BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.coscup.org//coscup-2026//talk//EHKNXW
BEGIN:VTIMEZONE
TZID:CST
BEGIN:STANDARD
DTSTART:20000101T000000
RRULE:FREQ=YEARLY;BYMONTH=1
TZNAME:CST
TZOFFSETFROM:+0800
TZOFFSETTO:+0800
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-coscup-2026-EHKNXW@pretalx.coscup.org
DTSTART;TZID=CST:20260808T155000
DTEND;TZID=CST:20260808T163000
DESCRIPTION:Most AI pentesting systems start from the same idea: give a mod
 el a toolbox\, let it choose commands\, and hope the loop converges.\nOur 
 projects takes a different approach. It treats offensive security as a com
 mand-and-control problem\, not a prompt-engineering problem.\n\nOur projec
 ts is a source-available red-team command platform built around C5ISR situ
 ational awareness and the OODA loop.\nGiven an authorized target\, it coll
 ects structured facts through recon\, OSINT\, vulnerability lookup\, and 2
 3 MCP tool servers covering network\, AD\, and cloud attack\n\nThis talk w
 alks through the architecture and the lessons learned: fact schemas\, atta
 ck graph pathfinding\, tool routing\, scope validation\, risk gates\, nois
 e budgets\, failure classification\, and MCP-based execution boundaries.\n
 We show how the project moves from reconnaissance to failed initial access
 \, classifies the failure\, pivots to an exploit-based path\, and records 
 the full chain as structured evidence\, contrasting this with the open-loo
 p pattern common in tools like PentestGPT and hackingBuddyGPT.\n\nThe key 
 lesson is not that AI can "hack automatically." The lesson is that AI beco
 mes useful when it is constrained by doctrine\; explicit rules of engageme
 nt\, typed tool outputs\, human-visible decisions\, deterministic safety g
 ates\, and execution engines that can be audited or stopped.\n\nAttendees 
 leave with a practical blueprint for building safer AI-assisted offensive 
 tooling\, and a clear model for where LLMs belong in cyber operations: not
  as unchecked operators\, but as Orient-stage reasoning engines inside a c
 ontrolled command loop.
DTSTAMP:20260827T134752Z
LOCATION:TR313
SUMMARY:Building an OODA-Native Red Team Platform Where AI Commands the Kil
 l Chain - Chen Harry\, Alex Chih
URL:https://pretalx.coscup.org/coscup-2026/talk/EHKNXW/
END:VEVENT
END:VCALENDAR
