**Securing the Summit: Inside the Black Hat NOC’s AI-Driven Defense Operations**
In the heart of Las Vegas, behind a guarded door on the second floor of Mandalay Bay, lies the command center for one of the world’s most high-stakes cybersecurity events: the Black Hat network operations center (NOC). A wall of windows offers a glimpse into a high-tech war room where analysts, threat hunters, engineers, and researchers work around the clock to protect a network that more than 23,000 attendees connect to each year. While *The Creator* flickers on screen, the team diligently monitors alerts, using a blend of cutting-edge technology and expert intuition to defend a network that is constantly probed by some of the world’s most sophisticated hackers.
—
### The Team and Its Technology
When the NOC team arrives at Mandalay Bay, they essentially take over the venue’s entire network infrastructure, replacing every router, switch, firewall, and access point with their own technology. This is not done out of arrogance, but out of necessity. “We do that for a couple of reasons,” explained Neil “Grifter” Wyler, senior network operations lead at Black Hat and vice president of defensive services at Coalfire. “One is that we’re control freaks. But it’s also that with what happens on the network, if we need to do any type of mitigation, we can’t open a support ticket with the team at Mandalay Bay and wait 90 minutes. When something hits the fan — and it will — we have to be able to respond immediately.”
The scale of the operation has grown exponentially since Black Hat began more than two decades ago. Back then, the NOC consisted of just two teammates using open-source scripts and basic hardware to secure a conference with 1,500 attendees. Today, a team of over 100 professionals uses handpicked vendor products and homegrown tools to protect a network fifteen times larger, supporting more than 100 training classes with up to 100 students each.
The Black Hat NOC is named as such because the team’s primary role is to stand up infrastructure. “We set up this enterprise network in a very short period of time, and then we switch roles into security,” said James Pope, SOC lead for the Black Hat NOC and senior director of security product research and technical marketing engineer at Corelight. “We call it a NOC because if it’s not available, then there’s really nothing to secure. But once it’s available, then we have a lot of eyes on glass and a lot of security functions.”
Vendors are eager to donate products and personnel, giving the Black Hat NOC effectively an unlimited budget. Yet, the team remains focused on a single goal: ensuring the most secure operations possible. “These are not sponsors, they are partners we choose,” Wyler emphasized. “You cannot pay your way into the SOC.”
—
### The Challenge of Securing the Black Hat NOC
Black Hat’s NOC is unique in both its resources and its target profile. While most security operations hunt for a “needle in a haystack,” Black Hat’s team searches for “a needle in a needle stack.” The network sees massive volumes of traffic — around 285 million informational alerts during this year’s event — which the team whittles down to 17.1 million potential threats. Of those, only 383 are blocked as actual malicious attempts.
Much of the traffic is inherently hostile, but at Black Hat that is expected. The real challenge comes from distinguishing legitimate hacking exercises and research activity from genuine threats. These “Black Hat positives” are often expected behaviors from training sessions and researcher demonstrations.
When anomalies do appear, the team treats them as outliers — the core of threat hunting. “That’s the key to threat hunting. It’s a game of outliers,” Wyler said. For example, if a single threat actor tries to exploit the network, the team zooms in, collects data such as IP and MAC addresses, and builds a profile. If the activity is illegal — which happens a dozen or so times each year — the team intervenes directly.
> “We have a 100% success rate at identifying people on the network based on their traffic and where they work. We take that, tie it into the registration database and often find the individual,” Wyler explained. Most of the time, the issue ends with a warning: “Doing illegal things at Black Hat is still illegal,” and the activity stops.
—
### AI in the NOC
AI dominates conversations at Black Hat, and the NOC is no exception. “Everybody’s running around going, ‘AI, AI, AI,’” Wyler said, “and we’re like, ‘That’s adorable. We’ve been using AI for years.’”
While the team uses AI for traditional functions like alerting, they quickly discovered that commercial tools couldn’t handle the scale or speed required for the conference. As a result, they developed their own solutions. In 2024, they created FragglePacket, a Rust-based network diagnostic tool enhanced with AI to add 71 new features, including attack path probing, packet fuzzing, PCAP replay, and staged HTTPS analysis. “At this point, this thing is a full-on network troubleshooting monster,” Wyler said.
The NOC also employs AI-driven agents such as Trevor, an AI chatbot that integrates with Palo Alto’s security operations platform to assist with threat hunting and incident response. This year, they introduced NOCgentic, a multiagent LLM platform that routes analyst questions to specialists, queries logs and telemetry, and delivers clear answers and next-step guidance. SOCgentic — described as “NOCgentic with the training wheels off” — powers an interface nicknamed Postcog, inspired by the precogs in *Minority Report*. It helps identify problematic behaviors before they escalate.
Importantly, the team insists that AI will not replace human analysts. “There’s always a human in the loop,” Wyler noted. AI acts as a force multiplier, making experienced professionals more efficient rather than replacing them.
—
### The Future Black Hat NOC
While AI-powered threats remain a concern, Wyler noted that they are currently noisy and rarely stealthy, often tripping deception technologies such as canaries and honeypots. Still, as attackers refine their methods, the NOC will need to evolve. “Our greatest line of defense is the fact that they trip every wire,” he said.
Looking ahead, the Black Hat NOC — with its unlimited resources, cutting-edge tools, and elite talent — is well-positioned to tackle the cybersecurity challenges of 2027 and beyond. As the threat landscape continues to shift, this unique operation will remain a benchmark for security excellence in the cybersecurity conference world.
—
### FAQ
**Q: What is the Black Hat NOC?**
The Black Hat Network Operations Center (NOC) is the command center that secures the network for the Black Hat cybersecurity conference. It replaces all network infrastructure on-site and operates a highly secure, scalable environment for thousands of attendees.
**Q: How many people does the Black Hat NOC team consist of?**
The team has grown to more than 100 members, a significant increase from its early days of just two or three people.
**Q: Why does Black Hat build its own network instead of using the hotel’s?**
The team takes over the network to ensure full control, eliminate reliance on external support, and enable rapid response to threats or disruptions.
**Q: How does the NOC handle threats during the conference?**
The team monitors hundreds of millions of alerts, filters out expected “positive” behaviors from training and research, and investigates outliers. Known malicious actors are identified through traffic analysis and often removed with a direct warning.
**Q: What role does AI play in the NOC?**
AI is used throughout the NOC, from alert triaging to custom-built tools like FragglePacket and AI agents such as Trevor and NOCgentic, which assist with threat hunting, log analysis, and analyst support.
**Q: Will AI replace human analysts at Black Hat?**
No. The team emphasizes that AI works alongside humans, enhancing their capabilities rather than replacing them. A human always remains in the loop, especially for critical decisions.
—
### Conclusion
The Black Hat NOC represents the pinnacle of cybersecurity event defense — a dynamic, AI-enhanced operation built for speed, scale, and precision. With unlimited vendor support, a team of elite experts, and a culture of innovation, the NOC not only protects one of the cybersecurity world’s most important conferences but also sets a standard for threat detection and response. As attacks grow more sophisticated, the combination of human expertise and advanced technology ensures that Black Hat remains a step ahead of those looking to exploit the event.



