How Mandiant Orchestrates Gemini to Find Zero-Days Before Adversaries
Tuesday, September 15, 2026, 1:00 PM - 1:45 PM
Atrium Ballroom A

To outmaneuver modern adversaries, defenders need a structural advantage. Manual source code review is too slow, and legacy SAST tools lack the contextual awareness needed to find complex logic flaws.


In this session, we explore how Mandiant modernized vulnerability discovery by leveraging Google’s Gemini as a force multiplier for defenders. We will detail the internal architecture Mandiant uses to safely and effectively audit massive codebases without falling victim to the context-window overload common in early AI tooling.


Rather than relying on universal bug-finding prompts that fail in production, we built a highly constrained pipeline. We will walk attendees through our methodology of deploying specialized agents for targeted analysis, coupled with an adversarial validation phase that forces the AI to aggressively try and invalidate its own alerts.
This is a practical look at how Mandiant does AppSec in the AI era. Attendees will leave with a clear understanding of how to harness Gemini’s capabilities to structurally filter out noise and proactively secure their own environments.