Skip to content

Cyber Resilience for Agentic AI: Learnings from the Hugging Face attack

September 15, 2026 - 10 AM PST/1 PM EST

The recent Hugging Face security incident involving misaligned AI agents provides a glimpse into a new era of cyber threats—where autonomous agents can perform reconnaissance, escalate privileges, move laterally, and interact with production infrastructure with minimal human involvement.

For healthcare security teams, this introduces a critical challenge: how do you identify the malicious attack path among thousands of seemingly legitimate actions generated at machine speed?

Join Suril Desai, VP of Detection Engineering at Acalvio, for a practitioner-focused discussion on what the Hugging Face incident reveals about agentic AI attacks and the implications for healthcare cybersecurity. Suril will examine how these attacks differ from traditional human-led threats and explore strategies for building cyber resilience by detecting and disrupting adversarial activity earlier in the attack lifecycle—starting at the reconnaissance phase, before attackers reach critical systems and data.

Attendees will gain practical insights into the anatomy of agentic AI attacks, the detection challenges they create, and how preemptive defense can help healthcare organizations prepare for autonomous, machine-speed threats.

Suril Desai
Suril Desai
VP Detection Engineering
Acalvio
Transcript

3
00:00:43.320 –> 00:00:47.959
Anand Akela: Good morning, good afternoon, depending on where you’re calling from.

4
00:00:48.790 –> 00:00:52.399
Anand Akela: We’ll wait for another minute as people are coming in.

5
00:00:52.720 –> 00:00:54.320
Anand Akela: And then we’ll get started.

6
00:00:55.020 –> 00:00:58.939
Anand Akela: Wait for another… 25 seconds or so.

7
00:01:40.150 –> 00:01:47.060
Anand Akela: Welcome, everyone. My name is Anand Akela, and I’m the Chief Marketing Officer at Akelview Technologies.

8
00:01:48.130 –> 00:01:53.079
Anand Akela: Today’s topic is, cyber Resilience for Agentic AI.

9
00:01:53.230 –> 00:01:55.609
Anand Akela: Learnings from the Hugging Face attack.

10
00:01:55.760 –> 00:02:02.890
Anand Akela: To discuss this today, I’m joined by Suril Desai, our VP of Detection Engineering at Akelvio.

11
00:02:03.280 –> 00:02:08.740
Anand Akela: Over the years, Surilil has led engineering for industry-leading cybersecurity solutions.

12
00:02:08.919 –> 00:02:13.379
Anand Akela: He’s a cybersecurity expert and holds multiple patents. Welcome, Suril.

13
00:02:16.310 –> 00:02:17.980
Suril Desai: Thanks to… Yeah.

14
00:02:18.220 –> 00:02:25.679
Suril Desai: So, happy to meet with you and talk about this topic, which is a topic of great relevance in today’s

15
00:02:25.680 –> 00:02:39.700
Suril Desai: threat landscape. So what we’ll do is we’ll… the agenda for today’s session is going to be about analyzing the actual Hugging Face security incident, talk about both aspects, what occurred at OpenAI, and then what occurred at Hugging Face.

16
00:02:39.850 –> 00:02:55.460
Suril Desai: And then we’ll talk about, at a more broader conceptual level, about the cyber risks of Agentic AI. So what does this adoption of agents mean from a cyber risk perspective, and what should defenders be aware of?

17
00:02:55.920 –> 00:03:01.070
Suril Desai: Then we’ll switch to the defender’s perspective and look at the implications on cyber defense.

18
00:03:01.880 –> 00:03:12.030
Suril Desai: Then we’ll talk about a defensive strategy to be able to get your security controls and pick the right controls to be able to combat this type of a threat.

19
00:03:12.640 –> 00:03:29.639
Suril Desai: Once the controls are deployed, we’ll look at how can defensive teams validate the security posture, so what are the techniques that can be used to make sure that these controls are actually effective, and that they will work when this eventual exploit occurs.

20
00:03:29.880 –> 00:03:46.380
Suril Desai: And then we’ll talk about the implications on security operations. So, for example, how should the SOC change as far as defending against an Agentic exploit is concerned? So that’s basically the idea, so it’s a broad set of topics that we will discuss today.

21
00:03:46.380 –> 00:04:00.570
Anand Akela: So really, before you go to, kind of get started, I just wanted to highlight for everyone, all the participants, that we’ll use the Q&A function at the bottom of the Zoom webinar window that you could use for asking your questions.

22
00:04:00.570 –> 00:04:11.370
Anand Akela: Feel free to ask the questions as you get them, you know, as Roly is talking about, but we’ll take them during the Q&A session at the end of the presentation and a short demo.

