Black Hat USA 2026: Practitioners Build Agentic AI Tools for Defense
At Black Hat USA 2026, security practitioners leveraged agentic AI to develop open-source defensive tools, aiming to democratize automation for common security tasks.

The landscape of cybersecurity is rapidly evolving, with agentic AI initially empowering attackers. However, Black Hat USA 2026 showcased a significant shift, as security practitioners harnessed the same technology to build powerful defensive tools. The inaugural SWARM event, hosted by Tenable, provided a platform for nearly 100 attendees to collaborate over 48 hours, focusing on practical applications of agentic AI to automate and streamline critical security operations.
The core takeaway from SWARM is the democratization of security automation. Previously, developing such tools required significant engineering expertise. Agentic AI, however, has lowered this barrier, enabling practitioners who deeply understand security pain points to build solutions without extensive coding knowledge. This initiative directly addresses the toil and repetitive tasks that consume security teams' time, such as vulnerability triage, cross-tool reconciliation, and prioritization.
All the tools developed at SWARM are now available on the CyberAgents Exchange, a repository for open-source agentic AI security tools. Each project includes its source code, allowing other teams facing similar challenges to leverage existing work rather than starting from scratch. This collaborative approach aims to accelerate the development and adoption of defensive AI, creating a compounding effect of innovation.
Examples of the practical tools built include an agent that prioritizes fixes based on the risk they mitigate across thousands of findings, another that correlates data from multiple scanners to determine exploitability, and a third that automates the process of documenting mitigations for audit purposes. These solutions tackle everyday problems that often go unaddressed due to resource constraints.
While keynotes at Black Hat USA 2026 focused on the declining cost of cyber offense due to agentic AI, the SWARM event highlighted the parallel rise in defensive capabilities. The event demonstrated that the same AI technologies enabling sophisticated attacks can also empower defenders to build robust automation. This empowers individuals who may not be traditional developers to create solutions for their specific operational needs.
The CyberAgents Exchange is positioned as a solution to the historical problem of defenders building in silos. Unlike offensive tools that often circulate and are iterated upon, defensive tools have traditionally been lost or rebuilt repeatedly. The exchange provides a centralized, open-source platform to share these innovations, closing a critical distribution gap for defensive cyber capabilities.
The SWARM event emphasized building "plumbing" rather than "robot analysts." The focus was on creating connective tissue that normalizes data across disparate security tools, wraps existing systems for agentic access, and packages recurring analyst tasks into reusable skills. This practical approach ensures that the developed AI agents address immediate, tangible needs within security operations, making them immediately deployable and valuable.
The initiative, sponsored by AWS with technical judging from Anthropic, underscores a broader trend: the need for accessible, practical AI solutions in cybersecurity. By enabling practitioners to build and share their own tools, SWARM and the CyberAgents Exchange are fostering a more resilient and efficient cybersecurity ecosystem, capable of keeping pace with evolving threats.