> reconvillage-2026-defcon-34

[DEF_CON_34]

schedule_2026

Las Vegas Convention Center, Las Vegas, USA · August 7-9, 2026

> speakers_2026
14 talks
6 workshops
DayTimeDurationSessionSpeaker(s)Room
Friday, August 710:00 AM – 12:30 PM150 minDhiyaneshwaran Balasubramaniam, Aman RawatRecon Village Workshop Area
10:45 AM – 11:30 AM45 minMiranda TedholmDEF CON Creator Stage 2
12:40 PM – 3:10 PM150 minMarcelle Lee, Will ThomasRecon Village Workshop Area
1:00 PM – 1:45 PM45 minNico DekensDEF CON Creator Stage 2
3:30 PM – 6:00 PM150 minMark GaddyRecon Village Workshop Area
4:30 PM – 5:00 PM30 minAnthony RussellDEF CON Creator Stage 6
Saturday, August 810:00 AM – 12:30 PM150 minAlessandra Rizzo, Ariel RopekRecon Village Workshop Area
12:40 PM – 3:10 PM150 minJeff FoleyRecon Village Workshop Area
1:00 PM – 1:30 PM30 minEddie MiroDEF CON Creator Stage 2
1:30 PM – 2:00 PM30 minFae CarlisleDEF CON Creator Stage 2
3:00 PM – 3:30 PM30 minSadettin BolukDEF CON Creator Stage 2
3:20 PM – 5:50 PM150 minLenin AlevskiRecon Village Workshop Area
3:30 PM – 4:00 PM30 minEli WoodwardDEF CON Creator Stage 2
5:00 PM – 5:30 PM30 minSuriya Prasath S, Chandru J, Muthu KumarDEF CON Creator Stage 2
5:00 PM – 5:30 PM30 minAvishai Efrat, Roey Ben ChaimDEF CON Creator Stage 3
5:30 PM – 6:00 PM30 minJohn McCaryDEF CON Creator Stage 2
Sunday, August 910:00 AM – 10:45 AM45 minMichael Reimsbach, Rishi CDEF CON Creator Stage 2
10:45 AM – 11:30 AM45 minJason HaddixDEF CON Creator Stage 2
12:00 PM – 12:30 PM30 minDavid CassDEF CON Creator Stage 5
12:30 PM – 1:00 PM30 minRedon Gashi, Armend GashiDEF CON Creator Stage 5
[Friday, August 7]
10:00 AM – 12:30 PMFriday, August 7Recon Village Workshop Area

Every organization relies on third-party vendors, open-source packages, and CI/CD tools to build and deliver software. In this session, we'll learn how to identify and map these external dependencies, understand the trust relationships between them, and discover potential security risks. Through practical demonstrations, attendees will see how issues such as dependency confusion, insecure GitHub Actions workflows, and vendor-related weaknesses can become entry points for supply chain attacks. The goal is to help security teams find and fix these risks before attackers do.

beginner
10:45 AM – 11:30 AMFriday, August 7DEF CON Creator Stage 2

We all know Quora - or do we? Like Internet herpes, if you're a Google user, it'll follow you, forever, haunting your inbox with clickbait if you Google while logged into your account. ...But do we REALLY know Quora? Because despite being a pustule on the Internet that exists for the sole purpose of spamming SERPs, you'll be shocked to learn that it's also got - spoiler alert!!! - a dark, seedy underbelly. One that I uncovered while volunteering on an MP investigation. One that can yield surprising, disturbing and useful intelligence. In this talk, I'll explain: 1. The traces Quora leaves behind when something is "limited," "deleted" or a user is "banned." Because on Quora, 'deleted' just nulls the post body while the API keeps serving the slug and author, and 'limited' barely hides anything at all. On Quora, Limited is UNLIMITED, just like Olive Garden's breadsticks! Except unlike Olive Garden breadsticks, Quora's "limited" option is a fig leaf, and "deleted" content isn't much better: The API doesn't hide it. It coughs up the slug and author fully visible to other accounts and even logged-out strangers. 2. How to use Quora's API hairball to see what a user posted and build a network graph 3. What the disturbing subcultures on Quora mean for OSINT 4. Limitations of approach and ideas for automating OSINT Trigger warnings: This talk may include mention of disturbing topics, though all information will be anonymized / sanitized and no graphic content shared.