23
00:04:11.370 –> 00:04:12.770
Anand Akela: So, over to you, Suril.

24
00:04:13.640 –> 00:04:22.710
Suril Desai: Okay, great. Thanks, Anand. So, we’ll talk about the overall analysis of, you know, what occurred at Hugging Face and the OpenAI security incident.

25
00:04:22.830 –> 00:04:26.720
Suril Desai: So, as we know, ultimately, the… at a snapshot view.

26
00:04:26.890 –> 00:04:35.010
Suril Desai: There was… this is basically one of the first reported fully autonomous exploits, so it’s an example of

27
00:04:35.220 –> 00:04:50.419
Suril Desai: agents that, were misaligned and then performed damage against Hugging phase, and there’s really no human attacker in the loop, okay? So basically, there was no, adversary involved.

28
00:04:50.510 –> 00:05:07.779
Suril Desai: and no threat actor. Ultimately, it’s a set of agents, and OpenAI was running a set of agents, some of them were released LLM models, some of them were unreleased versions. And the whole objective of those LLM models was to be able to

29
00:05:08.000 –> 00:05:16.689
Suril Desai: Verify the ability of these models to solve complex cyber challenges, such as the exploit Gym Cyber Benchmark.

30
00:05:16.690 –> 00:05:29.650
Suril Desai: Which is a way for mod… to verify the ability of models to be able to solve cybersecurity problems. And so that was the objective that was given to these agents and the corresponding LLM models.

31
00:05:29.930 –> 00:05:42.449
Suril Desai: And in this process, through a set of activities called as misalignment, these agents landed up doing malicious activity, so they broke out of the OpenAI environment.

32
00:05:42.480 –> 00:05:52.159
Suril Desai: Found a node which had internet access, egress point, and then used that node from… with internet access to be able to go and

33
00:05:52.260 –> 00:06:01.550
Suril Desai: find an entity that had the Exploit Gym benchmark available, which happened to be Hugging Face, and then went to Hugging Face and actually

34
00:06:01.920 –> 00:06:12.029
Suril Desai: compromised Hugging Faces infrastructure, and then got access to the Exploit Gym benchmark. So that was basically the analysis of what occurred at an overall view.

35
00:06:12.260 –> 00:06:29.129
Suril Desai: What I’ll be talking about today is… there’s been a lot of research around what really occurred, so what I’ll do today is, more than trying to repeat what has been discussed heavily, I’ll try to give some derived insights into what does this mean from a

36
00:06:29.130 –> 00:06:34.530
Suril Desai: Defender point of view, and talk about the attacker From the insights perspective.

37
00:06:35.620 –> 00:06:39.270
Suril Desai: So, the first point is about an example of

38
00:06:39.370 –> 00:06:44.569
Suril Desai: This incident is effectively an example of what is called as Agentic misalignment.

39
00:06:45.020 –> 00:06:49.240
Suril Desai: So, misalignment is effectively a case where the agent

40
00:06:49.290 –> 00:07:00.229
Suril Desai: performs actions that are beyond the intended goals. So, typically, agents and the corresponding LLM models are trained to achieve a set of objectives.

41
00:07:00.230 –> 00:07:16.399
Suril Desai: And they have built-in guardrails, model-specific guardrails, that are provided by the Frontier Lab providers that establish policies and bounds around agent behavior. So, example of these guardrails would be that the agent or the LLM should not

42
00:07:16.400 –> 00:07:31.530
Suril Desai: go and try to do cybersecurity attacks, or it should not try to do, you know, terrorism activity, or it should not find, you know, bioweapons. These are the type of things that, if somebody attempts that type of a prompt.

43
00:07:31.610 –> 00:07:43.020
Suril Desai: to the LLM, then the LLM is supposed to refuse that type of a request and deny it. That type of refusal is enforced through the model-specific guardrails.

44
00:07:43.100 –> 00:07:55.390
Suril Desai: However, as we saw in this particular case, there are several cases, for example, in the OpenAI incident, these models were run with… they were running an eval version of the models.

45
00:07:55.390 –> 00:08:12.549
Suril Desai: And the whole idea was to run them without the model-specific cart rails, because the objective was to be able to verify the ability of the LLM to solve these type of cybersecurity problems. So fundamentally, the models that were running were actually not having the cartrails built in.

46
00:08:12.560 –> 00:08:19.470
Suril Desai: We also know that there is a whole category of open weights models that are also now available.

47
00:08:19.680 –> 00:08:27.459
Suril Desai: Those models, by definition, don’t have any model-specific cartrils. And so, fundamentally, from a defender’s point of view.

