Episode 4

full
Published on:

2nd Jul 2025

HackTricks AI - The Ethical Cybersecurity AI Assistant with Carlos Polop

In this episode of the Security by Default podcast, host Joe Carson welcomes back cybersecurity expert Carlos Polop. They discuss Carlos's journey into the cybersecurity field, the creation and impact of HackTricks, and the role of AI in cybersecurity. Carlos shares insights on using large language models for hacking, the future of AI, and upcoming training courses.

The conversation emphasizes the importance of ethical hacking and the need for continuous learning in the rapidly evolving tech landscape.

Key Takeaways

  • HackTricks was created as a personal resource for learning and sharing knowledge.
  • The community has greatly benefited from HackTricks in their learning journeys.
  • AI is revolutionizing the field of cybersecurity and coding.
  • Large language models can assist in finding vulnerabilities and automating tasks.
  • It's important to ask the right questions when using AI tools.
  • Carlos is developing new training courses focused on cloud security and privilege escalation.
  • Hacktricks AI is designed to help users with specific cybersecurity queries.
  • The future of AI in cybersecurity is promising but requires ethical considerations.
  • Continuous learning and adaptation are crucial in the cybersecurity field.

Chapters:

  • 00:00 Introduction to Cybersecurity and Hacktricks
  • 02:54 The Journey into Hacking and OSCP
  • 05:54 The Impact of Hacktricks on the Community
  • 08:58 Recent Projects and Innovations in Cybersecurity
  • 12:00 The Role of AI in Cybersecurity
  • 14:57 Automating Code Creation with AI
  • 18:01 Future of Hacktricks and Upcoming Courses
  • 20:53 Final Thoughts on AI and Cybersecurity

Resources:

https://book.hacktricks.wiki/en/index.html

https://training.hacktricks.xyz/

https://www.hacktricks.ai/

https://github.com/peass-ng/PEASS-ng

Listen for free

Show artwork for Security by Default

About the Podcast

Security by Default
Security by Default is a cybersecurity podcast hosted by Joseph Carson, a renowned ethical hacker and security expert. Each episode dives into the latest security trends.
Security by Default is a cybersecurity podcast hosted by Joseph Carson, a renowned ethical hacker and security expert. Each episode dives into the latest security trends, real-world threats, and practical advice for staying safe in the digital world. With insightful interviews and clear explanations, Joseph makes complex topics accessible for both IT professionals and curious listeners alike.

About your host

Profile picture for Joseph Carson

Joseph Carson

I am a distinguished cybersecurity professional with over 30 years of experience in enterprise security and infrastructure.

Throughout my career, I have been an active contributor to the cybersecurity community, serving as an educator, ethical hacker, and speaker at global conferences. I hold both the Certified Information Systems Security Professional (CISSP) and Offensive Security Certified Professional (OSCP) certifications as well as advise various governments, critical infrastructure organizations, and industries such as finance and transportation on cybersecurity matters.
I am the author of "Cybersecurity for Dummies," a book that has gained global recognition for helping companies integrate people, processes, and technology to strengthen their defense against cyberattacks. The book has over 50,000 readers worldwide and provides a straightforward approach to understanding cybersecurity.

In addition to my writing, I have authored numerous articles and research papers, contributing to publications such as The Wall Street Journal, USA Today, Dark Reading, and CSO Magazine. I also host the bi-weekly podcast "Security by Default" which offers insights from leading cybersecurity experts and discusses best practices for navigating security challenges.
I am dedicated to educating the next generation of cybersecurity leaders and his commitment to building a safer internet have made him a respected figure in the cybersecurity community.