
Reclassify the Target
We take a live AI application and stop looking at it as an AI application. You map where the model's output goes and which of those destinations is privileged.




Twenty-five years of offensive security don't stop counting because the target has a model in it. What makes these systems exploitable isn't the model — it's that its output reaches privileged actions without ever being treated as input. Same sinks you've tested your whole career, one source nobody sanitizes. In four hours, on a live agent, you'll point your existing methodology at it and watch it work.


You didn't fall behind. You were handed a new target class that nobody gave you a method for, so you did the reasonable thing: prompt injection threads, an open-source LLM scanner, a saved list of jailbreaks, the OWASP LLM Top 10.
None of it made the next engagement easier, because all of it is the same thing — The Jailbreak Collection, the belief that AI security is a growing pile of clever prompts you accumulate. The prompt that works this week dies with the next model update, and no client pays for a trick with an expiration date.
What actually breaks these systems is duller. Everyone files the model as a component — something that computes, like a library or a service. It isn't. A model is a stranger typing into your application, and everything it emits is user input that nobody labeled as user input. Call it Model as Input. Output reaches a shell command: command injection. A database call: SQL injection. A rendered page: XSS. A file write, an internal API, an MCP tool call — the same sinks you've been testing your whole career, reached through the one source nobody sanitizes.
That's why four hours is enough. You're not learning a new discipline, you're deleting an exclusion. And you'll know it worked before the afternoon is over, when the agent in front of you executes something it was never supposed to execute.




You use every one of them inside the session or in the 48 hours after it. Nothing here waits for a course to finish — you're on a live target from the first hour.

One page each. The Sink Map, the Agent Recon Card, the Finding Write-Up Template and the 48-Hour Script — all filled in against a real target, not read about.

One page. Every place a model's output lands — shell, database, browser, filesystem, internal API, another agent — and the test you already know for each.

The questions for the first twenty minutes of an AI engagement: what the agent can call, what runs without a human, where the trust boundary was supposed to be.

One finding, one page. Turns “I got it to do something weird” into impact, reproduction and business risk — the version a client pays for.

What to do Monday morning on the AI target sitting in your queue. Order of operations, in one page, so the method leaves the session with you.
Nobody gave you a method for this target class, so the afternoon is built as one: reclassify the target, reach the sink, break the agent, write the finding. You leave with all four done, not described.

We take a live AI application and stop looking at it as an AI application. You map where the model's output goes and which of those destinations is privileged.

The model isn't the vulnerability; it's the delivery mechanism. We drive output into the places that act on it, working through the sinks in order of what pays.

An agent with tool access — function calling, an MCP server, an autonomous loop. You find the tool it shouldn't have been allowed to call, and you make it call it.

Impact in language a client acts on, reproduction steps that survive a model update, and where this sits in a report. Then the 48-hour script.
A jailbreak is a trick with an expiration date: it works this week and dies with the next model update, and no client pays for it. Model as Input is a rule that doesn't expire — everything the model emits is unsanitized user input reaching sinks you already know how to test. Same methodology, one exclusion deleted.
A saved list of clever prompts that dies with the next model update.
A method that runs again on a system you've never seen.
Each block ends with something finished. Nothing is left as homework.
We take a live AI application and stop looking at it as an AI application. You map where the model's output goes and which of those destinations is privileged — the moment “chatbot” turns back into a system you already know how to test.

The model isn't the vulnerability; it's the delivery mechanism. We drive output into the places that act on it and watch what happens when nobody sanitized it, working through the sinks in order of what pays.

This is where the event earns its name. An agent with tool access — function calling, an MCP server, an autonomous loop — not a chat window. You find the tool it shouldn't have been allowed to call, and you make it call it.

The part nobody teaches. Impact in language a client acts on, reproduction steps that survive a model update, and where this sits in a report. Then the 48-hour script: exactly what you do on Monday.

Four working tools. You use every one of them inside the session or in the 48 hours after it.

One page. Every place a model's output lands in a real system — shell, database, browser, filesystem, internal API, another agent — and the test you already know for each one. You fill it in during the first hour, against a live target.

The questions you ask in the first twenty minutes of an AI engagement to find where tool access actually lives.

One finding, one page. Impact, reproduction and business risk — the version a client reads and pays for.

What to do Monday morning on the AI target sitting in your queue right now. Order of operations, in one page.
Four hours, hands on keyboard, on the same live agent environment as everyone else in the room.
Not watching a demo — the lab is open the whole four hours and you're in it.
Tool access, MCP, autonomous loops. Not a chatbot in a browser tab.
When your test doesn't land, you find out why on Saturday instead of guessing about it on a client engagement.
So the first AI finding you show a client isn't the one you learned on.
The MCP server your client runs, the scope you were just handed, the target you're already stuck on.
Small enough that you can say “I'm lost at step three” out loud.
Saturday, 4:59 PM

The first AI target I had to test wasn't a client's. It was ours — a customer-facing assistant at the fintech where I run security. Twenty-five years in, and I got it producing code it had no business producing, then sat there with a finding I couldn't write up properly and no idea how to test the next one. Everything I had was a pile of prompts that worked that week.
Then I built the other side: agents with tool access, MCP servers wired into live security platforms. Once I saw what a model's output could actually execute, it stopped being a chatbot problem and became application security again. That's where Model as Input came from, and it's what I teach now — labs, live sessions, and a CTF where people break agents themselves.
I'm still testing real AI systems, which is the only thing that keeps the method honest.
MIT Cyber Security · CISSP · CISM · CRISC · C|CISO · CEH · C|RAGE

The price is low on purpose. Nobody in this room is short the money — you're short a method, and I'd rather the only question you ask yourself be whether the Saturday afternoon is worth it. It is. You'll have a finding by the end of it.
It isn't free because free events fill up with people who register and never show. This one doesn't work if you're not at the keyboard: you're breaking a live agent, writing up what you found, and getting it corrected in the room. Twenty-seven dollars filters for people who actually turn up, and everything about the session is built for people who turn up. The price exists to protect the room, not to pay for it.
Saturday, October 24, 2026 · 1:00 PM – 5:00 PM ET (10:00 AM – 2:00 PM PT) · Live online, closed room on Zoom
No. You need to have tested web applications. The whole premise is that the sinks are the ones you already know — shell, SQL, XSS, file writes, internal APIs — reached through a source nobody sanitizes. If you've never tested a web app, this is the wrong room.
No, and that's the point. A jailbreak is a trick with an expiration date. Model as Input is the rule that everything a model emits is unsanitized user input reaching a privileged action. You'll use injection as a delivery mechanism, not as the finding.
The price is low on purpose and it isn't free on purpose. Free events fill with people who register and never show, and this session doesn't work if you're not at the keyboard. Twenty-seven dollars filters for people who turn up. It protects the room, it doesn't pay for it.
The audience is experienced testers who were handed a target class without a method. Nothing in the four hours re-teaches you injection. What changes is the classification of the model, the recon questions for tool access, and the write-up that turns a weird behavior into paid impact.
That's what Block 4 and the 48-Hour Script exist for: impact in language a client acts on, reproduction steps that survive a model update, and exactly what to do Monday morning on the AI target already sitting in your queue.
Saturday afternoon you'll map a real AI target as an ordinary attack surface, drive model output into something that executes, break a live agent with tool access, and write the whole thing up as a finding a client would pay for — reviewed before you close your laptop.
You leave with the vulnerability, the write-up, the four tools, and a method that runs again on the next system you've never seen.