12:40 PM – 3:10 PMFriday, August 7Recon Village Workshop Area

Your mission: Stop chasing single indicators and start profiling the actual behavior of the adversary. From cybercriminals to state-sponsored actors, every threat group leaves a unique operational blueprint. Whether you are an OSINT hobbyist or an experienced cyber intelligence analyst, come ready to dissect real-world attack behaviors, translate data into actionable insights, and master the art of OSINT-powered TTP research. This hands-on workshop explores the world of cyber threat actors and the open-source intelligence (OSINT) methodologies used to unmask their behavioral patterns. Rather than focusing strictly on fleeting indicators of compromise (IoCs) like file hashes or IP addresses, participants will learn how to extract, analyze, and profile an adversary's true Tactics, Techniques, and Procedures (TTPs). Through interactive, real-world case studies, attendees will learn how to analyze public incident reports, open intelligence repositories, and external datasets to map out an actor's operational playbook. Using frameworks like MITRE ATT&CK and the Diamond Model, participants will practice pivoting from technical data to strategic threat profiles—equipping them with the research skills needed to predict and counter adversarial behavior without ever needing an enterprise budget. Workshop Structure: Module 1: Foundations of Threat Intelligence & Actor Profiling The Threat Landscape: Definitions and categories of actors (APTs, cybercriminals, hacktivists, insiders). Understanding Adversarial Motivation: Moving beyond what happened to why and how actors select their targets and techniques. Intelligence Categorization: Differentiating between Strategic, Operational, and Tactical/Technical intelligence, and how TTP research feeds all three. Module 2: The Analytical Frameworks MITRE ATT&CK Deep Dive: Navigating the matrix, understanding sub-techniques, and avoiding common mapping pitfalls. The Diamond Model: Connecting the four core nodes (Adversary, Capability, Infrastructure, Victim) to tell a complete campaign story. The Pyramid of Pain: Understanding why tracking TTPs inflicts the maximum cost on the adversary compared to trivial indicators. Module 3: Dissecting the Data (Case Study Analysis) Deconstructing DFIR Reports: Walking through real-world incident examples (e.g., Gootloader campaigns, ransomware operations) to extract behavioral indicators from public write-ups. Safe Analysis Practices: Utilizing basic web-based OSINT tools (urlscan.io, Browserling, CyberChef) to safely evaluate delivery mechanisms and landing pages without compromising investigator safety. Module 4: Live TTP Research (Group Exercise) The Scenario: Groups are given an initial, ambiguous threat brief or a raw dataset from a recent campaign. The Analysis: Using open-source resources, teams will collaborate to identify the actor's threat components (who, what, where, when, how, why). The Playbook: Teams will map their findings into the MITRE ATT&CK Navigator, build a comprehensive threat intelligence profile, and present their adversarial playbook to the room.

intermediate
1:00 PM – 1:45 PMFriday, August 7DEF CON Creator Stage 2

The OSINT landscape is undergoing a fundamental shift. Artificial Intelligence is no longer just a tool; it is becoming a crutch. As analysts increasingly rely on LLMs to triage data, translate foreign slang, and summarize massive datasets, a dangerous cognitive atrophy is taking hold. We are trading the slow, deliberate friction of critical thinking for the illusion of speed and certainty. This talk, "OSINT Is Still a Thinking Game," exposes the hidden vulnerabilities of AI dependence in intelligence work. Through real-world case studies—from misinterpreting Telegram chatter to falsely flagging logistics data—we will examine how the "Good Enough" trap leads to catastrophic analytical failures. More importantly, this session provides a concrete defense framework. Attendees will learn the four essential habits required to survive the AI era: reading the raw source, forcing a second hypothesis, separating speed from confidence, and auditing dependence. The tools will inevitably get better, but the thinking must get sharper. Join this session to learn how to maintain your tradecraft, keep your judgment visible, and ensure that in the age of automation, defensibility always wins over speed.

