BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: CyberKB: When Your AI Copilot Runs the Recon\, Crawl
 s the Dark\n   Web\, and Maps the Kill Chain\n   Tags: Recon Village | Cre
 ator Talk/Panel\n   When: Saturday\, Aug 8\, 17:00 - 17:30 PDT\n   Where: 
 LVCCW Level 1 Hall 3 801 (Creator Stage 2) - [1]Map\n\n   Description:\n\n
    What if your recon tool could understand "find leaked credentials for\n
    this company on the dark web\, cross-reference with their exposed\n   i
 nfrastructure\, and show me the attack path" — and then actually do\n   
 it\, autonomously\, with zero manual commands? CyberKB is a 214\,000-line\
 n   open platform that puts an AI copilot (Keke) in command of 131\n   off
 ensive tools spanning reconnaissance\, dark web OSINT\, Shodan\n   intelli
 gence\, breach databases\, and a full Kali Linux shell — all\n   orchest
 rated through natural language conversation. The Dark Web\n   Intelligence
  Pipeline (DarkMonitor): CyberKB's DarkMonitor module\n   queries .onion s
 earch engines concurrently through Tor\, uses\n   LLM-powered query refine
 ment to generate optimal dark web search\n   terms\, applies AI relevance 
 filtering to surface the most critical\n   results.\n\n   The AI Copilot (
 Keke): Keke isn't a wrapper around ChatGPT. It's a\n   function-calling ag
 ent with direct execution access to: a privileged\n   Kali container (nmap
 \, curl\, nikto\, sqlmap\, gobuster\, hydra — the\n   full toolkit)\, 16
  dark web search engines via Tor\, breach and paste\n   database aggregato
 rs\, a RAG-powered knowledge base with semantic\n   search over ingested r
 econ data\, Shodan lookups and CVE correlation\,\n   MITRE ATT&CK techniqu
 e mapping\, attack graph generation and path\n   prioritization\, and enga
 gement management (targets\, credentials\,\n   findings\, reports).\n\n   
 Scale Proof — 2\,250-Domain Assessment: We demonstrate CyberKB\n   again
 st a real-world external attack surface assessment: 2\,250 domains\n   bel
 onging to a single organization\, producing 11\,968 unique IPs\, 8\,494\n 
   hostnames\, 2\,444 CVEs\, 80\,238 open ports\, and a knowledge graph of\
 n   6\,390 nodes with 51\,990 infrastructure relationship edges. The entir
 e\n   dataset was parsed\, correlated\, and ingested into the AI-queryable
 \n   knowledge base in 25 seconds. Keke can now answer questions like\n   
 "which x domains share infrastructure with known-vulnerable IPs" by\n   se
 arching the graph\, not by re-scanning.\n\n   What This Means for Defender
 s: Every autonomous recon step Keke\n   performs leaves detectable artifac
 ts. We discuss what blue teams\n   should monitor: DNS burst patterns from
  multi-engine enumeration\, Tor\n   exit node correlation with target infr
 astructure\, behavioral\n   signatures of AI-driven sequential probing\, a
 nd how to distinguish\n   human recon from autonomous agent recon. The sam
 e platform that\n   empowers red teams reveals the detection surface that 
 defenders can\n   leverage.\n\n   Key Takeaways: 1. AI copilots with direc
 t tool execution compress\n   hours of reconnaissance into minutes of conv
 ersation — fundamentally\n   changing the operator's role from command e
 xecutor to strategic\n   decision-maker. 2. Dark web OSINT can be systemat
 ically automated with\n   LLM-driven search refinement and relevance filte
 ring\, making it\n   accessible beyond specialized analysts. 3. Infrastruc
 ture-scale attack\n   surface mapping (2\,250+ domains) becomes practical 
 when AI handles\n   correlation instead of humans. 4. Autonomous recon cre
 ates detectable\n   patterns that blue teams should be actively hunting fo
 r. Tool Stack:\n   Python\, Flask\, ChromaDB (RAG)\, Docker (Kali + Tor + 
 Browser Agent)\,\n   OpenAI-compatible LLM API\, SQLite\, Playwright\, Bea
 utifulSoup. 105\n   Python modules. Fully self-hosted — no cloud depende
 ncies for core\n   functionality.\n\n   Speakers:Suriya Prasath S\,Chandru
  J\,Muthu Kumar\n\n   SpeakerBio:  Suriya Prasath S\, zoho\, red teamer\, 
 manager\n\n   A Red Teamer and Security Manager at Zoho CRM–Red Team\, w
 ith 6+\n   years of experience driving adversarial simulations and real-wo
 rld\n   attack emulation at scale. He focuses on uncovering critical secur
 ity\n   gaps by thinking like an attacker—blending deep technical expert
 ise\n   with practical red team operations to challenge assumptions and\n 
   strengthen defences.\n\n   SpeakerBio:  Chandru J\, Zoho\, Product Secur
 ity Manager\n\n   Product Security Manager with over 12 years of experienc
 e in driving\n   cybersecurity initiatives\, enhancing organizational secu
 rity posture\,\n   and ensuring compliance with international standards su
 ch as ISO\n   27001\, SOC 2\, and GDPR. Adept at leading and mentoring tea
 ms\, managing\n   enterprise-wide security programs\, and developing in-ho
 use security\n   tools to address vulnerabilities effectively. Proven expe
 rtise in\n   vulnerability management\, incident response\, security gover
 nance\, and\n   implementing secure development lifecycle (SDLC) practices
 . Recognized\n   for fostering a security-first culture and collaborating 
 with\n   cross-functional teams to mitigate risks\, protect assets\, and i
 mprove\n   processes in rapidly evolving environments.\n\n   SpeakerBio:  
 Muthu Kumar\, Security Engineer\n\n   I am a Security Engineer with 10 yea
 rs of experience specializing in\n   web application security and security
  tool development. I have\n   extensive experience identifying security vu
 lnerabilities\, improving\n   secure development practices\, and building 
 tools that help\n   organizations detect and prevent security risks at sca
 le.\n\n   My expertise includes application security testing\, secure code
 \n   reviews\, threat modeling\, vulnerability assessment\, and developing
 \n   security automation solutions that reduce manual effort and improve\n
    detection accuracy. I have worked on enhancing security tools by\n   re
 ducing false positives and helping engineering teams address\n   vulnerabi
 lities more efficiently.\n\n   I am passionate about building secure syste
 ms and solving complex\n   security challenges through automation\, innova
 tion\, and practical\n   security engineering approaches. My focus is on s
 trengthening\n   application security while enabling development teams to 
 build and\n   ship secure products faster.\n\n   '\n\n   1. #LVCCW_Level1_
 Hall3\n\n\n
DTEND:20260809T003000Z
DTSTART:20260809Z
LOCATION:Recon Village - LVCCW Level 1 Hall 3 801 (Creator Stage 2)
SUMMARY:CyberKB: When Your AI Copilot Runs the Recon\, Crawls the Dark Web\
 , and Maps the Kill Chain
END:VEVENT
END:VCALENDAR
