Threat Research & Intelligence

Hallways Over Booths: Reflections from Black Hat 2026

Black Hat 2026 is starting to look a lot like RSA. The marketing spend is wild, the AI messaging blurs together, and the disconnect from actual practitioners is real. But the hallways? Still worth showing up for.

August 7, 20264 min read
MagicSword team member posing in front of the Black Hat logo wearing a dark t-shirt that reads "Reduce the attack surface before the attack surface reduces you" - photographed from behind at Black Hat 2026.

The best part of Black Hat is still the hallway con. Everything else is secondary.

Just seeing folks, greeting them, catching up, getting introduced to new people. That was honestly my favorite pass of the whole con. So many amazing people in this industry. Keeps me hopeful the mission continues and there’s still a chance to push back on the snake oil.

blackhat 2026
The real conference.

Black Hat is starting to feel a lot like RSA. Marketing spend is wild. Disconnect from the actual practitioner base is real. AI solution messaging all blends together. Hard to tell what half these vendors actually do. A lot of products are still hunting product market fit but somehow still dropping $100k on a booth. Wild.

Had a friend who’s a 20+ year veteran and director at an MDR tell me he wants out of the industry. Burned out on the snake oil. Wants to move into traditional business. That one made me sad. We’ve burned out people like this. Market dynamics reward the big shiny splash more than the substance. I keep hearing from folks leaving Microsoft that it’s a sales machine first. Get the bundles sold. Engineering often happens after the sale. Not saying there aren’t extremely talented people there, but the business optimizes for profits over outcomes. Hence the microslop and whole products that exist just to clean up after poor execution. Nobody can argue with the market cap though. Gravity of Microsoft is real.

Blog image
Still good to run into people doing real work.

Under the noise AI there was a signal. EDRs are table stakes now and are also clearly not silver bullets and actively getting disrupted. Attackers keep proving it with BYOVD and RMM abuse. Detection alone keeps leaving the same issues to fester. More people are finally saying it out loud, a ton of talk around machine speed and how things now need to be prevented instead. VCs are placing bets on what comes next. Companies like ent.ai, glow.ai, neo.ai getting attention shows the market is starting to acknowledge the gap too. 

Ent booth at BlackHat 2026 Secure work, understand intent
One of the clearer messages on the floor this year.

A few things actually stood out. Firemon config management, mainly because it is old school but still useful and effective. I did not see any AI theater, it was very refreshing. They also had a cigar roller as swag. As a Cuban I was genetically obligated to stop by that demo! Mimic looked interesting as an idea. ThreatLocker had solid demos and the fact that they were giving away free rubber duckies its a premium tier level swag. Airlock Digital had some new feature for agents and stopping them before they burn a ton of tokens. Cool idea! Crogl’s UI and workflow have clearly matured over the last few years. It's always nice to see a product like that show real progress and maturing given the AI SOC its such a muddled category.

The OpenAI and Hugging Face talk definitely got a ton of attention, worth watching on youtube if you couldn’t catch it at the conference like me.

The Black Hat NOC is still one of my favorite parts of the show. I’d push that even more front and center. Almost like more of the conference should feel like a bigger version of it. Just tools actually running, analysts you can talk to, data to nerd out on. Why don’t we have more of this?

Blog image
This is the energy more of the conference should have.

A few open source projects that stood out this week if you want something useful:

Arsenal

  • RedTeamSimmer – Web based adversary emulation and Atomic Red Team orchestration. Clean UI that finally makes running and coordinating Atomic tests feel approachable.
  • BadZure – Spins up misconfigured Entra ID / Azure labs with realistic attack paths. Great for purple teaming without burning days on setup.
  • Brutus – Modern multi-protocol credential testing tool in Go. Zero dependency single binary. Feels like a proper Hydra replacement.

Outside Arsenal

  • Numbat (Perplexity) – Endpoint visibility into AI agent activity with local detection and optional pre-action blocking. Very timely right now.
  • Pretty-Policy-Analyzer – Load, browse, compare and audit GPO backups without needing a domain controller. Super practical if you live in Windows environments.

Arsenal is still one of the best parts of the show for the same reason the NOC is, also it doesn’t feel too long since I was showcasing my own projects there. Real tools, people who built them, and you can usually walk away with something usable.

Had to leave before Defcon this year. I'm already looking forward to next year. Maybe skip Black Hat instead. Left craving more practitioner content honestly.

Blog image
Still the best shirt on the floor.


The people in the hallways are still why I keep showing up.

Jose Hernandez

Written by

Jose Hernandez

Threat Researcher

Jose Enrique Hernandez formed and served as the Director of Threat Research at Splunk. Jose is known for creating several security-related projects, including: Splunk Attack Range, Splunk Security Content, Git-Wild-Hunt, Melting-Cobalt, lolrmm.io and loldrivers.io. He also works as a maintainer to security industry critical repositories such as Atomic Red Team and lolbas-project.github.io.