# kamikos

- **Event:** [Built with Opus 4.7: a Claude Code hackathon](https://cerebralvalley.ai/e/built-with-4-7-hackathon)
- **When:** Apr 21 at 12:00 PM – Apr 27 at 2:00 AM (EDT)
- **Where:** Online
- **Team:** [Kamil Orzechowski](https://cerebralvalley.ai/u/kamikos)
- **GitHub:** https://github.com/kamikos/Kosa
- **Demo video:** https://youtu.be/3svCBbPh61c
- **Gallery:** https://cerebralvalley.ai/e/built-with-4-7-hackathon/hackathon/gallery
- **Page:** https://cerebralvalley.ai/e/built-with-4-7-hackathon/hackathon/gallery/145

Kosa is an agentic Attack/Defense CTF toolkit.

In a typical eight-hour ad ctf, a team has to repeat the same loop every minute: watch scoreboard, inspect suspicious network flows, reconstruct working exploits, patch vulnerable services without breaking the checker, and attack dozens of other teams before they fix the bug. At that pace, the challenge becomes less about individual hacking skill and more about keeping the whole workflow synchronized.

Kosa wraps that loop around a Claude Opus 4.7 dispatcher. It ingests scoreboards from FAUST, Enoflag, and ATKLAB; consumes traffic from Tulip, pcaps, and JSON logs; reconstructs exploit candidates from observed flag-stealing flows; proposes patches; validates them against the live checker; and deploys through gated approval. Every action is auditable and constrained by explicit allowlists.

Kosa supports two modes: manual mode, where Kosa acts as a dashboard and gated submitter, and autonomous mode, where the dispatcher drives the loop end to end. It is designed to complement existing A/D tooling such as Tulip for traffic capture and Ataka for exploit farming, rather than replacing them.

Kosa also ships with a fully Dockerized three-team A/D lab, letting you run the entire workflow locally in about five minutes.

---

Markdown version of https://cerebralvalley.ai/e/built-with-4-7-hackathon/hackathon/gallery/145. Site index for agents: https://cerebralvalley.ai/llms.txt · full text: https://cerebralvalley.ai/llms-full.txt
