BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Agenthound: Mapping Multi-Hop Credential Chains Acro
 ss MCP\,\n   A2A\, and LLM Gateways\n   Tags: Red Team Village | Misc\n   
 When: Sunday\, Aug 9\, 12:00 - 12:59 PDT\n   Where: LVCCW Level 1 Hall 1 3
 09 (Red Team Village) Workshop Stage 1 -\n   [1]Map\n\n   Description:\n\n
    A developer’s MCP configuration exposes a gateway credential. That\n 
   gateway holds production model keys\, an A2A agent can reach it through\
 n   a delegated tool\, and the agent loads instructions from a repository\
 n   an external contributor can modify. Each component looks harmless in\n
    isolation\; together\, they form a viable path from a low-trust\n   dev
 eloper environment to production systems. Modern AI infrastructure\n   is 
 full of these hidden chains\, spanning MCP servers\, agent runtimes\,\n   
 model gateways\, local inference hosts\, notebooks\, and web interfaces.\n
    No file declares the entire chain\, and no scanner confined to MCP\,\n 
   A2A\, or any one AI service can reconstruct it. The most dangerous\n   w
 eakness in the agentic stack is often not a component - it is the\n   trus
 t between components.\n\n   AgentHound (https://github.com/adithyan-ak/Age
 ntHound) is an offensive\n   security framework that serves as BloodHound 
 for AI agent\n   infrastructure. Its lean Go collector maps agent clients\
 , MCP servers\,\n   A2A agents\, tools\, resources\, identities\, credenti
 als\, and AI\n   services\; a local Neo4j-backed server correlates those o
 bservations\n   and derives cross-service reachability to reveal attack pa
 ths such as\n   poisoned instructions\, credential reuse\, impersonation\,
  and potential\n   execution or data exfiltration. What makes it special i
 s its ability\n   to merge evidence from multiple protocols and collectors
  into one\n   deterministic graph\, then rebuild higher-level relationship
 s turning\n   scattered configuration issues into concrete\, explainable a
 ttack\n   chains across the entire AI-agent ecosystem.\n\n   In this live 
 demo\, we follow one hidden attack chain end to end —\n   from a foothol
 d on a developer workstation to verified access to a\n   protected\, high-
 value resource. AgentHound discovers the local MCP\n   configuration\, con
 nected services\, tools\, credentials\, and resources\;\n   correlates the
 m into a walkable attack path\; and then safely tests\n   whether that pat
 h is genuinely exploitable\, upgrading the finding from\n   inferred risk 
 to verified evidence in real time. We finish by\n   poisoning an MCP tool 
 description\, detecting the new attack path\, and\n   restoring the target
  from a recovery receipt\, showing how AgentHound\n   makes cross-system w
 eaknesses visible\, testable\, explainable\, and\n   reversible.\n\n   Age
 ntHound is open source under Apache 2.0. Version 1.0 is released\n   and a
 vailable now.\n\n   SpeakerBio:  Adithyan Arun Kumar\n\n   Adithyan Arun K
 umar is an AI Security Engineer at Salesforce\,\n   specializing in AI adv
 ersarial red teaming\, RAG security\, and agentic\n   threat modeling acro
 ss the Agentforce ecosystem. Armed with over five\n   years of full-spectr
 um offensive security experience and a MS in\n   Information Security from
  Carnegie Mellon University\, he holds\n   advanced certifications includi
 ng OSEP\, OSWE\, OSCP\, and CRTP. His\n   extensive vulnerability research
  and offensive tradecraft have earned\n   him hall-of-fame acknowledgments
  from industry leaders such as Apple\,\n   Microsoft\, and Intel.\n\n   '\
 n\n   1. #LVCCW_Level1_Hall1\n\n\n
DTEND:20260809T195900Z
DTSTART:20260809T190000Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Wor
 kshop Stage 1
SUMMARY:Agenthound: Mapping Multi-Hop Credential Chains Across MCP\, A2A\, 
 and LLM Gateways
END:VEVENT
END:VCALENDAR
