Beyond SAST: An Analyst's Guide to Agentic Code Scanning and AI SAST
On-demand Release: September 24th at 1:00 pm ET
Security teams adopting AI-assisted code review have inherited a set of questions no application security program was designed to answer: frontier model or an affordable one, every commit or nightly, every repo or just the crown jewels.
Join Devin Maguire (Cycode) alongside James Berthoty (Latio Tech) for a practical breakdown of the AI-SAST landscape: what deterministic scanning still does best, where agentic reasoning earns its cost, and how to decide which one runs where instead of picking one and living with the gaps. We’ll walk through Cycode’s benchmark results, including two authorization CVEs that no rule engine could catch, found on an affordable open-weights model rather than a frontier one.
The session will cover:
- Deterministic vs. agentic, and when each wins - where rules stay fast and reproducible, and where they structurally can't reach.
- The real cost math of agentic scanning - why frontier reasoning on every commit doesn't scale
- Why findings don't stay isolated - how low and medium severity issues chain together into critical exploit paths, and what that means for how you prioritize fixes.
Presented by:
Get Access
Sign up to be notified when this webinar is released on-demand.