3:30 PM – 6:00 PMFriday, August 7Recon Village Workshop Area

Reconnaissance is the foundation of every successful engagement but fragmented tooling, manual chaining, and missed data leave gaps that cost you findings. BBOT (Bighuge BLS OSINT Tool) was built to solve that. Developed by Black Lantern Security, BBOT is a recursive, event-driven OSINT framework that replaces the traditional phased approach with continuous, real-time discovery every new piece of data is immediately fed back into the scan engine to uncover what linear workflows miss. This is a fully hands-on workshop. Attendees will install and configure BBOT, then run it live against their own scoped bug bounty targets turning the session into real reconnaissance rather than a slide-driven demo. We'll cover BBOT's 100+ module architecture spanning subdomain enumeration, cloud asset discovery, email harvesting, web spidering, and vulnerability scanning with Nuclei, all chainable in a single command and firing recursively in real time. Along the way we'll dig into scope management, passive vs. active recon tradeoffs, and the web hacking modules that can point you toward real findings. By the end of the session, attendees will walk away with actual scan output from a live target, a repeatable BBOT-driven recon workflow they can drop into their next program, and a clear understanding of how to triage findings into real submissions. Whether you're new to automated recon or a seasoned bug bounty hunter still stitching tools together by hand, this workshop will change how you approach OSINT at scale. Module 1 — Why BBOT? The Problem with How We Recon Now The fragmented toolchain problem: Amass → Subfinder → httpx → manual grep Why phased OSINT misses things — and what recursive, event-driven recon solves BBOT's origin at Black Lantern Security and design philosophy Quick architecture overview: modules, events, presets, scope 3.0 Updates - Rustification of HTTP and DNS Q&A / audience skill check Module 2 — Getting Oriented: Installation, Config & First Scan Verify install and run bbot --help Listing and exploring modules with bbot -l Understanding flags vs. modules vs. presets Exercise 2.1: Run your first subdomain scan Reading and understanding BBOT output Scan output folders, naming conventions, and where data lives Module 3 — Subdomain Enumeration Deep Dive How BBOT's recursive engine finds more than traditional tools Passive vs. active enumeration — when to use each Subdomain mutations and wordcloud usage Exercise 3.1: Full active subdomain enum Module 4 — Going Deeper: Cloud, Email & Asset Discovery Cloud enumeration: S3 buckets, Azure blobs, GCP assets Email harvesting for org footprinting Combining flags for broader discovery Exercise 4.1: Run a combined cloud + email + subdomain scan Identifying misconfigured or exposed cloud assets in output Discussion: how these findings translate to bug bounty submissions Module 5 — Web Hacking Modules & Vulnerability Scanning Overview of BBOT's web module suite: httpx, gowitness, wappalyzer, nuclei Web spidering for email, secrets, and exposed paths Nuclei integration — what it scans for and how to interpret results Exercise 5.1: Full web scan with screenshots Exercise 5.2: Kitchen sink scan (instructor-guided, safe target only) Setting expectations: BBOT points you at the doors — you still have to kick them open Module 6 — Triage, Workflow & What Happens After the Scan How to structure your post-BBOT workflow: what to investigate first Prioritizing findings by severity and exploitability Avoiding common pitfalls: rate limiting, duplicate findings, out-of-scope mistakes Building a repeatable bug bounty recon workflow around BBOT Scheduling and automating recurring scans for continuous monitoring Wrap-Up & Q&A Recap of key takeaways Recommended next steps and resources GitHub, docs, and community links Open Q&A

beginner
4:30 PM – 5:00 PMFriday, August 7DEF CON Creator Stage 6

Most LLM-powered recon tools look impressive in a 90-second demo and fall apart on real targets. They hallucinate, loop, go out of scope, double-fire the same endpoint, or die the moment a WAF or rate limit appears. This talk is about what it actually takes to run fifty-plus specialist agents in parallel for hours or days without the chaos. We built a system where every agent is locked to the rails: a concrete tool, a strict pipeline phase, explicit prerequisites, timeouts, and sandboxes. The model does not drive. It rides. The binaries (and only the binaries) touch the target. This "Agents on Rails" approach eliminates freestyle LLM behavior while still letting the model do what it is good at—reasoning over evidence.

