BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Taming the Swarm: Hard Architectural Lessons from Bu
 ilding a\n   Deterministic Agentic Web Pentesting System\n   Tags: DEF CON
  Official Talk | Demo 💻\n   When: Saturday\, Aug 8\, 16:30 - 17:30 PDT\
 n   Where: LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4 - [1]Map\n\n
    Description:\n\n   Most agentic systems for offensive security boast im
 pressive\n   benchmarks while hiding the real cost\, the real time\, and t
 he\n   architectural pain behind them. Many remain closed-source\, sacrifi
 cing\n   the transparency security demands.After 20 years as an offensive\
 n   security researcher\, I spent the last 10 months distilling all that\n
    accumulated experience into a deterministic agentic pipeline for web\n 
   pentesting.I’ll dissect the hard trade-offs I had to make: why\n   vis
 ual validation via Playwright\, CDP and Vision models became\n   mandatory
  (and why text-based parsing is architecturally broken for\n   client-side
  vulns like XSS)\, why suppressing creativity backfired\, how\n   speciali
 zation\, model shifting and temperature control enabled useful\n   determi
 nism\, why a dedicated Skeptic agent and weighted scoring were\n   essenti
 al\, and why immutable audit trails\, wet/dry separation and\n   native MC
 P support became non-negotiable.War stories included: the\n   "Dojo Incide
 nt" — where the agents decided rewriting server configs\n   was cheaper 
 than writing the exploit.Conclusion: reliable offensive\n   agentic system
 s must be open-source. Closed-source hides real behavior\n   and real risk
 s. Open-source is not a license choice — it is the only\n   architectura
 l and ethical safeguard we have left.\n\n   SpeakerBio:  Albert "yz9yt" Co
 rzo\n\n   I’ve been breaking things for over 20 years — legally\, most
  of the\n   time. An offensive security researcher with an adversarial min
 dset\,\n   multiple Hall of Fame recognitions\, and several critical CVEs\
 n   discovered.For the past 6+ years I’ve focused on the intersection of
 \n   AI and offensive security. My work centers on solving complex\n   eng
 ineering challenges in agentic systems: enforcing determinism\,\n   minimi
 zing token burn and environmental impact\, and creating reliable\n   pipel
 ines that combine LLMs with real web pentesting tools.I’m a web\n   pent
 ester and technical speaker passionate about helping the next\n   generati
 on of researchers execute more precise and effective web\n   attacks.\n\n 
   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260809T003000Z
DTSTART:20260808T233000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4
SUMMARY:Taming the Swarm: Hard Architectural Lessons from Building a Determ
 inistic Agentic Web Pentesting System
END:VEVENT
END:VCALENDAR
