BugBase, Co-founder & CTO
Sitaraman Subramanian is the CTO at BugBase. He has spent over five years working in offensive security and over a decade building products. His work spans full stack development, DevSecOps, cloud security, and offensive security. He built BugBase from the ground up, and now leads engineering on Pentest Copilot, an autonomous AI driven pentesting platform. He presented at Black Hat USA Arsenal in 2025 and Microsoft BlueHat in 2024. He is eJPT certified and a holder of the Certified AI/ML Pentester credential. He is an active open source contributor. Pentest Copilot is open sourced at https://github.com/bugbasesecurity/pentest-copilot, with 850+ stars and growing. He writes about hacking and AI evals at https://blog.ssitaraman.com.
12:30-12:55 PDT | Saturday, Aug 8th 2026 | Adversary Village Hands-on Activity Area, Las Vegas Convention Center Tool Demo
Co-presented with: Dhruva Goyal
Pentest Copilot is an MIT licensed open-source offensive security workspace built to assist operators during internal assessments.
This demonstration focuses on Active Directory operations.
During internal assessments, operators spend significant time reviewing BloodHound data, analyzing attack paths, identifying privilege escalation opportunities, investigating credentials, and deciding which actions are worth pursuing next.
Pentest Copilot helps reduce that analysis overhead by combining attack-path data, assessment context, operator objectives, and offensive tooling into a single workspace.
The demonstration will show how Pentest Copilot can assist with:
- BloodHound attack-path analysis
- Privilege escalation path identification
- High-value target discovery
- Credential exposure analysis
- Lateral movement planning
- Assessment note-taking and evidence tracking
The focus of the session is practical operator workflows and how autonomous systems can assist during adversarial operations without removing the human from the decision-making process.
Project: https://github.com/bugbasesecurity/pentest-copilot, 800+ GH stars
Introduction (3 min)
* Why internal assessments generate more information than a human can realistically process
* Overview of the multi-agent architecture
* Human-in-the-loop design philosophy
Initial Foothold and Situational Awareness (5 min)
Starting from a single compromised workstation:
* Agent receives initial context
* Enumeration objectives are automatically generated
* Local privilege escalation opportunities identified
* Relevant offensive tooling selected
* Findings stored and shared across agents
Demonstration of how agents build an operational picture from limited initial access.
Active Directory Enumeration and Attack Path Discovery (7 min)
* SharpHound/BloodHound data ingestion
* Relationship analysis
* Identification of privileged groups
* Discovery of shortest paths to Domain Admin
* Detection of misconfigurations and privilege escalation opportunities
Demonstration of how attack paths are prioritized and presented to the operator.
Autonomous Offensive Operations (7 min)
Agents execute and coordinate offensive workflows including:
* Credential harvesting opportunities
* Kerberoasting identification
* AS-REP roasting opportunities
* Delegation abuse paths
* ACL abuse opportunities
* Lateral movement candidate selection
Discussion of how agents decide what to investigate next and how findings from one workflow influence others.
Human + Agent Collaboration (4 min)
* Operator reviews attack paths
* Operator approves or redirects execution
* Agents generate supporting evidence
* Agents explain reasoning and proposed actions
* Multiple attack paths compared simultaneously
Demonstration of how operators remain in control while offloading analysis and prioritization.
Scaling Beyond A Single Host (2 min)
* Multi-host operation
* Shared memory and findings
* Agent coordination
* Expanding attack surface during large internal assessments
Lessons Learned (2 min)
* Where autonomous analysis provides the most value
* Failure cases encountered during development
* Areas where human judgment remains critical
* Future work
Agency.
Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!