Marauders Map as Code: I Solemnly Swear I Am 0wning GitOps Infrastructure
IaC repositories are complete maps of your infrastructure. MMaC is an AI-driven offensive tool that reads those repos, reconstructs your environment topology, profiles contributor behavior using Theory of Mind research, and generates targeted, timed attacks — without ever touching your live systems.
GitOps practices and Infrastructure as Code tooling have quietly created one of the most underguarded attack surfaces in modern security: the IaC repository. Terraform configs, CDK synthesis output, Helm values, and pipeline definitions collectively reconstruct your full environment topology — no live access, no state queries required.
Marauders Map as Code (MMaC) is an offensive tool that operationalizes this insight. From repository access alone, MMaC uses an LLM agentic layer to reconstruct infrastructure topology, map service dependencies and IAM relationships, and score attack paths by blast radius. It then applies published Theory of Mind research (arXiv corpus) to Agile artifact and ceremony data — sprint backlogs, PR velocity, retro outputs, commit patterns — to identify which contributors and processes are most exploitable, and precisely when.
The result is targeted, timed attacks delivered through the pipeline automation surface rather than direct infrastructure — because pipelines survive redeploys, span environments, and leave no anomalous network signatures. When MMaC determines direct infrastructure compromise is the higher-value path, it selects it automatically. Payloads are marshaled and persisted through legitimate workflow scheduling engines: Jira automations, ServiceNow workflows, Kubernetes CronJobs, and CI/CD pipeline schedules themselves — surviving incident response and cleanup operations that look for traditional IOCs.
This talk demonstrates the MMaC architecture, the contributor intelligence layer, the pipeline-first attack philosophy, and the evasion characteristics of scheduling-hook persistence. Demo runs live against a Proxmox-managed lab environment. Defensive implications and detection opportunities are covered.
datapleX has been active in the hacker community since the early 1990s, with roots in BBS culture, phreaking, and the IRC underground. He co-founded the first Computer Security Association at UTSA in 2004 and captained the UTSA team for the inaugural Collegiate Cyber Defense Competition in 2005. His work sits at the intersection of offensive security, software engineering, and AI — treating attack surfaces as code problems rather than compliance exercises. He is the author of Marauders Map as Code, conducts active research through thisisunsafe.ai, and is working on hAIvenet. He holds 35 years of experience across offensive and defensive security and the GCP Professional Cloud Architect certification. Consultant. Hacker. Occasionally correct.