Resources
/
Event
News

Meet the Armadin Team at Fal.Con 2026

8.31.26
WRITTEN BY
Armadin
Meet the Armadin Team at Fal.Con 2026

Frontier AI has removed the core assumption nearly every security program was built on: that you have time to act between finding a vulnerability and an adversary acting on it. That exploit window has closed. Armadin is at Fal.Con 2026 to share what that change means for you, and what you can do about it.

You can no longer rely on point-in-time penetration testing or periodic assessments to know what your real risk is. Our mission is to replace assumptions with proof. We continuously run a relentless AI attacker against your entire attack surface, safely and across every domain, to produce validated evidence of what a bad actor could actually exploit.

But proving your risk and exposure is only half the job. Someone has to close the gaps, and that’s why we partner with CrowdStrike. We identify the exploitable path, and the Falcon platform is how you fix it.

Join us at Mandalay Bay in Las Vegas as a Gold Sponsor of Fal.Con. Our red team experts, AI builders, and security leaders will be onsite all week to discuss why offensive security is so critical in the AI era.

Request a Meeting with Us

Don’t miss your chance to get practical insights on how AI is transforming the speed, scale, and scope of offensive security in the world’s most critical enterprise environments.

Request a meeting at Fal.Con

Where to Find Us

We’re excited to participate in a wide range of activities during Fal.Con. Here are a few ways to connect with us:

Hands-On Workshop: Front Door to Vault with Armadin

Wednesday, Sep 2 | 3:45 PM - 5:15 PM PDT

In this session, you start with nothing but a seed domain. Ninety minutes later you have confirmed domain compromise, and you have pushed detections into a CrowdStrike tenant that prove the path is closed.

This is a working lab, not a walkthrough. Teams map an external attack surface, land a non-destructive Remote Code Execution (RCE), pivot inward through Falcon Real Time Response, and follow a delegation misconfiguration all the way to the Domain Controller. Then the sides switch, and teams push a compensating control and a detection into CrowdStrike and re-attack to prove both hold.

An RCE is not a proven path to what matters. Blast radius is proven, not assumed.

You will leave this session being able to:

  • Enumerate a full external attack surface from a seed domain, including shadow assets
  • Merge external surface and internal Active Directory topology into a single asset graph
  • Read that graph to find an abusable delegation path, and explain why the misconfiguration rather than the exploit is what reaches the Domain Controller
  • Push a control and a detection into CrowdStrike, then validate both by re-attack rather than assumption

This session is built for Security Operations Center (SOC) and blue team practitioners, detection engineers, incident responders, and Falcon administrators. Working familiarity with Falcon is expected. No exploit development experience is required.

Deflectors Up: Accelerating the Find-and-Fix Loop to Reach Autonomous Defense

Thursday, Sep 3 | 1:00 PM - 1:45 PM PDT

Give a defender a proven kill chain with the exact commands that make it work, and they will sever it in 24 hours. Not 90 days. Not next quarter. Proof collapses the argument and skips the triage queue.

But a 24-hour fix is still done at human speed, and it closes one chain at a time. AI-orchestrated offense finds kill chains continuously and in parallel, faster than any team can sever them by hand. That means the bottleneck has moved. It used to be about finding risk. Now it’s about fixing at the rate you discover risk.

This session covers that inversion:

  • Real chains walked end to end, showing how mitigating a single finding severs the entire path
  • Which human steps in the loop are judgment, and which are latency dressed up as process
  • Where automated remediation is safe, where it is not, and what verification looks like when nobody is reading every ticket

Autonomous defense is not an agent with root on your network. It’s a find-and-fix loop that severs chains as fast as they are built. You’ll leave this session being able to measure the gap between your discovery rate and your severing rate, with a staged path to closing it.

Why Meet with Armadin at Fal.Con?

In April, we announced a partnership with CrowdStrike to defend against AI-driven cyberattacks. In May, we joined Project QuiltWorks, CrowdStrike’s coalition for securing frontier AI risk.

The mechanics are straightforward. Armadin's AI attacker integrates with the Falcon platform to run safe, continuous agentic Hyperattacks across enterprise infrastructure, identity, and endpoints. Armadin surfaces what’s exploitable. CrowdStrike and its ecosystem of partners prioritize it and remediate it.

That process closes a critical loop most organizations still run by hand, on a quarterly cycle, against adversaries that never stop.

Want to Learn More?

Curious about what the Armadin platform can do for you? Explore now or request a demo.

Continue reading
PRTremote: Extract PRT Cookies Remotely with InteractiveToken Scheduled Tasks
Blog
8.26.26
PRTremote: Extract PRT Cookies Remotely with InteractiveToken Scheduled Tasks
The AI Red Team: “Inside Armadin” Episode 3
Podcast
Video
Blog
8.25.26
The AI Red Team: “Inside Armadin” Episode 3
Kill Chains and Coffee Episode 4: World’s Largest Controlled Hyperattack
Podcast
Blog
Video
8.19.26
Kill Chains and Coffee Episode 4: World’s Largest Controlled Hyperattack