Principal Scientist at Security Risk Advisors
Evan Perotti is a Principal Scientist at Security Risk Advisors, focused on research and development within the offensive security space, with specialties spanning threat intelligence, AWS security, Windows endpoint security, and purple teaming. He is the primary creator of Security Risk Advisors' annual threat intelligence test plans, identifying the underlying threat intelligence for each exercise and turning that research into actionable test cases and complete test plans, and he helps lead the resulting workshops with contributors. Evan is the author of Market Maker, the tool he built to create threat simulation plans, and ALLCAPS, a capability-based payload generation framework used to execute the resulting test cases. He has presented at BSides Pittsburgh, BSides Philly, ShellCon, BSides Chicago, and Insomni'hack, and writes regularly on his blog.
17:00-18:00 PDT | Friday, Aug 7th 2026 | Adversary Village Workshop Stage, Las Vegas Convention Center Panel Discussion
Panel with: Joseph Hall, Nikhil Shrivastava
Adversary simulation has always been constrained by people. Building an emulation plan from threat intelligence, standing up infrastructure, executing the chain, and working through detection gaps with the blue team takes weeks of skilled operator time, which is why most organizations run these exercises once or twice a year instead of continuously.
AI systems are starting to change that math. Agentic tooling can parse intelligence reports into executable emulation plans, run attack chains autonomously against lab and production-adjacent environments, and iterate on technique variations far faster than a human operator can. This panel looks at what that actually delivers today. Panelists will discuss where agents produce credible threat actor behavior and where they generate plausible looking noise, how much operator oversight is still required, what it means for purple team exercises when the red side can execute a hundred variations of a technique overnight, and whether blue teams can consume that volume of signal in any useful way.
The conversation also covers the harder questions: fidelity against real adversary tradecraft, safety and scope control when an autonomous agent is executing offensive actions, and whether faster simulation actually produces better detections or just more tickets.
Attendees will leave with a grounded view of where AI assisted adversary simulation is genuinely working, where it falls short, and what it takes to run it responsibly.
Agency.
Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!