[Saturday, August 8]
10:00 AM – 12:30 PMSaturday, August 8Recon Village Workshop Area

North Korean threat actors are running one of the largest software supply chain campaigns ever observed in the npm ecosystem, and the infrastructure hiding it in plain sight is discoverable through open-source reconnaissance alone. This workshop walks participants through how we mapped a live DPRK delivery network targeting cryptocurrency developers, starting from a single malicious npm package and expanding outward to uncover 50+ malicious packages, 100+ GitHub repositories, 30+ throwaway npm personas, 20+ rotating C2 domains, and a social media promotion layer spanning X and Reddit. The investigation surfaces three malware families: PromptMink, ClipViper, and OtterCookie, which operate through what initially appeared to be separate campaigns but share overlapping infrastructure, actors, and delivery techniques. The workshop focuses on the recon methodology behind the mapping through six hands-on modules: - Dependency chain tracing: How malicious payloads hide one to three hops deep in transitive npm dependencies, evading surface-level code review and automated scanners - Actor network pivoting: Using email patterns, SSH key reuse, shared C2 infrastructure, and build artifact fingerprints to link 30+ throwaway npm accounts into operational clusters - Identity spoofing detection: How to catch developer identity theft through timezone offset analysis - GitHub delivery front reconnaissance: Tracing 40+ fork chains across front organizations all serving identical malicious payloads behind bot-inflated star counts and SEO-stuffed descriptions - Social media promotion mapping: Connecting verified X accounts and Reddit personas to the distribution layer, and observing how the social infrastructure persists even after GitHub takedowns - Evasion tracking in real time: Documenting the operators' shift from obfuscated JavaScript to on-chain payload storage via Solana, where the npm package contains zero malicious code and the payload lives in a blockchain account beyond the reach of static analysis Participants work directly with actionable IoCs (packages, C2 domains, SSH keys, YARA rules, detection queries) and leave with a breakdown of how current Contagious Interview and Contagious Trader toolsets are converging into a unified threat. Attendees will leave with a repeatable framework for mapping supply chain malware delivery networks using open-source data: package registries, Git metadata, DNS records, social media artifacts, and cross-referencing with community threat feeds.

intermediate
12:40 PM – 3:10 PMSaturday, August 8Recon Village Workshop Area

Attack Surface Management (ASM) lives or dies on a deceptively simple question: who owns this? Without reliable attribution, an asset inventory is just a pile of hosts, domains, certificates, and cloud endpoints—with no defensible way to scope an organization’s true digital footprint or separate first-party infrastructure from vendors, subsidiaries, acquisitions, joint ventures, and brand portfolios. This talk dives into the real-world challenge of attributing internet-exposed assets to legal entities, not just names. Corporate identity is messy: organizations operate under trade names, localized spellings, legacy names, and jurisdiction-specific registrations. Meanwhile, the internet leaks ownership signals through fragmented, lossy metadata—RDAP/WHOIS, certificate subject/issuer fields, ASN registrations, DNS TXT verification records, trademark references, and public corporate registries. Each source is incomplete on its own; together they can still conflict, drift over time, and create duplicate “identities” that quietly degrade attribution accuracy. Using the OWASP Amass Project as a concrete reference point, we’ll walk through an attribution-centric discovery workflow: collecting signals, normalizing entity identity, resolving aliases across jurisdictions, and scoring confidence to decide when to merge, when to split, and when to escalate for analyst review. We’ll also explore how attribution errors propagate into ASM outcomes—missed scope, false positives, and blind spots in third-party exposure—and how disciplined entity modeling can turn noisy OSINT into a repeatable system of record. Attendees will leave with practical techniques for improving attribution quality, a mental model for entity resolution, and actionable ideas for making ASM outputs trustworthy enough to drive risk decisions.

intermediate
1:00 PM – 1:30 PMSaturday, August 8DEF CON Creator Stage 2

We live in an era where our location data is constantly harvested, but what happens when the tracking becomes physical? From the clandestine beacons of the Cold War to the consumer-grade AirTags tucked into backpacks today, physical tracking technology has become incredibly cheap, accessible, and pervasive. In this talk, we will trace the evolution of physical tracking tech, analyze how modern implementations exploit wireless protocols like BLE, cellular, and GPS, and discuss practical defense strategies to detect and neutralize unwanted eyes. Finally, we will demystify the threat by turning the tables: demonstrating how to build and deploy a fully functional, budget-friendly tracking beacon using off-the-shelf DIY hardware. Attendees will leave with a deep understanding of the tracking landscape and the knowledge required to both defend against and build these systems.

