Senior Principal Troublemaker, Oracle Red Team
Michael (@r00tkillah) has done hard-time in real-time. An old-school
computer engineer by education, he spends his days hacking the
mothership for a fortune 100 company. Previously, he developed and
tested embedded hardware and software, fooled around with strap-on
boot roms, mobile apps, office suites, and written some secure
software. On nights and weekends he hacks on electronics, writes CFPs,
and contributes to the NSA Playset.
11:00-11:30 PDT | Sunday, Aug 9th 2026 | DEF CON Creator Stage 3, Las Vegas Convention Center Talk
Co-presented with: Niranjanaa Ragupathy
Red Teaming is about thinking and acting like an attacker to improve an organization's defenses. In practice, it is less about flashy exploits and more about providing prioritization signals, validating and improving detection capabilities, and telling compelling stories that drive meaningful security outcomes.
The rise of AI has introduced a new challenge and a new mandate. Organizations are increasingly asking Red Teams to "use AI to hack things" as both attackers and defenders race to understand what AI can and cannot do. To cut through the hype, the role of Red Teams to speak truth to power is more important than ever.
Our responsibility is to separate speculation from reality. To understand the capabilities of AI-powered attackers, assess how well our defenses stand up against them, and evaluate the risks introduced by new AI-driven attack surfaces. By doing so, we help organizations make informed decisions about where to invest, what to defend, and how to prepare for the threats that matter most.
* whoami
* Adversarial Simulation
* The hidden cost of accuracy
* When realistic simulations are expensive
* Why perfectly emulating attackers is not always the goal
* Attacker diversity
* Different attackers have different objectives and tradecraft
* How do we cover the right ones?
* Role of a Red Team in an organization
* Provide prioritization signals
* Where should the organization invest resources?
* Separating the signal from the noise
* Sparring partner for Blue Team
* Find balance between overt and covert to avoid burnout
* Avoiding overfitting to the Red Team attacker
* Creating effective feedback loops
* Storytellers who drive change
* Turning technical findings into compelling narratives
* Making risk understandable
* Speaking truth to power
* Independent assessment of security posture
* Challenging assumptions
* Red Teaming and AI
* Understanding how attackers are using AI
* Benchmarking to understand current vs. perceived capability
* Leveraging AI responsibly
* Defending against AI powered attackers
* How do our current controls fare?
* What are new controls we can develop
* Distinguishing between a rogue agent, malicious insider, compromised insider
* Protecting the AI attack surface
* Agents that are eager to please
* Targeting models or training data
* Closing
* The value of a Red Team is not the cool hacks. It is in helping organizations understand reality, prioritize risk, and make better security decisions. This is especially important when the technology landscape is changing faster than anyone fully understands.
Agency.
Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!