BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: LLM-Coached Red Team Tactics to Attack Zero Trust\n 
   Tags: Red Team Village | Misc\n   When: Friday\, Aug 7\, 15:00 - 15:59 P
 DT\n   Where: LVCCW Level 1 Hall 1 309 (Red Team Village) Workshop Stage 2
  -\n   [1]Map\n\n   Description:\n\n   This workshop is targeted toward no
 vice and intermediate red teamers\n   and explores how AI-assisted offensi
 ve agents can support attack-path\n   discovery and adversarial operations
  within modern Zero Trust\n   environments. Following a brief overview of 
 ARES (Autonomous\n   Reconnaissance & Exploitation System)\, participants 
 spend most of the\n   session interacting with the agent while navigating 
 a live enterprise\n   range.\n\n   ARES is built upon a retrieval-augmente
 d generation (RAG) architecture\n   incorporating offensive doctrine\, MIT
 RE ATT&CK mappings\, operational\n   playbooks\, and offensive knowledge s
 ources including the Red Team\n   Field Manual and UK Ministry of Defence 
 Red Teaming Handbook. The\n   system integrates common offensive tooling i
 ncluding Nmap\, Metasploit\,\n   NetExec\, BloodHound CE\, Hashcat\, Impac
 ket\, Evil-WinRM\, and native\n   Linux terminal workflows. ARES can gener
 ate attack scripts for\n   operator approval\, analyze successful and unsu
 ccessful attacks\,\n   identify attack paths\, and capture operational kno
 wledge for future\n   recommendations.\n\n   Participants will receive con
 tinued access to the range and ARES\n   following the conference.\n\n   Pa
 ired Tactic\n\n   The paired tactic places participants inside a simulated
  enterprise\n   environment running Windows Server 2022 Active Directory\,
  Windows 11\n   workstations\, Ubuntu 24.04 application servers\, GitLab C
 ommunity\n   Edition\, Jenkins CI/CD\, and Microsoft Entra-style identity 
 services.\n   The environment includes MFA enforcement\, network segmentat
 ion\,\n   service accounts\, privileged automation workflows\, and least-p
 rivilege\n   access controls representative of modern Zero Trust deploymen
 ts.\n\n   Participants begin with access to a Kali Linux attack workstatio
 n\n   equipped with Nmap\, NetExec\, BloodHound CE\, Hashcat\, Metasploit\
 ,\n   Impacket\, Evil-WinRM\, and ARES. The objective is not simply to exp
 loit\n   a vulnerability but to identify hidden trust relationships betwee
 n\n   users\, service accounts\, deployment pipelines\, automation platfor
 ms\,\n   and protected resources.\n\n   ARES assists participants with rec
 onnaissance interpretation\,\n   attack-path discovery\, trust-chain analy
 sis\, script generation\, and\n   recommendations following both successfu
 l and failed operations.\n   Participants may discover exposed service-acc
 ount credentials\,\n   deployment tokens embedded in Git repositories\, ov
 erprivileged CI/CD\n   workflows\, delegated administrative rights\, and o
 ther trust\n   assumptions that remain despite Zero Trust controls.\n\n   
 Throughout the exercise\, all offensive actions require participant\n   ap
 proval and execution. The workshop demonstrates how modern red team\n   op
 erations increasingly focus on identities\, trust relationships\, and\n   
 authorization paths rather than traditional perimeter exploitation\n   whi
 le showcasing how AI-assisted systems can support offensive\n   decision-m
 aking and operational knowledge reuse.\n\n   Speakers:Rudy Ristich\,Vijay 
 Anand\n\n   SpeakerBio:  Rudy Ristich\n\n   Rudy Ristich is a long-time ha
 cker based in Chicago. He has lead red\n   teams and vulnerability assessm
 ent practices\, contributed to THOTCON\n   hardware badges\, and delivered
  podcasts and workshops on offensive\n   ops. Rudy strongly believes that 
 red teaming is most valuable when it\n   actually changes how defenders ca
 n operate. Most recently Rudy has\n   advised the UC2ADAM project helping 
 to support up-skilling public\n   sector works on information security ski
 ll. Rudy has served as a Goon\n   at DEFCON for over a decade.\n\n   Speak
 erBio:  Vijay Anand\n\n   Vijay Anand is an Associate Professor in the Dep
 artment of Information\n   Technology at Kennesaw State University. He hol
 ds a Ph.D. degree from\n   Illinois Institute of Technology. His research 
 interests are in\n   zero-trust architectures\, cyber intelligence\, embed
 ded security\,\n   blockchain technologies\, trustworthy cyberinfrastructu
 re\, and\n   cybersecurity education. Before joining Kennesaw State Univer
 sity\, he\n   had multiple academic appointments\, notably as an Associate
  Professor\n   and Director of Cybersecurity at the University of Missouri
  - St.\n   Louis and an Associate Professor and Director of Cybersecurity 
 at\n   Southeast Missouri State University. He has previously held industr
 y\n   positions as an Embedded Security Architect at Motorola\, Senior\n  
  Security Engineer at PALM Inc.\, and as a Security Research Engineer at\n
    Computation Institute. He has served as a member of the Missouri\n   Go
 vernor’s Cybersecurity Taskforce and was the director of the\n   Missour
 i Collegiate Cyber Defense Competition. Currently\, he has\n   multiple fu
 nded research projects from the Department of Defense (DoD)\n   and the Na
 tional Science Foundation (NSF).\n\n   '\n\n   1. #LVCCW_Level1_Hall1\n\n\
 n
DTEND:20260807T225900Z
DTSTART:20260807T220000Z
LOCATION:Red Team Village - LVCCW Level 1 Hall 1 309 (Red Team Village) Wor
 kshop Stage 2
SUMMARY:LLM-Coached Red Team Tactics to Attack Zero Trust
END:VEVENT
END:VCALENDAR
