COSCUP x UbuCon Asia 2026 標誌
  • 關於我們
  • 議程
  • 交通
  • 會場地圖
  • 社群
  • 贊助夥伴
    • 參與指南
    • 第一次參與
    • 活動參與
    • 講者參與
    • 前夜派對
    • 海外參與者
    • 開源社群、攤位及議程軌
    • 贊助夥伴
    • 邀請函申請指南
  • 工作人員
  • 周邊活動 / BoF
  • 部落格
  • 社群守則
English

Building an OODA-Native Red Team Platform Where AI Commands the Kill Chain

時間
2026-08-08 15:50 ~ 16:30
講者
Chen Harry, Alex Chih
位置
TR313
共筆
https://hackmd.io/rJ1bJ4l8zg
即時字幕
https://rozeta.app/en/meetings/fTfySyWeL5/share
Hackers In Taiwan 進階中文

議程簡介

Most AI pentesting systems start from the same idea: give a model a toolbox, let it choose commands, and hope the loop converges. Our projects takes a different approach. It treats offensive security as a command-and-control problem, not a prompt-engineering problem.

Our projects is a source-available red-team command platform built around C5ISR situational awareness and the OODA loop. Given an authorized target, it collects structured facts through recon, OSINT, vulnerability lookup, and 23 MCP tool servers covering network, AD, and cloud attack

This talk walks through the architecture and the lessons learned: fact schemas, attack graph pathfinding, tool routing, scope validation, risk gates, noise budgets, failure classification, and MCP-based execution boundaries. We show how the project moves from reconnaissance to failed initial access, classifies the failure, pivots to an exploit-based path, and records the full chain as structured evidence, contrasting this with the open-loop pattern common in tools like PentestGPT and hackingBuddyGPT.

The key lesson is not that AI can "hack automatically." The lesson is that AI becomes useful when it is constrained by doctrine; explicit rules of engagement, typed tool outputs, human-visible decisions, deterministic safety gates, and execution engines that can be audited or stopped.

Attendees leave with a practical blueprint for building safer AI-assisted offensive tooling, and a clear model for where LLMs belong in cyber operations: not as unchecked operators, but as Orient-stage reasoning engines inside a controlled command loop.

講者

Chen Harry

Chen Harry

網路中文資訊股份有限公司 資安部 紅隊主管

擁有 9 年以上紅隊演練與雲端安全實戰經驗。參與多項政府與企業級滲透測試與 APT 模擬。現專注於零信任架構與雲端資安防護,致力以攻擊者視角強化防禦策略。

Alex Chih

Alex Chih

七維思股份有限公司 資安暨雲端顧問

從事雲端、開發、資安等相關工作超過6年,專注於雲端安全與雲端原生技術。現負責雲端資安代管服務的策略制定與執行,亦協助多家企業提供資安架構與防護建議。

鑽石級

累計贊助4 年Canonical

黃金級

連續贊助2 年中華民國資訊經理人協會連續贊助2 年國泰金融控股公司連續贊助5 年玉山銀行累計贊助13 年MySQL累計贊助6 年華捷智能股份有限公司Nitra

白銀級

累計贊助16 年慧邦科技股份有限公司  Gamesofa Inc.累計贊助3 年Linux Professional Institute

青銅級

累計合作2 年華娛網路娛樂股份有限公司累計贊助3 年財團法人國家實驗研究院國家高速網路與計算中心ONLYOFFICE累計贊助6 年QNAP Systems, Inc. 威聯通科技連續贊助16 年祐生研究基金會源鋼技術顧問有限公司 SUN SQUARE Co., Ltd醫知彼

好朋友級

連續贊助3 年晶心科技股份有限公司累計贊助12 年沛星互動科技股份有限公司累計贊助3 年Geode Labs & ETHTaipei

特別感謝

連續贊助2 年臺北市政府資訊局累計合作3 年美商賽發馥股份有限公司臺灣分公司Ministry of Digital AffairsRozeta AIGrafana Labs麗陽商場【台灣科技大學活動中心第一餐廳】累計合作5 年三輪行動咖啡氣泡飲累計合作9 年Hackmd累計合作4 年天瓏書局累計合作3 年TapPay個人贊助

共同主辦單位

累計合作9 年臺灣科技大學 電子工程系

協辦單位

累計合作12 年開放文化基金會

COSCUP x UbuCon Asia 2026

Conference for Open Source Coders, Users, and Promoters | 亞洲最大開源年會,由社群自發舉辦。

聯絡我們

  • 會眾服務
  • 贊助合作
  • 議程投稿
  • 行銷方案

相關資源

  • COSCUP 部落格
  • 訂閱電子報
  • 活動照片

網站導覽

  • 首頁
  • 關於我們
  • 交通資訊
  • 贊助夥伴
20062007200820092010201120122013201420152016201720182019202020212022202320242025