COSCUP x UbuCon Asia 2026 Logo
  • About
  • Session
  • Transportation
  • Venue
  • Communities
  • Sponsors
    • Participate Guide
    • First Timer
    • Activity
    • Speaker Participation
    • Welcome Party
    • For Overseas Visitors
    • Open Source Communities
    • Sponsorship Partners
    • Invitation Letter Guide
  • Staff
  • Fringe Events / BoF
  • Blog
  • CoC
中文

Building an OODA-Native Red Team Platform Where AI Commands the Kill Chain

Time
2026-08-08 15:50 ~ 16:30
Speaker
Chen Harry, Alex Chih
Room
TR313
Co-write
https://hackmd.io/rJ1bJ4l8zg
Live Caption
https://rozeta.app/en/meetings/fTfySyWeL5/share
Hackers In Taiwan AdvancedMandarin

Abstract

Most AI pentesting systems start from the same idea: give a model a toolbox, let it choose commands, and hope the loop converges. Our projects takes a different approach. It treats offensive security as a command-and-control problem, not a prompt-engineering problem.

Our projects is a source-available red-team command platform built around C5ISR situational awareness and the OODA loop. Given an authorized target, it collects structured facts through recon, OSINT, vulnerability lookup, and 23 MCP tool servers covering network, AD, and cloud attack

This talk walks through the architecture and the lessons learned: fact schemas, attack graph pathfinding, tool routing, scope validation, risk gates, noise budgets, failure classification, and MCP-based execution boundaries. We show how the project moves from reconnaissance to failed initial access, classifies the failure, pivots to an exploit-based path, and records the full chain as structured evidence, contrasting this with the open-loop pattern common in tools like PentestGPT and hackingBuddyGPT.

The key lesson is not that AI can "hack automatically." The lesson is that AI becomes useful when it is constrained by doctrine; explicit rules of engagement, typed tool outputs, human-visible decisions, deterministic safety gates, and execution engines that can be audited or stopped.

Attendees leave with a practical blueprint for building safer AI-assisted offensive tooling, and a clear model for where LLMs belong in cyber operations: not as unchecked operators, but as Orient-stage reasoning engines inside a controlled command loop.

Speaker

Chen Harry

Chen Harry

網路中文資訊股份有限公司 資安部 紅隊主管

擁有 9 年以上紅隊演練與雲端安全實戰經驗。參與多項政府與企業級滲透測試與 APT 模擬。現專注於零信任架構與雲端資安防護,致力以攻擊者視角強化防禦策略。

Alex Chih

Alex Chih

七維思股份有限公司 資安暨雲端顧問

從事雲端、開發、資安等相關工作超過6年,專注於雲端安全與雲端原生技術。現負責雲端資安代管服務的策略制定與執行,亦協助多家企業提供資安架構與防護建議。

Diamond

Cumulative4 YrsCanonical

Gold

Consecutive2 YrsInformation Management AssociationConsecutive2 YrsCathay Financial HoldingsConsecutive5 YrsE.SUN BankCumulative13 YrsMySQLCumulative6 YrsBerry AINitra

Silver

Cumulative16 YrsGamesofa Inc.Cumulative3 YrsLinux Professional Institute

Bronze

Collaborator2 YrsKKTIXCumulative3 YrsNational Center for High-performance ComputingONLYOFFICECumulative6 YrsQNAP Systems, Inc.Consecutive16 YrsThe Archilife Research FoundationSUN SQUARE Co., LtdPenpeer

Friend

Consecutive3 YrsAndes Technology CorporationCumulative12 YrsAppierCumulative3 YrsGeode Labs & ETHTaipei

Special Thanks

Consecutive2 YrsDepartment of Information Technology, Taipei City GovernmentCollaborator3 YrsSiFive數位發展部Rozeta AIGrafana LabsLive YoungCollaborator5 YrsThree Wheel Nitro CoffeeCollaborator9 YrsHackmdCollaborator4 Yrs天瓏書局Collaborator3 YrsTapPayIndividual-Sponsorship

Co-host

Collaborator9 YrsNTUST - Department of Electronic and Computer Engineering

Co-organizer

Collaborator12 YrsOpen Culture Foundation

COSCUP x UbuCon Asia 2026

Conference for Open Source Coders, Users, and Promoters | Asia's largest open source community conference.

Contact

  • Attendee Services
  • Sponsorship
  • Call for Proposals
  • Marketing

Resources

  • COSCUP Blog
  • Newsletter Subscription
  • Event Photos

Sitemap

  • Home
  • About
  • Transportation
20062007200820092010201120122013201420152016201720182019202020212022202320242025