48
00:08:27.590 –> 00:08:44.059
Suril Desai: This type of activity can now occur, and misalignment is… effectively occurs when these LLM models and corresponding agents try to do the right thing in their mind, but eventually it’s creating harm for the organization.

49
00:08:46.470 –> 00:08:51.909
Suril Desai: So the other aspect is what we call as long horizon problem solving and persistence.

50
00:08:51.960 –> 00:09:00.599
Suril Desai: So, if you look at the evolution of LLM models over time, so for example, in 2022, when ChatGPT came out as an initial version.

51
00:09:00.620 –> 00:09:08.819
Suril Desai: Many of the initial versions of the LLM models were trained for what is called a short horizon tasks. So the user provides a prompt.

52
00:09:08.820 –> 00:09:21.579
Suril Desai: And the LLM model provides a response. And the whole interactive experience was to be able to provide a set of questions and get back an update. And that’s what the models training was optimized for.

53
00:09:22.180 –> 00:09:26.680
Suril Desai: In the new world, for example, in the last year or so.

54
00:09:26.730 –> 00:09:43.289
Suril Desai: there has been an advance of what is called as Agentic workflows. So, Agentic workflows are designed for long horizon activity, so things that occur over hours, sometimes over days, sometimes over weeks, without a human intervention in the loop.

55
00:09:43.620 –> 00:09:54.010
Suril Desai: And the whole reason for that is it has said there are several automation benefits. So, for example, if you take the case of any given organization, if somebody wants to

56
00:09:54.010 –> 00:10:04.089
Suril Desai: perform a backup of a production database data. Then that type of activity can be time-consuming, and it can involve analysis of large amounts of data.

57
00:10:04.210 –> 00:10:23.719
Suril Desai: And that requires a long time horizon, typically, so the new versions of these models are all being tuned for problem solving over long durations of time. So they’re specifically trained for that purpose, and while that has many benefits from an automation point of view.

58
00:10:23.760 –> 00:10:43.389
Suril Desai: It also creates a set of cyber risks, because these long horizon problem solving inherently requires model persistence. So the model is trained to be able to never give up. So they need to make sure that in order to, once given a task or an objective.

59
00:10:43.390 –> 00:10:48.290
Suril Desai: They will do everything within their power to be able to find a way to achieve that object.

60
00:10:48.290 –> 00:10:58.770
Suril Desai: Even if it means taking multiple steps, performing retries, changing their paths, all that is okay, because that’s what the model is trained to do.

61
00:10:58.930 –> 00:11:04.650
Suril Desai: And from a cyber perspective, when this model is misaligned.

62
00:11:04.720 –> 00:11:19.229
Suril Desai: This type of behavior can create a huge problem, because these models are effectively trained to be able to go and achieve their objective, which means when they’re misaligned, they can actually try very hard and find a pathway to get to their mission.

63
00:11:19.300 –> 00:11:31.710
Suril Desai: In example of the OpenAI exploit, the models were running in a part of the environment which did not have internet access, so it was not like they were just immediately given internet access.

64
00:11:31.710 –> 00:11:52.339
Suril Desai: But the long-horizon problem-solving characteristics enable the models to find a way by going after the artifactory repository, finding a particular type of an exploit, and then eventually getting to a node which had egress to the internet, and then getting to Hugging phase. So this type of activity and characteristics that are being exhibited

65
00:11:52.340 –> 00:11:55.500
Suril Desai: Have many different ramifications from a defender’s point of view.

66
00:12:01.830 –> 00:12:02.670
Suril Desai: Pardon?

67
00:12:23.430 –> 00:12:26.030
Anand Akela: Why don’t we go ahead and,

68
00:12:26.420 –> 00:12:41.899
Suril Desai: I think in the interest of time. So we’ll talk about some other aspects of the LLM behavior. So one other difference between traditional early generation of LLM models and agents and current generation is that

69
00:12:41.990 –> 00:12:56.400
Suril Desai: tradition… the new generation of agents and LLM models are having a team of agents, okay? So they’re not a single agent anymore. And these… the inherent nature of these tasks are to make it

70
00:12:56.400 –> 00:13:09.830
Suril Desai: partitioned across a team. And so the team of agents can break down an overall problem, and then decompose it into sub-problems, and then divide it across the team to be able to eventually achieve the objective.

71
00:13:10.170 –> 00:13:14.979
Suril Desai: And the team of agents are also, because they’re designed to operate as a team.

72
00:13:14.980 –> 00:13:33.600
Suril Desai: There’s also the ability of these team of agents to communicate with each other, to have communication pathways and share data and state across the members of the team. So an example of a team of agents would be a case where, let’s say, if you take the database backup again example.

