Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Advent of Cyber and AI-assisted AppSec training: what changes for teams?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Security professionals can get hands-on web security practice across web attack forensics, IDOR exploitation, cURL-based request crafting, and web log analysis through Advent of Cyber, according to PortSwigger. The takeaway for practitioners is that AI can accelerate AppSec workflow, but it does not replace the need for human judgment, request-level understanding, and careful evidence handling, while BurpAI is positioned as an aid for validation and repetition.

NHIMG editorial — based on content published by PortSwigger: PortSwigger x TryHackMe: Supporting Advent of Cyber Hassan Ud-Deen

Questions worth separating out

Q: How should AppSec teams use AI tools without losing control over findings?

A: Treat AI as an assistant for repetition, suggestion, and formatting, not as the decision-maker.

Q: Why do request manipulation skills still matter in web application testing?

A: Because many access-control flaws only become visible when you change a request and compare the application’s response.

Q: How do teams know whether AI-assisted AppSec is actually helping?

A: Look for findings that can be traced back to named components, repeated across assessments, and mapped to concrete remediation actions.

Practitioner guidance

  • Strengthen request-level testing discipline Build lab and production testing routines that require testers to inspect, edit, replay, and compare HTTP requests before a finding is accepted.
  • Define human sign-off for AI-assisted findings Set a rule that AI-generated payload suggestions, summaries, or variations may accelerate testing, but a human must confirm exploitability, scope, and business impact before remediation tickets are raised.
  • Use challenge-based training to close skill gaps Incorporate hands-on exercises on web attack forensics, IDOR exploitation, and log analysis so teams can connect attack behaviour to defensive controls and evidence handling.

What's in the full article

PortSwigger’s full post covers the practical event support and Burp Suite workflow detail this post intentionally leaves for the source:

  • The prize package details, including 5 Burp Suite Professional licences with BurpAI and 100 certification exam entries.
  • The specific Advent of Cyber challenge categories mapped to web testing skills, including web attack forensics and IDOR exploitation.
  • The explanation of how BurpAI is positioned to help validate findings, shape payloads, and reduce repetitive manual work.
  • The broader context behind PortSwigger’s view of AI as an everyday part of the pentester toolkit.

👉 Read PortSwigger’s note on AI-assisted AppSec learning and Advent of Cyber →

Advent of Cyber and AI-assisted AppSec training: what changes for teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

AI-assisted testing is becoming a workflow accelerator, not a substitute for security judgment. PortSwigger’s framing reflects a wider shift across AppSec: automation can shorten the time to iterate, but it cannot decide whether a finding is real, exploitable, or material. The practitioner still owns validation, context, and remediation priority. The durable lesson is that AI should support testing throughput while preserving human accountability.

A question worth separating out:

Q: What should security teams do to build practical AppSec skills?

A: Use guided labs and realistic attack exercises that force people to inspect traffic, reason about application behaviour, and explain why a control failed. The best training makes practitioners prove they understand the path from request to impact, because that is what real testing and incident review require.

👉 Read our full editorial: PortSwigger’s Advent of Cyber support underscores AI-assisted AppSec training



   
ReplyQuote
Share: