AIFT - Associate GenAI Security Researcher
I am currently working as a Associate Associate GenAI Security Researcher at AIFT. Over the past year, I have presented various cybersecurity-related research topics at more than 20 domestic and international conferences (DEFCON, ROOTCON, BSides..). I enjoy conducting research, especially focusing on AI/ML applications this year. By engaging with different technical domains, I aim to solve cybersecurity problems, uncover vulnerabilities across various platforms, and identify new CVE vulnerabilities. I have found vulnerabilities in multiple platforms, including Google, Cloudflare, open-source projects, and educational institutions. Learning and research have become the central focus of my life.
Blog: https://no-flag.com/
14:45-15:15 PDT | Friday, Aug 7th 2026 | DEF CON Creator Stage 3, Las Vegas Convention Center Talk
Co-presented with: Ariz Soriano
Cyber deception research has spent decades placing honeypots, honeyfiles, and fake credentials in enterprise environments to catch attackers. Yet practitioners in real Security Operations Centers do not investigate individual artifacts in isolation - they construct causal narratives to explain sequences of events, routing attention toward high-severity signals, end-of-attack-chain activities, and operations in sensitive infrastructure. As Sundaramurthy et al. documented through ethnographic study of live SOC environments, analyst behavior under alert overload is governed by triage heuristics and pattern-matching rather than systematic evidence review - creating a systematic cognitive attack surface that no existing offensive framework has been designed to exploit.
In this work, we introduce SEND (Self-Evolving Narrative Deception), an adversary simulation framework that reframes offensive deception as an investigation narrative poisoning problem: the objective is not to evade detection, but to corrupt the causal story defenders reconstruct during incident response. Drawing on direct consultation with active SOC analysts and incident responders, we identify three empirically grounded cognitive attack vectors that structure the SEND action space - (a.) severity escalation exploitation, targeting the operational requirement to fully investigate HIGH/CRITICAL alerts regardless of underlying harm, (b.) end-of-chain activity simulation, targeting mandatory runbook escalation triggered by ransomware staging or exfiltration patterns regardless of actual file content, and (c.) sensitive location poisoning, targeting the elevated investigative attention guaranteed by activity near domain controllers, privileged shares, and executive endpoints.
We present a design analysis showing that each attack vector can be instantiated at negligible red team cost - failed LSASS reads, dummy outbound transfers of random bytes, and mass-created ransomware-extension files are designed to generate the same mandatory investigation burden as their genuine counterparts, without requiring those actions to succeed. A key design distinction structures the SEND action space: activity simulation generates authentic system telemetry that defenders cannot distinguish from genuine attacker behavior at the telemetry level, while artifact implantation provides cross-system narrative coherence. A Narrative Consistency Engine coordinates both modalities using an LLM to ensure every fabricated email thread, file access log, and collaboration platform entry supports a single coherent false story - shifting the defender's task from "did something anomalous happen?" to "which of several plausible explanations is true?"
Moreover, to enable rigorous evaluation of narrative deception beyond detection evasion metrics, we introduce the Investigation Narrative Divergence Reward (INDR) - a four-dimensional cognitive metric quantifying divergence across event reconstruction, causal graph structure, inferred attacker intent, and attribution outcome. INDR is designed to capture a class of deception success that existing red team metrics cannot measure: a defender may correctly identify every process in a malicious process tree yet still produce an incident report attributing the wrong objective, wrong actor, and wrong scope. We further formalize Investigation Graph Poisoning as a measurable attack surface, and outline experimental protocols for evaluating SEND across SOC environments of varying maturity, tooling, and analyst expertise.
In conclusion, SEND establishes the incident investigation itself as a first-class attack surface in adversary simulation, derives deception strategy from empirically grounded blue team cognitive prioritization rather than intuition, and proposes INDR as a new evaluation metric for simulation fidelity - one that asks not whether a simulation triggered alerts, but whether it distorted the reasoning of the defenders who responded to them. Our framework operationalizes at a systematic level what nation-state actors have long practiced intuitively, and makes that threat model legible enough for both red teams and defenders to reason about and build against.
00:00 - 03:00 | Introduction: The Illusion of Evasion
Visual & Conceptual Hook: Opening on the dark title theme, I will challenge the reflex that has driven offensive security for decades — the obsession with stealth and "how do I avoid being detected?" Modern SOCs catch anomalies, so the sharper question is "what story explains these events?"
Reframing the Attack Surface: Using a cold open where every red-team action was detected yet the incident report was still wrong, I will state the thesis — the attack surface is the investigation, not the detection; we poison the investigation graph rather than drop fake files.
03:00 - 07:00 | The Defender's Mindset: Why This Works
How SOCs Actually Triage: I will ground the attack in reality — under alert overload analysts run on fatigue, heuristics, and pattern matching, and that predictable behavior is itself a repeatable cognitive attack surface.
The Three Vectors & the Shift: I will name the levers that manufacture investigation pressure — Severity Escalation Bias, End-of-Chain actions, and Sensitive Locations — and argue a plausible false story built on coherent telemetry is more dangerous than a real attack that looks anomalous.
07:00 - 13:00 | Weaponizing the Narrative: How SEND Works
SEND & the Core Asymmetry: I will frame SEND as an adversary-simulation framework that optimises the defender's investigation graph, driven by a three-tier priority engine and a MITRE-mapped action library — and expose why it's cheap: the red team needs actions only to log, not to succeed.
The Narrative Engine & the Metrics: I will show how an LLM aligns every artifact to a single false story, shifting the analyst from "did something happen?" to "which explanation is true?", and introduce the Poison Ratio and the composite INDR reward that SEND optimises.
13:00 - 18:00 | Live Demo
The Range & the Scenario: I will switch to a monitored AD range where every alert traces to a real event, and set the trap — one genuine domain compromise (mgarcia to NTDS.dit) hidden beneath a loud bsmith decoy — then show the decoy dominating the SIEM queue while the real compromise sits in plain sight.
The Reveal: I will open the generated report — truth versus reconstruction with plain-language captions — with a recorded capture as fallback if the live range is unavailable.
18:00 - 24:00 | Measuring the Poison: Validation & Conclusion
Confidently Wrong: I will show detection scores this a clean catch while every dimension of INDR is wrong, and that the real danger is a confident analyst who reconstructed the wrong incident — confirmed at scale and by a human pilot, where half the practitioners named the wrong actor and one rebuilt the real attack yet still blamed the plant.
The Minimal Strategy & the Takeaway: I will show three evolved actions reproducing almost all of the misdirection at a fraction of the cost, confirmed live, and leave the room with one mandate — measure whether the report is true, not whether the alert fired.
24:00 - 25:00 | Q&A
Agency.
Join Adversary Village official Discord server to connect with our amazing community of adversary simulation experts and offensive security researchers!