1:30 PM – 2:00 PMSaturday, August 8DEF CON Creator Stage 2

Most threat intelligence focuses on what attackers have already done: payloads, malware families, and post-compromise behavior. But adversaries are far more fluid at the payload layer than they are at the infrastructure layer. Domains rotate, IPs churn, and malware gets recompiled but infrastructure leaves patterns. This article explores how to track threat actors through their infrastructure by leveraging fingerprinting techniques that expose those patterns at scale. We’ll walk through practical methods including JARM for active TLS stack fingerprinting, JA3/JA4 for identifying consistent communication behaviors, SSH host key correlation for infrastructure pivoting, and MurmurHash for clustering phishing kits and web panels through shared assets. Individually, these signals are useful. Combined, they allow defenders to map infrastructure clusters tied to a single actor or campaign—even when traditional indicators change. The focus is not on attribution for its own sake, but on building a repeatable approach to discovering “sister infrastructure” and identifying campaigns earlier in their lifecycle. By shifting attention away from payloads and toward the systems attackers stand up to operate, defenders can detect patterns before deployment and reduce time to awareness. Attackers rely on reuse of configurations, tooling, and infrastructure. That reuse creates fingerprints. And those fingerprints are often more durable than the indicators most teams prioritize. If you want to track threat actors effectively, stop chasing malware. Track the infrastructure they can’t help but reuse.

3:00 PM – 3:30 PMSaturday, August 8DEF CON Creator Stage 2

Modern Wi-Fi clients are designed to hide. They randomize MAC addresses, reduce directed probes, avoid exposing preferred networks, and use per-network private addresses. Yet before a device connects, it still speaks. This talk introduces a Python-based proof-of-value tool for passive Wi-Fi reconnaissance and privacy exposure analysis. The tool listens to 802.11 management traffic, builds an environmental AP map from beacon frames, observes client reactions through probe requests, parses Information Elements from probe and association frames, and correlates randomized MAC identities using IE semantics, sequence behavior, packet size, timing, and channel context. The core idea is, even when the MAC address changes, the device’s wireless behavior may remain linkable. We will demonstrate how passive wireless metadata can reveal device presence, movement context, SSID exposure, privacy leakage, and probable same-device candidates even when MAC randomization is enabled. The demo will use only controlled test devices in a lab environment. The talk also introduces an AI-assisted scoring module trained on IE-level Wi-Fi fingerprints to improve correlation accuracy and reduce false positives. By combining semantic 802.11 features with behavioral signals, the tool aims to produce a practical privacy exposure score for Wi-Fi clients. This is not a tracking product or a vendor-specific platform. The goal is to show defenders, researchers, privacy engineers, and red teams what Wi-Fi clients still expose by default, and how passive management-frame metadata can become a meaningful reconnaissance surface.