73
00:13:33.600 –> 00:13:43.050
Suril Desai: There’s a master agent whose job is to orchestrate the backup of the database. There’s a second agent whose job is to actually go and read the production data.

74
00:13:43.050 –> 00:13:55.759
Suril Desai: There is a third agent that’s… whose job is to analyze the data and figure out whether it is worthy of being backed up or not. And there could be a fourth agent whose job is to deal with the persistence of the

75
00:13:55.760 –> 00:14:13.519
Suril Desai: backed up data into a new store. So fundamentally, most of these agentic workflows are broken down into subtasks, and the subtasks are orchestrated by a team of agents. Each agent itself could have a sub-agent within it, and these sub-agents and agents can communicate with each other through

76
00:14:13.520 –> 00:14:16.180
Suril Desai: shared communication pathways.

77
00:14:16.340 –> 00:14:27.430
Suril Desai: Now, on the right-hand side, you see an example of OpenAI did a talk at Black Hat, where in the Hugging Face incident, there was basically a team of agents that was involved.

78
00:14:27.570 –> 00:14:33.360
Suril Desai: And these team of agents were using a shared message board for communicating with each other.

79
00:14:33.700 –> 00:14:41.340
Suril Desai: And so, OpenAI gave, on the right and the bottom, if you see, they talk about the agent uploading a note.

80
00:14:41.470 –> 00:14:58.199
Suril Desai: to be able to share the information with other agents. And so, this type of shared communication pathways brings many different implications, because now the agents can self-orchate itself. So it is now a swarm of agents, which is a self-organizing swarm.

81
00:14:58.200 –> 00:15:02.229
Suril Desai: Keep in mind, there’s no human in the loop at all, so there was absolutely no person involved.

82
00:15:02.230 –> 00:15:15.000
Suril Desai: These are self-organizing themselves, they decide to use a shared communication, they’re uploading notes, they’re storing their interim statuses, and they’re exchanging communication between themselves to be able to achieve their objective.

83
00:15:15.400 –> 00:15:27.700
Suril Desai: So that clearly is a different evolution. As OpenAI calls it, it’s Cambrian explosion. This basically explodes the number of communication pathways by orders of magnitude.

84
00:15:29.560 –> 00:15:32.939
Suril Desai: One other dimension is what is called as reward hacking.

85
00:15:32.950 –> 00:15:45.369
Suril Desai: Okay, so ultimately, as you know, LLMs and the underneath technology is based on neural networks, and neural networks have a set of built-in weights, and the whole objective of the training

86
00:15:45.370 –> 00:15:53.179
Suril Desai: phase of these neural networks and corresponding LLMs is to be able to optimize for achieving a certain objective function.

87
00:15:53.310 –> 00:16:01.849
Suril Desai: So in that process, the models are inherently trained to optimize and achieve a certain reward function.

88
00:16:01.990 –> 00:16:17.390
Suril Desai: And the reward function can be specified as part of the model training process. In this case, in the OpenAI Hugging Face incident case, the reward function that was set was to find a solution for the exploit Gym Cyber benchmark.

89
00:16:17.550 –> 00:16:27.799
Suril Desai: And once these models have that type of inherent characteristics, they are trained to be able to optimize to achieve that type of a reward.

90
00:16:28.010 –> 00:16:40.770
Suril Desai: And when they are misaligned, or when the attacker controls the agent, then it starts exhibiting what is called as reward hacking characteristics, which means they will keep hacking.

91
00:16:40.770 –> 00:16:52.069
Suril Desai: Till they achieve the actual reward that they’re trying to seek, right? And this… this can create a set of many different dimensions to it. So on the right, you can see

92
00:16:52.070 –> 00:17:06.470
Suril Desai: analysis by the… in the OpenAI talk, where it talks about the agent fundamentally looking for internet access, not finding it, and says, it strongly suggests no exploitation possible. We are stuck.

93
00:17:06.470 –> 00:17:24.050
Suril Desai: Okay? And then it gives its own way out as well. So it says, perhaps the answer is online, okay? And so, effectively, these are… this is what’s agent’s internal thinking and decisioning loop that it’s going through as part of the reward hacking characteristics.

94
00:17:24.180 –> 00:17:38.539
Suril Desai: And the agent then continues to find new exploits, which is generating dynamically, for example, SSRF in this case, and it uses those generated exploits to be able to get to the objective that it is trying to seek for.

95
00:17:39.480 –> 00:17:44.689
Suril Desai: So this gives you a quick overview of what occurred as part of this type of an exploit.

