BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: GnawLab: Open-Source AWS Attack Scenarios Based on R
 eal-World\n   Breaches\n   Tags: Intro/Beginner | AI | DEF CON Demo Labs |
  Cloud | Offense/Red\n   Team | DEF CON Demo Labs\n   When: Friday\, Aug 7
 \, 12:00 - 12:45 PDT\n   Where: LVCCW Level 1 Hall 3 1002 (Demo Labs Track
  2) - [1]Map\n\n   Description:\n\n   GnawLab is a community-driven\, open
 -source offensive cloud security\n   training platform that recreates real
 -world AWS attack chains. Each\n   scenario is modeled after documented br
 eaches—Capital One's\n   SSRF-to-IMDS pivot\, Uber's leaked credential e
 xploitation\,\n   SolarWinds-style CI/CD pipeline hijacking—deployed via
  Terraform in\n   your own AWS account. Attendees will see live demonstrat
 ions of\n   multi-hop attack chains: from SSRF and command injection entry
  points\,\n   through IMDS credential theft and Secrets Manager extraction
 \, to full\n   CI/CD pipeline compromise with Blue/Green deployment backdo
 ors.\n   GnawLab bridges the gap between theoretical cloud security knowle
 dge\n   and hands-on exploitation skills.\n\n   Speakers:ialleejy\,Kyul\,H
 yunJun "Beaver King" Kwon\n\n   SpeakerBio:  ialleejy\n\n   I am ialleejy\
 , a Security Researcher at ENKI focusing on web security\n   and cloud sec
 urity. I have created WEB challenges for CODEGATE and\n   HACKTHEON SEJONG
  CTF\, and I am interested in designing CTF challenges\n   that connect re
 al-world service architectures with practical\n   vulnerability research.\
 n\n   Recently\, I have been exploring Offensive Cloud Security\, especial
 ly\n   how traditional web vulnerabilities can lead to privilege escalatio
 n\,\n   credential exposure\, and abuse of trust relationships in cloud\n 
   environments. I am currently diving deeper into AWS Bedrock AI Agents\,\
 n   RAG-based knowledge poisoning\, OIDC authentication flows\, and IAM\n 
   trust policies.\n\n   Through this talk\, I aim to show how a small vuln
 erability on the web\n   can evolve into a broader cloud security issue\, 
 crossing trust\n   boundaries between applications\, identities\, and clou
 d services.\n\n   SpeakerBio:  Kyul\n\n   I am a college student relentles
 sly exploring cloud vulnerabilities. I\n   possess an exceptionally high t
 hreshold for hunting\, gathering\, and\n   deeply analyzing whatever pique
 s my interest.\n\n   My mindset is clear: effective defense demands an att
 acker's lens.\n   Only by understanding actual infiltration paths and how 
 they trigger\n   critical risks can defenders accurately prioritize assets
  and build\n   robust controls.\n\n   Driven by this\, I’ve operated at 
 the intersection of Red and Blue.\n   In incident response projects\, I an
 alyzed real-world TTPs to build\n   attack scenarios while collaborating t
 o engineer detection rules and\n   automated responses. I’ve also resear
 ched and presented how AWS\n   misconfigurations can be weaponized to caus
 e cascading breaches.\n\n   Currently\, alongside the BeaverDam community\
 , I am developing GnawLab\n   for the DEF CON Demo Lab. GnawLab is an open
 -source\, community-driven\n   cloud security training platform. It provid
 es high-fidelity sandbox\n   environments reflecting real-world flaws\, en
 abling players to execute\n   realistic scenarios and vividly master cloud
  exploitation and\n   analysis.\n\n   At DEFCON\, my goal isn't just to sh
 ow what I've built. I want to share\n   this sandbox\, break it alongside 
 you\, and absorb the brilliant\,\n   diverse approaches of world-class hac
 kers. I am here to hack\, learn\,\n   and grow together.\n\n   SpeakerBio:
   HyunJun "Beaver King" Kwon\n\n   HyunJun Kwon is an Application and Clou
 d Security Engineer with 12\n   years of offensive security experience. Cu
 rrently at Rapport Labs in\n   Korea\, he previously led vulnerability ass
 essments\, DevSecOps\, and\n   cloud security initiatives at Woowa Brother
 s\, the company behind\n   Baemin\, South Korea's largest food delivery pl
 atform.\n\n   He serves as an AWS Community Builder for security and leads
  the\n   Beaver Dam Community\, an offensive cloud security research group
 . He\n   also contributes to AWS Bedrock Agent Samples and mentors junior\
 n   security professionals through programs like Baby Beavers\, K-Shield\n
    Junior\, and Whitehat School.\n\n   His cloud security research focuses
  on scaling security in dynamic\n   environments. He built automated CCE a
 ssessment systems using AWS VPC\n   Endpoints and Systems Manager. Recentl
 y he explored AI and security\n   intersections\, building LangChain and L
 angGraph agents for\n   infrastructure assessment automation and MCP secur
 ity checkers to\n   detect supply chain risks.\n\n   He won the 2021 HDCON
  Grand Prize for cloud security architecture and\n   authored two books on
  web hacking. He spoke at .HACK 2025 on Offensive\n   Cloud Security and a
 t .HACK 2026 on whether CloudTrail and GuardDuty\n   are really enough.\n\
 n   Links:\n       GitHub - [2]https://github.com/Beaver-Dam-Community/Gna
 wLab\n   '\n\n   1. #LVCCW_Level1_Hall3\n   2. https://github.com/Beaver-D
 am-Community/GnawLab\n\n\n
DTEND:20260807T194500Z
DTSTART:20260807T190000Z
LOCATION:Demo Labs - LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)
SUMMARY:GnawLab: Open-Source AWS Attack Scenarios Based on Real-World Breac
 hes
END:VEVENT
END:VCALENDAR
