Keynote | Red Team | Offensive Security Meets Vibe Coding

Keynote | Red Team | Offensive Security Meets Vibe Coding

🎙 Marcus J. Carey 👥 70K 📅 February 17, 2026 ⏱ 40 min 👁 296 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

vibe codingred teamAIautomationoffensive security

Summary

In this keynote from SANS Hack & Defend Summit 2025, Marcus J. Carey, Principal Research Scientist at ReliaQuest, discusses the intersection of AI and offensive security, coining the term ‘vibe coding’ to describe the use of AI to rapidly develop attack tools. He shares his personal journey from NSA to creating breach and attack simulation tools, emphasizing the importance of automation and learning to code. Carey demonstrates how he used AI tools like Claude Code and GitHub Copilot to build a ransomware and RAT platform for a customer, overcoming AI safety guardrails by breaking the task into ambiguous steps. He also recommends books and movies to understand AI, and highlights tools like Whisperflow, Comet, and NotebookLM for enhancing productivity. The talk concludes with a call for security professionals to embrace AI to stay ahead of adversaries.

136 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable insights into practical applications of AI in offensive security, with concrete examples and demonstrations. The speaker’s argumentation is persuasive, based on his extensive experience and successful projects. He effectively illustrates how AI can accelerate tool development and red team operations, and addresses potential concerns about safety and ethics. However, the argumentation relies heavily on anecdotal evidence and personal opinion, lacking systematic comparison or quantitative data.

Scientific Rigor, Source Quality, Title Accuracy

The talk is scientifically rigorous in terms of practical demonstrations, but lacks formal citations. The speaker references books and tools, but does not provide URLs or detailed sources. The title accurately reflects the content. The speaker’s credibility is high due to his background, but the lack of verifiable sources reduces the overall rigor. The talk is more of an expert opinion than a peer-reviewed study.

149 words

Title / Content Match

The title accurately reflects the content, which focuses on using AI for offensive security operations, specifically 'vibe coding'.

Quality & Reliability

7/10

The speaker is a seasoned security professional with extensive experience in red teaming and AI. The talk is based on personal experience and practical demonstrations, but lacks formal citations and rigorous scientific methodology. The information is plausible and aligns with current trends, but the reliability is moderate due to anecdotal evidence and lack of peer review.

Key Moments

Cited Sources

  • The Master Algorithm — Recommended book for understanding AI algorithms
  • The Fourth Age — Recommended book on AI and robotics
  • On Intelligence — Recommended book by Jeff Hawkins on neuroscience and AI
  • Her — Recommended movie on AI ethics
  • Ex Machina — Recommended movie on AI
  • Offensive Countermeasures — Book by John Strand and Paul Asadoorian that inspired HoneyDocks

Concurring Sources

  • AI and Cybersecurity: A New Era — SANS blog on AI in cybersecurity, aligns with the talk's themes.
  • The Rise of AI-Powered Cyber Attacks — CISA article on AI in cyber attacks, supporting the talk's claims.

Dissenting Sources

  • AI Safety Concerns in Offensive Tools — Raises concerns about the misuse of AI in offensive security, contrasting with the talk's positive view.

Contribution & Novelties

The talk provides a unique perspective on using AI for offensive security, coining ‘vibe coding’ and demonstrating practical applications. It offers a methodology for red teaming with AI and emphasizes the importance of understanding AI fundamentals. The speaker’s personal experiences and tool recommendations add practical value.

Pour aller plus loin :

81 words

Radar Profile

The radar profile shows high scores in quantity and quality of information, moderate technical level, and moderate reliability. This indicates a talk that is informative and practical but relies on anecdotal evidence rather than rigorous scientific methodology.

Reliability 6/10

💬 No comments were provided for analysis.