96
00:17:45.380 –> 00:17:51.469
Suril Desai: Now let’s look at, you know, pop back the stack a little bit and analyze this at an overall level.

97
00:17:51.620 –> 00:17:59.130
Suril Desai: So let us see what are the implications of these type of agentic threats from an attacker and then corresponding to the defender’s point of view.

98
00:17:59.720 –> 00:18:03.299
Suril Desai: So, we all know this popular tool called Bloodhound.

99
00:18:03.430 –> 00:18:15.719
Suril Desai: And Burdound is basically a tool that can show what is called as attack pathways in Active Directory. So it finds a set of pathways to get from a source to a destination.

100
00:18:15.720 –> 00:18:25.459
Suril Desai: And so the whole idea is to be able to help the defender in this case, and sometimes the attacker as well, say that from original machine, how can I get to a domain admin?

101
00:18:25.980 –> 00:18:30.549
Suril Desai: Now, if you run a tool like Bloodhound in a production Active Directory domain.

102
00:18:30.900 –> 00:18:44.219
Suril Desai: One can find sometimes thousands, and sometimes more than that, number of attack pathways, because there are many different pathways that exist by virtue of connected entities and machines in the environment.

103
00:18:44.430 –> 00:18:48.469
Suril Desai: And so, if an attacker had to use a tool like Bloodhound.

104
00:18:48.580 –> 00:18:55.639
Suril Desai: Then the attacker has inherent human limitations, and they can only process a few pathways at a given time.

105
00:18:55.790 –> 00:18:59.599
Suril Desai: So typically, the human threat actor is going to look at

106
00:18:59.700 –> 00:19:12.009
Suril Desai: for example, a shortest path from the source to the destination. So they’re going to say, what can I… what pathway gives me the least number of steps to get to domain admin? And they’re going to prefer that pathway.

107
00:19:12.090 –> 00:19:20.260
Suril Desai: And as defenders, we can anticipate that a human attacker is likely to go after the shortest path and set our strategy accordingly.

108
00:19:20.430 –> 00:19:28.800
Suril Desai: But the Agentic attacker does not have those type of limitations. The Agentic attacker has a team of agents at its disposal.

109
00:19:28.930 –> 00:19:42.339
Suril Desai: And if there are a thousand pathways in the environment, they can have 100 agents working on those, and they can partition the problem among the 100 agents. So Agent 1 is processing pathways 1 to 10,

110
00:19:42.340 –> 00:19:51.300
Suril Desai: Agent 2 is processing pathways 11 to 20, and all these agents are working in parallel. So now, from a defender’s perspective.

111
00:19:51.310 –> 00:19:56.480
Suril Desai: One can no longer assume that one needs to only defend the shortest path.

112
00:19:56.790 –> 00:20:13.040
Suril Desai: One now needs to defend all possible pathways, because any of those pathways could be the ones that the agent might actually go and go after. And so that significantly shifts the defender’s perspective and the implications from a cybersecurity point of view.

113
00:20:15.010 –> 00:20:28.540
Suril Desai: So now that we’ve looked at, you know, the threat landscape from an attacker’s perspective, let’s switch to the defender’s view and see what can we do as defenders to be able to defend against this type of evolving threat.

114
00:20:28.630 –> 00:20:40.289
Suril Desai: And as, you know, there are many different dimensions to it. There is prevention, detection, security operations, and we’ll talk about many of this in today’s session, at least at an overall view.

115
00:20:40.890 –> 00:20:42.410
Suril Desai: So, we’ll start with

116
00:20:42.410 –> 00:21:05.669
Suril Desai: an approach, which is a well-proven approach in cybersecurity called Defense In Depth. And basically, this is based on first principles, and, you know, OpenAI did an excellent detailed technical report after the Hugging Face incident. That report is available on the public domain. You know, many of you might have read it. If you haven’t had a chance, it’s good reading, so…

117
00:21:05.670 –> 00:21:07.690
Suril Desai: You know, worth your time.

118
00:21:07.710 –> 00:21:15.049
Suril Desai: What I have done is… and extracted a single sentence, which I think is the crux of their report.

119
00:21:15.110 –> 00:21:27.730
Suril Desai: And it talks about a very fundamental point, saying the security controls must be robust and independent of one another across threat prevention, detection, and mitigation.

120
00:21:27.910 –> 00:21:34.480
Suril Desai: So that’s basically the idea, that there is no one silver bullet in cybersecurity that can solve all problems, as we know.

