BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Purple teaming? Simulating the Adversary in the Worl
 d of AI\n   systems\n   Tags: Adversary Village | Creator Talk/Panel\n   W
 hen: Friday\, Aug 7\, 17:00 - 17:59 PDT\n   Where: LVCCW Level 1 Hall 2 60
 2 (Adversary Village) Workshop Stage -\n   [1]Map\n\n   Description:\n\n  
  Adversary simulation has always been constrained by people. Building\n   
 an emulation plan from threat intelligence\, standing up\n   infrastructur
 e\, executing the chain\, and working through detection\n   gaps with the 
 blue team takes weeks of skilled operator time\, which is\n   why most org
 anizations run these exercises once or twice a year\n   instead of continu
 ously.\n\n   AI systems are starting to change that math. Agentic tooling 
 can parse\n   intelligence reports into executable emulation plans\, run a
 ttack\n   chains autonomously against lab and production-adjacent environm
 ents\,\n   and iterate on technique variations far faster than a human ope
 rator\n   can. This panel looks at what that actually delivers today. Pane
 lists\n   will discuss where agents produce credible threat actor behavior
  and\n   where they generate plausible looking noise\, how much operator\n
    oversight is still required\, what it means for purple team exercises\n
    when the red side can execute a hundred variations of a technique\n   o
 vernight\, and whether blue teams can consume that volume of signal in\n  
  any useful way.\n\n   The conversation also covers the harder questions: 
 fidelity against\n   real adversary tradecraft\, safety and scope control 
 when an autonomous\n   agent is executing offensive actions\, and whether 
 faster simulation\n   actually produces better detections or just more tic
 kets.\n\n   Attendees will leave with a grounded view of where AI assisted
 \n   adversary simulation is genuinely working\, where it falls short\, an
 d\n   what it takes to run it responsibly.\n\n   Speakers:Evan Perotti\,Jo
 seph Hall\,Nikhil Shrivastava\n\n   SpeakerBio:  Evan Perotti\, Principal 
 Scientist at Security Risk\n   Advisors\n\n   Evan Perotti is a Principal 
 Scientist at Security Risk Advisors\,\n   focused on research and developm
 ent within the offensive security\n   space\, with specialties spanning th
 reat intelligence\, AWS security\,\n   Windows endpoint security\, and pur
 ple teaming. He is the primary\n   creator of Security Risk Advisors' annu
 al threat intelligence test\n   plans\, identifying the underlying threat 
 intelligence for each\n   exercise and turning that research into actionab
 le test cases and\n   complete test plans\, and he helps lead the resultin
 g workshops with\n   contributors. Evan is the author of Market Maker\, th
 e tool he built to\n   create threat simulation plans\, and ALLCAPS\, a ca
 pability-based\n   payload generation framework used to execute the result
 ing test cases.\n   He has presented at BSides Pittsburgh\, BSides Philly\
 , ShellCon\, BSides\n   Chicago\, and Insomni'hack\, and writes regularly 
 on his blog.\n\n   SpeakerBio:  Joseph Hall\, Threat-Intel Leader\n\n   Jo
 seph Hall is a Threat-Intel Leader joining the Adversary Village\n   panel
  at DEF CON 34.\n\n   SpeakerBio:  Nikhil Shrivastava\, Organizer\, BSides
  Ahmedabad\n   Panel with: Evan Perotti\, Joseph Hall\n   Abstract\n   Adv
 ersary simulation has always been constrained by people. Building\n   an e
 mulation plan from threat intelligence\, standing up\n   infrastructure\, 
 executing the chain\, and working through detection\n   gaps with the blue
  team takes weeks of skilled operator time\, which is\n   why most organiz
 ations run these exercises once or twice a year\n   instead of continuousl
 y.\n\n   AI systems are starting to change that math. Agentic tooling can 
 parse\n   intelligence reports into executable emulation plans\, run attac
 k\n   chains autonomously against lab and production-adjacent environments
 \,\n   and iterate on technique variations far faster than a human operato
 r\n   can. This panel looks at what that actually delivers today. Panelist
 s\n   will discuss where agents produce credible threat actor behavior and
 \n   where they generate plausible looking noise\, how much operator\n   o
 versight is still required\, what it means for purple team exercises\n   w
 hen the red side can execute a hundred variations of a technique\n   overn
 ight\, and whether blue teams can consume that volume of signal in\n   any
  useful way.\n\n   The conversation also covers the harder questions: fide
 lity against\n   real adversary tradecraft\, safety and scope control when
  an autonomous\n   agent is executing offensive actions\, and whether fast
 er simulation\n   actually produces better detections or just more tickets
 .\n\n   Attendees will leave with a grounded view of where AI assisted\n  
  adversary simulation is genuinely working\, where it falls short\, and\n 
   what it takes to run it responsibly.\n\n   Links:\n       adversaryvilla
 ge.org/adversary-events/DEFCON-34/ - [2]https://adversaryvillage.org/adver
 sary-events/DEFCON-34/\n   '\n\n   1. #LVCCW_Level1_Hall2\n   2. https://a
 dversaryvillage.org/adversary-events/DEFCON-34/\n\n\n
DTEND:20260808T005900Z
DTSTART:20260808Z
LOCATION:Adversary Village - LVCCW Level 1 Hall 2 602 (Adversary Village) W
 orkshop Stage
SUMMARY:Purple teaming? Simulating the Adversary in the World of AI systems
END:VEVENT
END:VCALENDAR
