Building an Advanced LLM-Driven Vulnerability Scanning Pipeline for Your Code
Building an Advanced LLM-Driven Vulnerability Scanning Pipeline for Your Code
2 Day Dojo
Dates:
tbd
Attendance Type: In-PERSON only
Price includes 5% GST tax.
***The Dates of this training are still being decided.
Course Details
LLMs and classic SAST both find real bugs in your code. They also both produce noise, and they miss different things. This training is about building a pipeline that gets more out of each.
We start with why simple prompting underdelivers, then take SAST apart (sources, sinks, taint propagation) so you know where it misses and why. From there: using LLMs to improve SAST output, using context to improve LLM-driven scanning, and combining the two.
Then the hard part: cutting false positives with existing test frameworks, fuzzing harnesses, live test systems, and skeptical triage against source alone. We finish with remediation.
By the end of the training, you'll leave with a working pipeline design you can adapt to your own codebase and toolchain, not just a mental model of the ideas.
For more course details, please visit here.
Details last updated August 18, 2026
About the Instructor: Erlend Oftedal
Erlend Oftedal's long-standing professional focus is secure coding, application security, and software supply chain security, with hands-on depth in application security tooling, AI-assisted coding and security, and many years of traditional secure software development. He is a frequent speaker at developer and security conferences such as OWASP AppSec, SecAppDev and NDC conferences.