121
00:21:34.690 –> 00:21:45.149
Suril Desai: And it’s also important to pick the controls carefully and strategically, because some of these controls can have overlapping characteristics, and

122
00:21:45.150 –> 00:21:47.639
Suril Desai: You know, might have similar gaps.

123
00:21:47.640 –> 00:22:12.150
Suril Desai: So if they’re all having a similar gap, then the agent can go through the gap that exists across these controls. So it’s very important to pick the layers carefully, so that we remove the gaps across the layers, and that way it becomes hard for the attacker to get through unnoticed, and one of these layers will at least pick up. And so that includes a combination of preventive controls.

124
00:22:12.260 –> 00:22:17.079
Suril Desai: and detective conducts. And let’s look into each of this in a little more detail now.

125
00:22:18.350 –> 00:22:19.839
Suril Desai: So, the…

126
00:22:19.840 –> 00:22:44.380
Suril Desai: from an overall organization of a defensive matrix perspective, MITRE has done this excellent work called Atlas Framework. So, MITRE ATLAS is basically… MITRE has always had the attack matrix that categorizes threats, but there is basically the Atlas Framework, which is AI threat landscape for artificial Intelligence Systems.

127
00:22:44.480 –> 00:22:58.099
Suril Desai: It’s an overall taxonomy for analyzing Agentic and AI-orchestrated attack TTPs, and classifying them into the set of different combinations that occur in the… across the universe of exploits.

128
00:22:58.100 –> 00:23:10.169
Suril Desai: So, the defender can use this as a basis for organizing their preventive as well as detective controls, because it gives a standardized taxonomy and a well-defined reference point, so something to consider.

129
00:23:10.820 –> 00:23:23.599
Suril Desai: Now, let’s look at, you know, what can we do from a preventive as well as detective controls point of view. So, for prevention, clearly, you know, deploying… applying all the patches.

130
00:23:23.600 –> 00:23:29.670
Suril Desai: And reducing the exploitable attack surface is important, and so wherever one can patch

131
00:23:29.670 –> 00:23:48.590
Suril Desai: One should patch, and that is a given. And the… with AI-based tools, defenders have the ability to use AI tools on the defender side to find vulnerabilities ahead of the attacker and apply the patches. So that’s… that is an operating principle that should always be applied.

132
00:23:48.840 –> 00:24:07.419
Suril Desai: Once that’s done, then the next step is about detective controls. Because ultimately, there are many things that one cannot completely patch, there are also things that occur, for example, zero days can be used by the exploit, and those zero days may not have an available patch associated with it.

133
00:24:07.420 –> 00:24:22.600
Suril Desai: So, fundamentally, there is an aperture that is an available, exploitable attack surface that cannot be solved only by preventive controls, so one needs to apply layered defenses with detective controls for dealing with that.

134
00:24:22.670 –> 00:24:25.500
Suril Desai: And for detective controls.

135
00:24:25.680 –> 00:24:33.089
Suril Desai: Finding the signal among the events is very challenging. So if you look at the Hugging Face attack.

136
00:24:33.430 –> 00:24:48.739
Suril Desai: OpenAI did their research, but Aginkface did their own independent research, and they published an exhaustive report. And so, in their report, what they did is, what were the type of evidence that they were seeing from their point of view?

137
00:24:48.760 –> 00:24:55.390
Suril Desai: And so it is not the case that Hugging Face did not see any activity among this type of an Agentic attack.

138
00:24:55.620 –> 00:25:05.920
Suril Desai: The attack involved reconnaissance for about 48 hours, and it took more than 48 hours before the Hugging Face team was able to say that this is malicious.

139
00:25:06.040 –> 00:25:21.819
Suril Desai: So within the 48 hours, they didn’t see a bunch of events, but the problem that they had was that there were too many events. So it was not like there were no events, the problem was the reverse, that there were too many. And finding the signal from the noise.

140
00:25:21.880 –> 00:25:31.209
Suril Desai: proved to be the difficult problem. And they had about 17,000 events that were reported by traditional security controls.

141
00:25:31.210 –> 00:25:48.840
Suril Desai: And the issue that they had was that it was non-confirmatory. There were low confidence alerts. As a result, they were unable to know that this is actually indicative of malicious activity. So the successful attack path was hidden among the noise of the thousands of the failed ones.

142
00:25:49.320 –> 00:25:51.800
Suril Desai: So, given that type of context.

143
00:25:52.370 –> 00:25:55.210
Suril Desai: A good strategy from a defender’s point of view.

144
00:25:55.340 –> 00:26:05.040
Suril Desai: is to set a trap as a layered defense strategy for an Agentic threat. So the whole idea with traps, which are a form of cyber deception.