3:20 PM – 5:50 PMSaturday, August 8Recon Village Workshop Area

Everyone is talking about vibe coding, but most examples stop at TODO apps, landing pages, or simple CRUD applications. This workshop goes far beyond that. Participants will use modern AI coding agents to build a real-world Open-Source Intelligence (OSINT) platform from scratch designed to aggregate and visualize intelligence data on an interactive 3D globe. Rather than simply watching a demo, attendees will actively build the application alongside the instructor while learning the mindset, prompting techniques, and engineering workflow required to successfully collaborate with AI coding assistants. The workshop begins with the fundamentals of vibe coding: what it actually is, why it works, where it fails, and how to communicate effectively with AI agents. Participants will learn practical prompting strategies, iterative development techniques, and methods for breaking large software systems into manageable tasks that AI can successfully implement. From there, we'll progressively build an intelligence dashboard capable of consuming and visualizing multiple real-time OSINT sources, including flight tracking, satellite positions, earthquake feeds, maritime traffic, and other publicly available intelligence signals. Along the way, participants will generate modern user interfaces, integrate external APIs, debug AI-generated code, and learn when to trust the model and when not to. Rather than treating AI as a code generator, this workshop teaches attendees how to use AI as an engineering partner capable of dramatically increasing development velocity while still maintaining high-quality software. By the end of the workshop, every participant will have: 1. A working open-source intelligence platform running locally 2. A practical workflow for building complex software using AI coding agents 3. A reusable prompting framework applicable to future projects 4. Experience integrating multiple public OSINT data sources 5. An understanding of the strengths and limitations of AI-assisted software development 6. A roadmap for continuing to extend the platform after the workshop The workshop is based on the open-source project: https://github.com/Alevsk/respondent-community # `Workshop Outline (150 Minutes)` ## `Part 1 — Introduction to Vibe Coding (20 min)` - `What vibe coding actually means` - `Mental models for collaborating with AI` - `Selecting the right AI model for the task` - `Understanding agentic coding workflows` - `Common mistakes and misconceptions` --- ## `Part 2 — Prompt Engineering for Software Development (25 min)` - `Structuring prompts that produce maintainable code` - `Breaking large systems into incremental tasks` - `Designing software through conversation` - `Iterating instead of regenerating` - `Knowing when to intervene manually` --- ## `Part 3 — Building the Intelligence Platform (75 min)` `Participants will build the platform together while learning how to:` - `Generate a modern frontend` - `Create a real-time 3D globe visualization` - `Integrate multiple public OSINT APIs` - `Display flights, satellites, earthquakes, ships, and additional intelligence feeds` - `Build reusable UI components with AI` - `Debug AI-generated code` - `Refactor and improve generated implementations` - `Continue extending the application using AI as a development partner` --- ## `Part 4 — Lessons Learned & Advanced Techniques (20 min)` - `What AI does well` - `Where AI still struggles` - `Managing technical debt` - `Building larger projects with AI` - `Cost optimization strategies` - `Recommended workflows and tooling` - `Future directions for AI-assisted engineering`

intermediate
3:30 PM – 4:00 PMSaturday, August 8DEF CON Creator Stage 2

Cl0p has executed at least nine major exploitation campaigns since 2020, targeting file transfer and edge devices from Accellion to MOVEit to Centrestack. Each campaign looks different on the surface, different CVEs, different victims, different tooling. But their infrastructure tells a different story. This talk presents the results of a multi-year infrastructure reconnaissance effort tracking Cl0p's hosting, ASN usage, and operational patterns across all known campaigns. By mining passive DNS data, network telemetry, and hosting records, I mapped the infrastructure behind each campaign and identified patterns the group can't seem to shake — including a favorite bulletproof hosting provider used across four separate campaigns, a finding that roughly one-third of their ASNs get recycled, and pre-attack reconnaissance probing observed as far as two years before exploitation.

