AI Hacking Jam #1: Build offensive & defensive AI security projects inspired by the ANCPI breach
Recently the Romanian institution that manages all the public records for cadastral numbers and real estate ownership was breached. Consequently, no property has been bought or sold for the last three weeks because their platform is down.
A public technical report on the ANCPI ransomware incident describes a familiar but brutal chain:
Exposed service → initial foothold → secrets and credentials → lateral movement → identity and management-plane access → backups, virtual machines and source code → encryption, deletion and extortion
This is the backbone of the hackathon.
Not because we want to recreate the breach. Because it gives us a real Romanian story about how infrastructure actually falls apart - and a thousand interesting things to build around it.
Bring your own idea, setup and stack. Use local models, APIs, agents, existing security tools, stuff you build from scratch, or whatever combination gets you to a fun working demo.
You can rebuild something that already exists with AI. You can make an AI layer on top of it. You can automate it. You can connect five tools that normally never talk to each other.
Just build something. Demo it. Have fun.
🔥 Pick a phase
1. Find the exposed thing
AI recon copilot, local attack-surface mapper, CVE hunter, “what would I attack first?” tool. Public-exposure auditor, patch-debt prioritiser, internet-facing asset inventory
2. Get a foothold
Safe exploit validator for your own app, web-app testing agent, auth-flow mapper. Web-shell detector, unsafe endpoint finder, application hardening assistant
3. Find secrets
Repo/config intelligence agent, credential discovery tool, source-code treasure map. Secret scanner that understands context, credential rotation planner, reversible-encryption detector
4. Move sideways
AI attack-path mapper, credential-reuse graph, “what does this account unlock?” simulator. Micro-segmentation planner, forbidden-path detector, identity Tier 0 auditor
5. Reach the crown jewels
Safe virtualisation identity / backup exposure mapper. vCenter and ESXi anomaly detector, privileged-access firewall, backup-isolation checker
6. Cause impact
Ransomware-chain simulator, destructive-action decision model, red-agent versus blue-agent battle. Early-warning detector for shutdown/deletion encryption patterns, immutable-backup validator
7. Respond
Adversary-emulation simulator, deception or honeypot projectAI incident-response copilot, timeline reconstructor, evidence-gap detector, detection-rule generator
You do not need to build the whole chain. A great project can be one weird, sharp idea around one tiny part of it.
👾 Things you might build
An AI-powered version of a vulnerability scanner.
A local model that reads a Git repository and explains which secrets actually matter.
A graph that shows how one reused password becomes access to an entire organisation.
An agent that proves whether production workloads can reach vCenter, AD, backups or monitoring.
A ransomware early-warning dashboard for virtualisation environments.
A tool that reads logs and tells the ANCPI story as a timeline—with confidence levels and missing evidence.
A local AI SOC assistant.
An agent firewall that blocks dangerous tool calls.
An “AI BloodHound” for identity, network and infrastructure relationships.
An “AI Nuclei” that turns approved test results into useful attack-path evidence.
A safe worm or lateral-movement visualisation.
A game where red agents try to reach a synthetic crown jewel and blue agents try to stop them.
Something that makes us say, “this should probably exist.”
The tools already exist. That is not a problem.
The question is whether AI can make them more connected, more understandable, more autonomous, more defensive, more fun—or more dangerous in a way that teaches us something useful.
🕹️ Format
Solo or teams of 2–3
Six-hour build sprint
Bring your own laptop, tools and environment
Final demos at the end
Five minutes per project
Winners chosen by audience vote
Drinks after the demos
🚀 What to submit
A working demo: live, local or safely simulated
A one-paragraph description
Which stage of the ANCPI story inspired it—or why you ignored the brief
How AI was used: to build it, run it, analyse it or all three
What is real versus simulated
Optional: GitHub repo, screenshots, video or write-up
🗳️ What we vote for
Does it work?
Is it fun, sharp or surprising?
Does it connect to a real security problem?
Did AI meaningfully help build or run it?
Can you demo it in five minutes without a 40-slide deck?
⚠️ Tiny but important rule
The ANCPI incident is a public case study—not a target.
Only test systems, accounts and data you own or are explicitly authorised to use. Keep destructive behaviour, credential theft, worms and ransomware experiments inside your own environment or a simulation.
Come build the thing you wish had existed before the breach. Or the thing an attacker would wish existed during it.
Then stay for drinks 🍸
Hosted by Builders House & Bukarest Hackers
Shouts to eu-acc.ro & ambasada