145
00:26:05.240 –> 00:26:16.839
Suril Desai: A new version of honeypots or honey tokens are basically giving opportunities to an agent to go after entities that do not typically exist in the environment.

146
00:26:16.920 –> 00:26:33.539
Suril Desai: And those could represent, like, a decoy in the network, or an identity store, honey token. And if the agent goes after any of them, the defender gets a high-confidence alert, which enables the defender to know that there is malicious activity going on.

147
00:26:33.540 –> 00:26:41.299
Suril Desai: without waiting for the triaging that is occurring with the… with the low confidence alerts. So that’s basically the idea.

148
00:26:41.480 –> 00:26:52.959
Suril Desai: The deception field is not new, it’s been there in cyber for a while, and that itself has to evolve as the threat landscape changes from an Agentic threat perspective.

149
00:26:53.280 –> 00:27:09.360
Suril Desai: So there’s been a lot of good research around this space, around what does the deception characteristics require to do for an Agentic threat. So here is a research paper called Rogue, Honey, and Traps, published by Ben-Gurion University in Israel.

150
00:27:09.360 –> 00:27:17.439
Suril Desai: which actually specifically analyzes the type of deceptions that make sense for an Agentic LLM-based

151
00:27:17.440 –> 00:27:31.650
Suril Desai: attack, like the case of the Hugging Face exploit. It talks about certain characteristics that are inherently needed in a deception-based control to be able to effectively detect as well as slow down the Agentic attack.

152
00:27:33.940 –> 00:27:51.250
Suril Desai: So, several industry agencies, such as SANS and the Cloud Security Alliance, after the Hugging Face attack, have published their CISO’s advisory, and one of the things they speak about is the recommendation to deploy deception technology liberally.

153
00:27:51.370 –> 00:28:08.590
Suril Desai: And the interesting part about that is the reason for their analysis. So they speak about the fact that the reconnaissance showed up as a low-confidence probe, which is what we were talking about. And then they say that because you can set these traps that provide the fidelity.

154
00:28:08.610 –> 00:28:17.090
Suril Desai: One can get the telemetry that enables immediate action to be able to early detect and then slow down the Agentic attack.

155
00:28:18.700 –> 00:28:24.279
Suril Desai: So now let’s look at the role of deception from a MITRE attack framework point of view.

156
00:28:24.570 –> 00:28:32.080
Suril Desai: So, as you know, that MITRE basically has analyzed the set of attacks into a set of tactics and techniques.

157
00:28:32.480 –> 00:28:38.510
Suril Desai: Some of these tactics are associated with activity that occurs earlier in the exploit lifecycle.

158
00:28:38.880 –> 00:28:49.759
Suril Desai: For example, reconnaissance, credential access, lateral movement. These are the tactics that occur prior to later stage tactics, like

159
00:28:49.760 –> 00:29:09.119
Suril Desai: impact or exfiltration, which occurs at a later stage of the kill chain. And so, as a defender, it’s very important to be able to anchor the strategy around the early-stage tactics, so that when the Agentic attacker starts the reconnaissance, now, for example, in the 48-hour window that went

160
00:29:09.220 –> 00:29:19.240
Suril Desai: uncaptured very early within the 48-hour window, let’s say within the first few minutes, or ideally within even the first few seconds.

161
00:29:19.240 –> 00:29:29.479
Suril Desai: The defender should be able to detect that there is malicious activity, and then also impact it by slowing it down and redirecting it, and that is basically the…

162
00:29:29.480 –> 00:29:43.859
Suril Desai: the basis for the thesis, and that thesis has to be organized around the early-stage tactics from a MITRE point of view. So that’s the role of deception strategy for organizing a defense against an Agentic attack.

163
00:29:45.300 –> 00:30:02.019
Suril Desai: Now, let’s look at a few types of deception. So, there are various types of deception that would be applicable and would make sense for an exploit of this nature. So, ultimately, an misaligned agent or an attacker-controlled agent is going to go after an asset of value for it.

164
00:30:02.150 –> 00:30:14.060
Suril Desai: And so the assets of value could be an Active Directory domain, it could be an important database server, or it could be even AI infrastructure itself, like a MCP server.

165
00:30:14.340 –> 00:30:18.939
Suril Desai: So, we know as defenders that these are the assets that we are trying to protect.

166
00:30:19.040 –> 00:30:37.509
Suril Desai: So for those, a defender has a first mover advantage. So, we can set specific traps in the form of decoys and honey tokens, organized based on those assets of value, and then place them in the environment. Any activity against them will immediately surface evidence of malicious activity.