5:00 PM – 5:30 PMSaturday, August 8DEF CON Creator Stage 2

What if your recon tool could understand "find leaked credentials for this company on the dark web, cross-reference with their exposed infrastructure, and show me the attack path" — and then actually do it, autonomously, with zero manual commands? CyberKB is a 214,000-line open platform that puts an AI copilot (Keke) in command of 131 offensive tools spanning reconnaissance, dark web OSINT, Shodan intelligence, breach databases, and a full Kali Linux shell — all orchestrated through natural language conversation. The Dark Web Intelligence Pipeline (DarkMonitor): CyberKB's DarkMonitor module queries .onion search engines concurrently through Tor, uses LLM-powered query refinement to generate optimal dark web search terms, applies AI relevance filtering to surface the most critical results. The AI Copilot (Keke): Keke isn't a wrapper around ChatGPT. It's a function-calling agent with direct execution access to: a privileged Kali container (nmap, curl, nikto, sqlmap, gobuster, hydra — the full toolkit), 16 dark web search engines via Tor, breach and paste database aggregators, a RAG-powered knowledge base with semantic search over ingested recon data, Shodan lookups and CVE correlation, MITRE ATT&CK technique mapping, attack graph generation and path prioritization, and engagement management (targets, credentials, findings, reports). Scale Proof — 2,250-Domain Assessment: We demonstrate CyberKB against a real-world external attack surface assessment: 2,250 domains belonging to a single organization, producing 11,968 unique IPs, 8,494 hostnames, 2,444 CVEs, 80,238 open ports, and a knowledge graph of 6,390 nodes with 51,990 infrastructure relationship edges. The entire dataset was parsed, correlated, and ingested into the AI-queryable knowledge base in 25 seconds. Keke can now answer questions like "which x domains share infrastructure with known-vulnerable IPs" by searching the graph, not by re-scanning. What This Means for Defenders: Every autonomous recon step Keke performs leaves detectable artifacts. We discuss what blue teams should monitor: DNS burst patterns from multi-engine enumeration, Tor exit node correlation with target infrastructure, behavioral signatures of AI-driven sequential probing, and how to distinguish human recon from autonomous agent recon. The same platform that empowers red teams reveals the detection surface that defenders can leverage. Key Takeaways: 1. AI copilots with direct tool execution compress hours of reconnaissance into minutes of conversation — fundamentally changing the operator's role from command executor to strategic decision-maker. 2. Dark web OSINT can be systematically automated with LLM-driven search refinement and relevance filtering, making it accessible beyond specialized analysts. 3. Infrastructure-scale attack surface mapping (2,250+ domains) becomes practical when AI handles correlation instead of humans. 4. Autonomous recon creates detectable patterns that blue teams should be actively hunting for. Tool Stack: Python, Flask, ChromaDB (RAG), Docker (Kali + Tor + Browser Agent), OpenAI-compatible LLM API, SQLite, Playwright, BeautifulSoup. 105 Python modules. Fully self-hosted — no cloud dependencies for core functionality.

5:00 PM – 5:30 PMSaturday, August 8DEF CON Creator Stage 3

AI agents quietly created a new external attack surface: copilots, custom agents, AI cakends and various deployments that ship to the internet, often without anyone realizing they are reachable, enumerable, or over-permissive. In this talk, we’ll show how attackers can already find your agents in the wild, shedding light on the technical details that enable this kind of malicious activity, including how we used these details to find 1000s of exposed agents of different kinds. We’ll follow up with explaining how to measure exposure, see the proof for obscurity failing, and understand how to detect threat-actor agent-focused recon before it turns into an impactful attack. Capping it all off by showcasing PowerPwn, a recon tool you can use to test your own exposure

5:30 PM – 6:00 PMSaturday, August 8DEF CON Creator Stage 2

We scanned every IPv4 address on the planet. Twice. We collected public records in one of at least three places: the RIR registration, the operator's reverse DNS, or whatever service answers on port. Most threat intelligence pipelines read one of those. Darkmouse lines up all of them and flags the disagreements. The result is attack-surface visibility that no single source gives you, and a methodology you can run yourself. This talk walks the recon pipeline behind three findings from a single cross-domain pass over 4.3 billion IPv4 addresses in five days, plus a 92 million IP targeted scan in 34 hours (Russia, Iran, and North Korea). We used ZMap on single-use Jetstream2 VMs, zdns for PTR and forward verification, bulk RPSL and ARIN XML and APNIC data loaded into DuckDB alongside MaxMind GeoLite2, OpenSanctions, and the US Trade Consolidated Screening List. Enrichment is baked into the scan row at ingest. Every field carries a source-date stamp so longitudinal comparison actually works. Lead finding for a recon audience: 6,656 Iranian IPs in RIPE where the registrant placed fabricated US street addresses into the authoritative registry. 4,608 of them cite AT&T Mobility's ARIN IP-management address verbatim. 2,048 cite a Philadelphia apartment building. All geolocate to Iran. All trace to one operator through a shared RIPE maintainer object linking a Shiraz Local Internet Registry and an Omani shell. Between September 2025 and January 2026 the fabricated addresses began rotating out, replaced by netnames like "Datacamp-Limited" that impersonate real UK hosting companies. A single-point-in-time feed cannot see that rotation. Two dated snapshots can. We are currently running follow up scans and expect to have new data before the conference. Additional Findings: five active PTR records in Russia and the Netherlands claiming US government domains, including .fbi.gov subdomains, four of five still live six months after first observation (April 2026). And 1,534 APNIC-registered IPs for Entity Listed Chinese telecoms, declared country=US, geolocating to One Wilshire in Los Angeles, running production email and DNS on FCC-revoked Section 214 infrastructure. Every finding ships with the RDAP query, the DNS check, and the cross-reference that verifies it. Every finding ships with the RDAP query, the DNS check, and the cross-reference that verifies it. Attendees leave knowing which four sources to line up, which fields to trust, and what to look for when two dated snapshots disagree.

