Stav David is a security researcher and founder who builds automated offensive security infrastructure. He started by building multi-cloud DDoS attack simulation tooling - real bot fleets testing whether mitigation vendors actually block what they claim to block. The recon pipeline he built to enumerate attack surfaces kept surfacing more than DDoS vectors: SSRF vulnerabilities, exposed internal services, configuration weaknesses at the infrastructure layer. He automated the vulnerability research loop using LLM reasoning to cluster findings and surface root causes at scale, which is what this talk is about. His infrastructure currently spans 13 cloud providers. He reports findings via HackerOne responsible disclosure.
linkedin.com/in/stavdavid/
ddactic.net/blog (blog)