Skip to content
FACTION
All posts

Black Hat 2025 Arsenal Experience

FACTION Security 4 min read
Black Hat Arsenal

I know this post is kind of late, but I’m just now getting around to posting about my Black Hat USA 2025 and SECTOR 2025 Arsenal experiences. For context, this is not my first time presenting at Black Hat Arsenal. I’ve built other open source projects that I presented at both Black Hat 2017 and 2018. I’ve been attending Black Hat on and off over the last 18 years now, and of all my Black Hat experiences, Arsenal is by far my favorite. Not only as a presenter but as an attendee.

What I like about Arsenal is that it gives you a chance to interact directly with open source developers from all different areas of tech and cyber. It’s a bit of a smaller forum, so it’s easier to interact with the presenters, and the interaction is generally encouraged. If you are on the introverted side (as I am) and looking for an environment that’s more casual to start up a conversation, then I think you would feel more at home in the Arsenal area. You will get to see some really impressive work by developers and have a chance to brainstorm with some very creative people. I’ve always left this area feeling inspired and bringing back new toolsets. These conversations have also made their way back into my own tools as well. At least two features in Faction have already been built based on lively conversations I had in Arsenal this year, and others are in the works!

Submitting Your Open Source Tools

If you’re developing an open source tool and are looking to get both feedback and to garner some attention, then you should be applying for Arsenal (and DEFCON DemoLabs as it has a similar format). To increase your chances of getting selected, my advice is to apply early. Look for when the Call for Tools is going live on the Black Hat site and apply the same day. They are going to ask you for a few things, so be ready to have this information before you apply. You will need your personal bio, a summary of your tool, a detailed description of your tool, and a public repo or site where they can learn more about your tool. Your tool should be easy to run and be functional before applying. When selected, they will ask you to do a recorded video to submit before the event. Below is an example of what you would expect to see when submitting a tool for Arsenal review for both Black Hat and SECTOR (the Canadian Black Hat).

If you are able to attend multiple Black Hats (e.g., USA, Asia, SECTOR), then keep these write ups handy because you can resubmit for the later conferences. There is probably a high chance that if you get selected for one, you would get selected for a later conference as well. At least that was my experience as I was selected for both Black Hat and SECTOR.

My Favorite Talks

I saw a lot of tools that were really impressive this year but I wanted to highlight a few that I found really interesting.

PromptFoo: This is an Open Source tool for finding weakness in LLM systems. Think of this tool as like SQLMap for LLM Prompts. It helps detect jailbreaking and issues with agentic AI. If you do pentesting on AI tools then I think this is a must have for your toolset.

ReARM — SBOM / xBOM Manager: This is an open source tool for managing SBOMs. It allows you to track product releases and associated Bills of materials. It shows vulnerabilities related to those SBOMS and translative dependencies.

FinBot Agentic AI CTF: This is an OWASP project that has built a vulnerable GenAI application that you can leverage attacks against and learn how to abuse agentic AI systems.

Arsenal Videos

Missed an Arsenal tool you wanted to see at Black Hat? You’re in luck! Most of the tools have a video available in the Black Hat Events App on iPhone and Android. You can go to the Arsenal section of the app and click on the event where you can view a pre-recorded video of the talk.

Final Thoughts

For regular Black Hat attendees who haven’t been over to the Arsenal, you’re totally missing out! You will level up on some cutting edge tools and it’s a great way to meet your fellow hackers. You may even have your ideas included in their tools and you might come back with ideas to build your own. It’s one of my favorite forums for collaborating with other technologists.

And finally, if you’d like to see my presentation at BlackHat Arsenal, you can view it here.

You can find out more about PenTesting with Faction at our website and try it for yourself on our github.

Originally published on Medium .

Keep reading

3 min read

See You at SecTor Arsenal 2026 in Toronto

We're heading back to Black Hat SecTor Arsenal on October 8th to demo OWASP Faction 2.0 live. Come say hi, grab some stickers, and tell us what would make your reporting workflow better.

FACTION Security
  • News
  • SecTor
  • Blackhat
6 min read

Releasing Faction 2.0 at BlackHat Arsenal 2026

I’m excited to announce that I’ll be returning to Black Hat Arsenal 2026 in Las Vegas and SecTor 2026 in Canada to demo OWASP Faction 2.0 — the biggest…

FACTION Security
  • Cybersecurity
  • Red Team
  • Pentesting