[Sunday, August 9]
10:00 AM – 10:45 AMSunday, August 9DEF CON Creator Stage 2

People are getting hired and trusted every day. Some of them do not exist at all, yet they still pass interviews, collect paychecks, and gain access to sensitive systems. Campaigns attributed to the DPRK have shown that this threat is very real. So how do you catch a ghost with a resume? Attendees will learn practical OSINT techniques for spotting fake personas and receive a checklist for thorough background checks. They will see these methods applied through two cases based on a true story, illustrating how these personas succeeded, how one could have been prevented, and where OSINT reaches its limits. These techniques not only help attendees detect fake personas but also provide practical ways to protect their own privacy and control what personal information is visible online.

10:45 AM – 11:30 AMSunday, August 9DEF CON Creator Stage 2

Building AI-Powered Penetration Testing Bots In this talk, we'll walk through the core design philosophy behind AI hackbots and the architecture that makes them work: single-purpose vs. multi-stage bots, context engineering for targeted prompting, and tool integration with output parsing workflows. Then we'll get hands-on. We'll live-build a functional hackbot for a common offensive task — demonstrating asset discovery, endpoint analysis, or mutation-focused testing (e.g., XSS/SSRF) — and show how context engineering and hallucination mitigation work in practice against real targets. You'll see where AI genuinely accelerates reconnaissance and web analysis, and where it falls flat if you aren't careful. We'll close with lessons on cost optimization, auditability, and integrating hackbots into actual engagements. Who should attend: Pentesters and bug bounty hunters with offensive security experience who want to meaningfully integrate AI into their workflow — not as a novelty, but as reliable tooling. What you'll walk away with: A clear mental model for when and how to build hackbots, a live demo you can replicate, and a path into the full course where you'll build seven production-ready bots from asset discovery through mutation testing.

12:00 PM – 12:30 PMSunday, August 9DEF CON Creator Stage 5

You scrape a public site. You enumerate subdomains. You grep GitHub for secrets. You curl a misconfigured API. Each one touches a statute. Some have been to the Supreme Court. Most operators don't know which is which — until the preservation letter arrives. A federal-court-qualified expert witness (U.S. v. Sullivan) walks through five live OSINT techniques with real-time legal annotation. Zero lawyer-speak. GitHub release included.

12:30 PM – 1:00 PMSunday, August 9DEF CON Creator Stage 5

LLM-powered tooling is becoming a force multiplier for attackers, from reconnaissance automation to post-exploitation enumeration. Using their own API keys creates attribution and cost, so they look for alternatives. Thousands of inference endpoints sit exposed on the internet: misconfigured Ollama instances, open vLLM deployments, leaked API keys in directory listings, and expired OAuth tokens from AI coding assistants that can be silently refreshed. Attackers can discover these resources and use them as free compute for their operations, without spending a dollar or registering an account. Attendees will learn how to: •⁠ ⁠Discover exposed inference endpoints and leaked API keys using Infreerence •⁠ ⁠Validate that discovered resources provide usable inference access •⁠ ⁠Operate Echidna, powered entirely by discovered inference •⁠ ⁠Chain LLM skill agents together to execute a guided campaign against a target network Current LLMs are effective force multipliers when directed, and significantly more so when the compute bill goes to someone else. This is resource hijacking applied to the AI era: living off someone else's inference. Understanding this threat is essential for any organization deploying or exposing AI infrastructure. Two tools will be released as open source during the session: •⁠ ⁠Infreerence: A multi-phase scanner and dashboard that discovers exposed inference endpoints and leaked API keys through Shodan and Censys, validates them against live provider APIs, and catalogs usable inference resources across 10+ providers. •⁠ ⁠Echidna: A Mythic C2 agent type that consumes discovered inference endpoints and turns them into operator-directed skill agents for reconnaissance, exploitation planning, post-exploitation, and lateral movement.