[Speakers]
Adversary Village at
DEF CON 34

Duane Dunston

Cybersecurity Training for Everyone

Dr. Duane Dunston, EdD was a Senior Adversarial Engineer at Cloud Range where he created cyberattacks within a live range and trained corporate cybersecurity teams to identify and respond to the attacks. Duane was previously an Associate Professor of Cybersecurity at Champlain College from 2012 - 2022. He has been in Information Security since 1997 working in the education, government, and private sectors. He focuses on risk management, red and blue team training development, security education, threat intelligence, threat hunting, and using technology for social change.

Hiding Infrastructure in Plain Sight

13:00-13:25 PDT | Saturday, Aug 8th 2026 | Adversary Village Hands-on Activity Area, Las Vegas Convention Center
Tool Demo

Abstract

When performing adversary emulation for training SOC analysts, incident responders and threat hunters, tools are employed within a platform to monitor the status of the attack flow and participant behaviors. For example, training providers or in-house training platforms may use computer based agents to perform activity to simulate users authenticating to a host, opening files, browsing the web, uploading and downloading files, monitoring 'flags' to determine if they were detected and removed, or an instructor may be watching user's as they participate via a remote access program.


When it is time for the participants to engage in investigating the attack, they may encounter the applications that are used to perform the infrastructure tasks, such as the simulated computer use. That could potentially confuse the participant or cause them to go down rabbit holes investigating the infrastructure backend processes and not the intended processes that are part of the emulation. For instance, if they see a tool like Veyon, or TacticalRMM, they could confuse that for the attacker's tools. Rather, those could be the instructor or host monitoring their activity (Veyon) or the tool used to manage the dozens of VMs that may be employed (TacticalRMM) for the learning and training platform.


One method to mitigate this issue is to have a list of what to ignore and the participants have to keep checking that list, if they remember.


I am proposing the use of "Phantom Infra." An eBPF program I created to hide infrastructure tasks and processes so users can focus on capturing the flags and honing their threat hunting skills and not chase rabbit holes or become confused by infrastructure processes. This allows adversary emulation activities to run with many distractions and allows the creators of the simulation to perform activities on the host to prepare and stage files for a successful simulation.


This is useful and targeted for training purposes and for education based adversary emulation exercises or CTF events where users are actively logged into an OS and performing activities to learn and hunt for adversary TTPs.

Tool demo outline

- Present the current issues of hiding infrastructure during adversary simulations. 5 minutes
- Brief explanation of eBPF. 5 minutes
- Demonstrate a full adversary simulation and show what the participant sees using native and well-known third-party tools to enumerate the host. 10 minutes
- Show what the simulation looks like without Phantom Infra using the same enumeration techniques. 5 minutes
- Conclusion. - 1 minute
- Q&A. 4 minutes.

Agency.


Join Adversary Village Discord Server.

Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!