday September 22, 2026 2:45pm - 3:30pm PDT
As infrastructure grows beyond human scale, traditional manual patching is no longer a viable security posture. This session introduces a research-driven framework for Autonomous Infrastructure Healing.

Instead of treating security as a static checklist, we explore a model where the system functions as a self-correcting organism. By wrapping Microsoft Intune and Microsoft Entra with a custom Agentic AI orchestration layer, we can transform Windows 11 endpoints into self-healing assets. I will discuss the methodology of the "Red-to-Green" transition—using Automation and Agentic AI to interpret security telemetry and execute sub-60-second remediations without human intervention. This is a visionary look at how Microsoft Security Copilot and autonomous agents will redefine the future of the regulated workplace.
Speakers
avatar for Harshavardhan Malla

Harshavardhan Malla

Information Systems Security Engineer, Arizona Department of Transportation
Information Systems Security Engineer | Arizona Department of Transportation (ADOT) | Cloud Security & Compliance Automation | 3× Co-Founder (Digitailor)Harshavardhan Malla is an Information Systems Security Engineer at the Arizona Department of Transportation (ADOT), supporting... Read More →
Tuesday September 22, 2026 2:45pm - 3:30pm PDT
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.