Security
DEF CON Through a Junior Pentester’s Eyes
An AHEAD Red Team Perspective

I recently came back from DEF CON, and I’ve been thinking about how different the experience felt this time.

The first time I went, I was overwhelmed by everything. There was so much knowledge, so much community, and so many different things happening at once. Every village felt like a new world. I was like a kid in a candy store, but I also left disappointed in myself because I realized I wasn’t prepared to retain everything I had seen and learned.

This time, I still felt overwhelmed — but it was different. I understood more of what I was looking at. I had a better idea of what questions to ask, what areas I wanted to focus on, and how the things I was seeing connected to my work as a junior pentester.

Before DEF CON

Before going, I expected DEF CON to be more centered around AI than my previous experience. AI has taken the world by storm, and it keeps evolving, so I expected to see it involved in offensive security, bug bounty work, and pentesting in general.

At the same time, I wanted to focus on a few areas that I knew I still needed to improve: AI security, web application security, and physical security. Web application testing was the biggest one for me. I feel like I can always improve in every part of pentesting, but web testing is a technical domain I specifically want to understand better.

I also wanted DEF CON to challenge one of my assumptions about pentesting: that a pentest can guarantee complete security.

It can’t. Complete security will never be guaranteed. A pentest is a point-in-time assessment, and it is based on what the tester can discover, validate, and safely demonstrate within the agreed scope. That doesn’t make the work less valuable. It makes it even more important to be honest about what a test can and cannot prove.

For me, a successful trip meant three things: making new connections, learning something useful, and bringing something home that could help me with real-world pentesting.

The Hallway Track Is a Real Part of the Conference

A lot of people go to conferences focused on talks, but some of the most memorable parts of DEF CON happened outside of formal presentations.

People talked about hacking, technology, innovation, and where the industry is going. People shared their own perspectives and experiences. I even ended up talking about fragrances with another DEF CON attendee. That conversation had nothing to do with pentesting, but it still captured what I liked about the conference: you can meet someone and immediately have a conversation about almost anything.

DEF CON is not just a place to collect technical information. It is a place to connect with people, share experiences, and evolve the way you think about technology.

The connections I made are probably the most useful thing I brought home. I made connections that could continue into next year’s DEF CON, and I also strengthened connections with current coworkers. I think those relationships will help me in the long run of my career more than any single tool or talk will.

AI Is Changing Offensive Security, But Manual Pentesting Is Not Gone

AI was one of the biggest differences I noticed compared with my previous DEF CON experience. It felt much more central to the conversation around offensive security.

One thing I kept thinking about was the evolution of the script kiddie. In the past, a script kiddie might use an existing tool or exploit without fully understanding how it worked. Now, someone with very little technical knowledge could potentially use an AI pentesting model to help attack or test a company.

I jokingly think of this as the rise of the “AI kiddie.”

That possibility is genuinely interesting, but it is also something security teams need to take seriously. AI can lower the barrier to entry, speed up reconnaissance, help analyze information, and make it easier for inexperienced people to attempt attacks. It may also help experienced pentesters move faster and explore more possibilities.

However, I don’t think that means manual pentesting is gone.

AI can help identify possibilities, but it still takes human judgment to understand context, validate an attack path, determine impact, and explain the risk clearly. A model may be able to suggest an attack, but that does not mean the attack is reliable, in scope, or meaningful to a client. Pentesting still requires curiosity, creativity, communication, and the ability to recognize when an automated result does not make sense.

The question is not whether AI will be used in pentesting. It already is. The better question is whether it will be used responsibly and whether pentesters will use it to improve their work instead of treating it as a replacement for understanding the fundamentals.

Pentesting is evolving. Whether it is evolving for better or worse will depend on how people use these tools.

The Areas Where I Still Need to Grow

DEF CON also showed me where I still have work to do.

I visited the AppSec Village and the Bug Bounty Village, and I could understand what was happening. But understanding the conversation is not the same as having strong practical skills. I realized that I need to spend more time actually practicing web application pentesting.

I also felt out of my depth in the Privacy Village. Privacy and operational security are areas I have wanted to learn more about, especially because hacking has become such a big part of my life. My coworkers have always encouraged me to have good OPSEC, and I have been trying to improve by using throwaway email addresses, limiting the personal information I share, and using a VPN when appropriate.

At the Privacy Village, I saw a company called Veiled that had created a peer-to-peer privacy framework for encrypted communications. The creator showed a badge-shaped node that contained a Linux server built into an LTE modem. I had never seen anything like it before, and I was honestly astonished that something like that was possible.

That experience reminded me that there will always be areas of security where I am still a beginner. Feeling out of my depth is not necessarily a bad thing. Sometimes it is the clearest sign that I found something worth learning.

What I’m Taking Back to My Team

The main thing I want my team to know is that pentesting is changing, especially with AI augmentation. Companies are beginning to use AI for pentesting, and some of them are doing impressive work. At least one company I saw was created by genuine pentesters and hackers rather than being built only around a business idea.

That does not mean manual pentesting is becoming irrelevant. It means the job is going to continue changing, and pentesters will need to understand both the tools and the fundamentals behind the work.

My action plan is simple:

  • Improve my web application pentesting skills.
  • Complete a Secure AI Home Assistant project.
  • Continue researching the evolution of script kiddies into “AI kiddies.”
  • Learn more about tools such as AD-Necromancer and consider how they fit into internal network testing.
  • Challenge the assumption that a company is secure just because a test did not find a problem.

Final Thoughts

I did not leave DEF CON knowing everything. I left with better questions, a clearer understanding of what I need to practice, and a stronger sense of where I can contribute.

For another junior pentester attending DEF CON for the first time, my advice would be to attend a few talks you are genuinely interested in. Don’t stress too much about missing everything. Many talks are recorded, and you can watch them later.

Connect with as many attendees as you can. DEF CON is not just a place to learn; it is a place to connect with the security community.

Finally, take it all in. It will probably feel chaotic, especially the first time. Take notes, absorb as much as you can, and give yourself permission not to remember every single detail.

The best thing I brought back from DEF CON was not one tool, one talk, or one flashy demonstration. It was a better understanding of where I am as a junior pentester, where I want to go next, and how much more there is to learn.

That feels like a pretty successful trip to me.

About the author

Gabe Terrazas

Associate Technical Consultant, AHEAD Red Team

Gabe is a security professional specializing in offensive security, application security, and security engineering. He currently performs penetration testing and red team assessments across web applications, networks, wireless environments, physical security, and emerging AI attack surfaces for enterprise and Fortune 500 organizations.

SUBSCRIBE

Subscribe to the AHEAD I/O Newsletter for a periodic digest of all things apps, opps, and infrastructure.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.