AI-Powered Security Analysis: Generate meaningful VEX (Vulnerability Exploitability eXchange) docs
Event description
Join the Bendigo Tech Community as Ross Miles, senior software engineer at Microsoft, discusses AI-Powered Security Analysis with VEX Generation.
Traditional security scanning tools overwhelm teams with endless vulnerability alerts, flagging every potential issue without considering whether they pose a risk in your specific environment. This talk introduces an innovative approach combining automated security scanning with AI-powered exploitability analysis to generate industry-standard VEX (Vulnerability Exploitability eXchange) documents.
We'll explore how this automated workflow transforms vulnerability management from reactive CVE catalogue matching to proactive, evidence-based risk assessment through comprehensive code reachability analysis, attack surface mapping, and environmental protection evaluation. Through live demonstrations, we'll show how this system generates three key deliverables: executive summaries, detailed technical reports with remediation guidance, and OpenVEX-compliant documentation for transparent vulnerability communication. By shifting focus from vulnerability presence to actual exploitability, this methodology helps security teams allocate resources effectively, reduce alert fatigue, and build evidence-based security programs that address real risks rather than theoretical possibilities.
Key Takeaways: Practical implementation of AI-driven vulnerability analysis, OpenVEX standard adoption, and strategies for reducing security noise while improving risk assessment accuracy.
Who is Ross Miles?
Ross Miles is a seasoned software engineer with over 20 years of experience delivering cloud and enterprise solutions. He recently joined Microsoft as a Senior Software Engineer in Industry Solutions Engineering, where he works on building scalable, secure, and innovative systems that help customers solve real-world challenges.
His expertise includes .NET Core, Kubernetes, Azure, Docker, and modern front-end frameworks, with a strong background in cloud-native development, automation, and DevOps practices.
He's passionate about solving complex problems, sharing knowledge with his peers, and delivering software that makes a meaningful difference for businesses and industries.
Thank you to our regular sponsors, Ligantic: the essential emerging tech platform, from prototype to production.
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity