Speeding Up Vulnerability Triage: Automating Context Retrieval with AI Agents @FIRSTdotorg
Speeding Up Vulnerability Triage: Automating Context Retrieval with AI Agents  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 1 hour ago
Jorge Gimenez (Kraken, ES)

Modern vulnerability management suffers not from a lack of data, but from an overload of it. Security teams receive thousands of vulnerability findings from scanners, cloud platforms, and bug bounty programs, each providing fragmented and incomplete context. As a result, vulnerabilities are often evaluated in isolation, making triage slow and inconsistent and delaying remediation of issues that actually pose real risk. This talk presents a practical vulnerability triage enrichment process built around AI agents. Instead of treating findings as individual alerts, these agents aggregate all available context related to a detection. Each alert is expanded by examining how the code is written, where and how it runs, and whether the vulnerable functionality can realistically be reached. Bringing this information together into a single view helps analysts move faster and make more consistent risk decisions.

---

Jorge Gimenez is a Security Engineer at Kraken on the Vulnerability Management team, where he works on vulnerability triage, security automation, and risk prioritization at scale. Before joining Kraken, he worked as a red teamer focused on malware development and infrastructure hacking, a perspective he brings into his current role.
Speeding Up Vulnerability Triage: Automating Context Retrieval with AI AgentsPanel: Tips and Tricks to Run a CSIRT in Low-income and Fragile ContextsEngaging with the Media to Foster Cybersecurity ResilienceEvading in Plain Sight: How Adversaries Beat User-Mode Protection EnginesVulnrichment PlaygroundBenchmarking Your Constituency: A Practical Framework for CERTs with Results from Academic SectorBillions of Indicators, Zero Action: How We Fixed ThatCritical SaaS, Critical Blind Spots: A Detection Engineers Field Guide to SaaS AttacksThe Hidden Cost of CVEs: Can CSAF and VEX Change the Equation?The SOC Of The Future… The Future Is NowOne SOC, The Whole SOC, and Nothing But The SOC, So Help MeEiffel: A Tool to Oversee Incident Response From the Heights
FIRST |

Speeding Up Vulnerability Triage: Automating Context Retrieval with AI Agents

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER