I’m excited to announce that we’re coming back to Black Hat SecTor 2026 in Toronto next month to demo OWASP Faction 2.0 in the Arsenal area! SecTor runs October 6–8 at the Metro Toronto Convention Centre, and we’ll be on the floor Thursday.
If you read my Black Hat post from earlier this summer, you already know how I feel about Arsenal — it’s my favorite part of any Black Hat event. It’s casual, it’s collaborative, and you get to talk directly with the people building the tools you’ll be using on your next engagement. SecTor has that same energy, just with a slightly smaller crowd, which honestly makes it even easier to strike up a conversation. If you’re on the introverted side like me, this is the place to be.
I’ll be presenting alongside Sandra Arber again this year, so between the two of us you should be able to get a demo without waiting in line. Come find us!
Save the date
OWASP Faction 2.0 at Black Hat SecTor Arsenal 2026
Thursday, October 8 at 11:30 AM – 12:50 PM (Eastern)
Arsenal, Business Hall, Station 4 — Metro Toronto Convention Centre
Want dedicated time?
Arsenal gets busy. If you’d rather sit down with us for a proper walkthrough or talk through your team’s workflow, grab a slot while we’re in Toronto.
What We’re Showing
We’ll have Faction 2.0 running live and ready to poke at. If you missed the announcement, 2.0 is a ground-up rewrite of the entire platform — modern frontend, modern backend, and a completely rethought approach to how security assessments should work. And it’s fully open source, as always!
A few of the things we’ll be walking through:
- AI where it actually helps. Context-aware AI in every text editor, global prompts you can share with your team, and an MCP server built into every assessment so your agents can read and write findings directly.
- Reporting that uses your existing DOCX templates. Drop Faction variables into the report you already use, upload it to the Report Designer, and you’re done. No rebuilding your template in a web editor.
- Application inventory and remediation workflow. Track owners, tech stacks, and vulnerabilities per application, and let app owners request retests right from their own dashboard.
- AI security controls. Tokenization of sensitive data before it hits an LLM, full audit logging, and support for self-hosted models so nothing leaves your network.
If you want the full rundown before the show, the Faction 2.0 release post goes through all of it with screenshots.
Stickers and Swag
We are bringing lots of stickers and swag this time. Last year we ran out faster than I expected, so I over-corrected. Come by the station, grab a handful, and cover your laptop in purple triangles.
Come Say Hi
The best ideas for Faction have always come from conversations at conferences like this one. At least two features in 2.0 started as hallway chats at Arsenal. So if you have a reporting workflow that drives you crazy, a tool you wish Faction integrated with, or you just want to see what the MCP server can do, come find us at Station 4 in the Business Hall on Thursday, October 8th from 11:30am to 12:50pm. If that window doesn’t work for you, book a meeting and we’ll find time during the conference.
For those who can’t make it to Toronto, you can find out more and download Faction at the links below.
- GitHub: https://github.com/factionsecurity
- Website: https://www.factionsecurity.com
- Docs: https://docs.factionsecurity.com
- OWASP: https://owasp.org/www-project-faction/
OWASP Faction is an open-source security assessment management platform designed for penetration testing teams who want to spend less time on reporting and more time finding vulnerabilities.