DEF CON 33 - Orion: Fuzzing Workflow Automation - Max Bazalii, Marius Fleischer

DEF CON 33 - Orion: Fuzzing Workflow Automation - Max Bazalii, Marius Fleischer

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 44:21

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Orion automates the entire fuzzing workflow using AI agents to identify targets, generate harnesses and seeds, reproduce bugs, and create patches—reducing manual effort and improving bug detection. 2:55

Key Takeaways:
• Orion uses agentic loops to automate fuzzing from target selection to patch generation, with each phase validated by trusted tools like compilers and sanitizers 5:03
• AI agents analyze code to identify high-risk interfaces, generate harnesses with proper dependencies and cleanup, and produce valid seeds that avoid crashes 6:43
• A validation loop ensures generated code and patches are reliable; patches must pass reproducer tests and human review before deployment 10:23
• Orion achieved 95% accuracy in interface analysis and high success rates in harness generation, with 70% of patches accepted after validation 21:44

Orion significantly reduces time spent on manual fuzzing tasks, saving days to weeks per target, and has found hundreds of memory corruption bugs in real-world codebases 23:13

Sources:

  • 2:55 Overview of Orion’s automation goals and core loop
  • 5:03 Explanation of agentic workflow and validation loops
  • 6:43 Details on harness and seed generation with code analysis
  • 10:23 Patch generation and validation process
  • 21:44 Benchmarking results and patch acceptance rate
  • 23:13 Time savings and re

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right. Uh, hi everyone. Welcome to Devcon. Today we'll talk about Orion like a system we built to automate the entire fingertips even like creating fixes. This work is collaboration between me and Marios. We both spent many years creating offensive security tooling. So Orion is our way to make fuzzing smarter, faster, and frankly less painful. All right. Um, let's talk who we are. I'm Max Bazali, a leading offended security team at NVIDIA drivers. Main focus right now is like discovery of vulnerabilities using AI tools, formal methods and like general security research. Before Nvidia, I was doing a lot of research on Apple operating systems. Uh, creating jailbreaks for iOS and watch. Actually I present very first Apple Watch jailbreak here at Defcon 25 many years ago. During the time w…