From Crash to Code Execution: Inside an AI-Assisted PLC Exploit Port
About This Session
Forescout’s Vedere Labs set out to answer a practical question: how effectively can today’s AI tools help an experienced researcher adapt a working exploit from one industrial device to another?
This technical session walks through the team’s experiment porting a remote code execution exploit for CVE-2021-31886 from a WAGO 750-852 PLC to the related WAGO 750-831. The presentation will examine the research workflow, including the use of Claude Code, Ghidra, firmware analysis, live probing, and direct access to the physical PLC.
Rather than focusing on AI hype, the session will explore what actually happened during the experiment: where the AI identified useful paths, where it pursued incorrect assumptions, what technical context researchers had to provide, and how the team progressed from simply crashing the PLC to achieving controlled code execution.
The session will also examine the subsequent attempt to extend the exploit into a command-and-control implant, which ultimately resulted in a bricked device, along with the time, cost, and level of human expertise required throughout the process.
Attendees will leave with a clearer understanding of the current capabilities and limitations of AI-assisted exploit development and what increasing automation of this work could mean for industrial device manufacturers, OT security researchers, and defenders as similar techniques become easier to scale across related devices.
This technical session walks through the team’s experiment porting a remote code execution exploit for CVE-2021-31886 from a WAGO 750-852 PLC to the related WAGO 750-831. The presentation will examine the research workflow, including the use of Claude Code, Ghidra, firmware analysis, live probing, and direct access to the physical PLC.
Rather than focusing on AI hype, the session will explore what actually happened during the experiment: where the AI identified useful paths, where it pursued incorrect assumptions, what technical context researchers had to provide, and how the team progressed from simply crashing the PLC to achieving controlled code execution.
The session will also examine the subsequent attempt to extend the exploit into a command-and-control implant, which ultimately resulted in a bricked device, along with the time, cost, and level of human expertise required throughout the process.
Attendees will leave with a clearer understanding of the current capabilities and limitations of AI-assisted exploit development and what increasing automation of this work could mean for industrial device manufacturers, OT security researchers, and defenders as similar techniques become easier to scale across related devices.
Speaker
Sai Molige
Forescout Technologies Inc
Sai Molige, also known as Cyb3rhawk, is Senior Manager of Threat Hunting at Forescout Technologies, where he leads threat hunting research, incident response, and adversary infrastructure operations. His work focuses on understanding attacker behavior and translating threat intelligence into practical, repeatable approaches for threat hunting and detection engineering.
Sai has held cybersecurity roles at Comcast and Snap Inc. and has extensive experience investigating ransomware, advanced threat activity, exploitation campaigns, and threats spanning IT, IoT, and operational technology environments. He is an active security researcher and community contributor who regularly publishes technical research and shares practical methodologies for threat hunting, detection engineering, DFIR, and cyber threat intelligence.
Sai has held cybersecurity roles at Comcast and Snap Inc. and has extensive experience investigating ransomware, advanced threat activity, exploitation campaigns, and threats spanning IT, IoT, and operational technology environments. He is an active security researcher and community contributor who regularly publishes technical research and shares practical methodologies for threat hunting, detection engineering, DFIR, and cyber threat intelligence.