167
00:30:39.390 –> 00:30:54.109
Suril Desai: So here is the concept of what we call as a deception guardrail for Agentic AI. So if you look at an analysis of an agent, so there’s an agent running on an endpoint, it has its client-side environment, which is a configuration and skills repository.

168
00:30:54.270 –> 00:31:12.629
Suril Desai: it’s talking to the enterprise infrastructure using, you know, standardized protocols like model context protocol, MCP, and it can also talk to RAG pipelines. And within the MCP, there would be a set of tools, and those tools would be talking to back-end systems for the agent to achieve its objective.

169
00:31:12.690 –> 00:31:30.429
Suril Desai: So that is the Agentic workflow and the pipeline as it is deployed and as it exists. So what the defender can do for organizing the traps is to place the traps around interesting pathways that the agent is likely to pursue when it is misaligned or when it is controlled by an attacker.

170
00:31:30.670 –> 00:31:45.139
Suril Desai: Those pathways can be placed in an identity store, or as a… in a database server, and the whole idea is that as… if the agent does anything malicious, tries to talk to any of these tabs, the defender will get to know.

171
00:31:47.020 –> 00:31:56.980
Suril Desai: So, we’ll take an example of how this might occur. So, one of the things that an agent has is that the agent is trained based on internet data.

172
00:31:57.060 –> 00:32:12.880
Suril Desai: But the thing that the agent does not have is that the agent does not know your organization’s environment. So it has to do an initial form of reconnaissance, because the agent does not know where all the assets in a given organization are.

173
00:32:12.880 –> 00:32:20.110
Suril Desai: That is not available in the public domain, and as a result, is not available in the training data for the agent. So the agent, when it is

174
00:32:20.210 –> 00:32:30.160
Suril Desai: misaligned, or when it is controlled by an attacker, it has the step to perform called reconnaissance step, which occurred in the Hugging Face incident as well.

175
00:32:30.240 –> 00:32:44.249
Suril Desai: During the reconnaissance step, it is trying to perform a worldview of the operating environment under which it is executing, which is the enterprise environment. So it’s trying to get an understanding where are the assets, what do they represent.

176
00:32:44.440 –> 00:32:56.489
Suril Desai: what are the good targets to select? So, in that selection criteria, the defender can alter the agent’s worldview or its concept of ground truth.

177
00:32:56.700 –> 00:33:10.760
Suril Desai: By placing these traps within the environment, which the agent will ingest as part of the reconnaissance step, believe that these are actually the entities worthy of targeting, and then go after them.

178
00:33:10.760 –> 00:33:19.119
Suril Desai: So that’s basically the way that this is altering the agent’s mapping when it’s trying to form its situational awareness.

179
00:33:19.910 –> 00:33:27.459
Suril Desai: So I’ll show one example of a quick demo on how this thing can occur in a concrete rendition.

180
00:33:27.940 –> 00:33:36.380
Suril Desai: So, we… here is an enterprise environment where they’ve deployed agents, and those agents are talking to

181
00:33:36.750 –> 00:33:54.539
Suril Desai: MCP servers, and they’re achieving a bunch of productivity workflows. For example, they’re trying to go and achieve email backup or database backup. Those are the type of use cases for the agents that have been set up, and as part of that deployment.

182
00:33:54.600 –> 00:34:06.080
Suril Desai: We will now look at what the defender… what… what an attacker control agent does, and what can the defender do for being able to defend against that.

183
00:34:06.270 –> 00:34:10.900
Suril Desai: So here is a case where an attacker gets access to an agent.

184
00:34:11.170 –> 00:34:16.949
Suril Desai: In this case, the agent is installed on an endpoint. It happens to be a Claude

185
00:34:16.980 –> 00:34:29.879
Suril Desai: for example, desktop, and that cloud desktop, as you know, has a configuration profile. That configuration profile provides a list of MCP servers that are connected to

186
00:34:29.880 –> 00:34:44.409
Suril Desai: to the cloud desktop. So what an attacker can do is, when they get access to such an agent, or if the agent is misaligned, it’s going to do a reconnaissance to look at that configuration profile and find the set of connected MCP servers.

187
00:34:44.520 –> 00:35:03.920
Suril Desai: So, in this case, it’s looking and finding that there is a connected MCP server that represents a SQL server, and so now, the attacker uses this type of a MCP server to try to talk to it, to get access to the data that is backed by the server. So it establishes a session with the MCP server.

188
00:35:04.030 –> 00:35:07.040
Suril Desai: It looks at the set of tools exposed by the server.

189
00:35:07.440 –> 00:35:11.040
Suril Desai: Finds a set of tools, it finds the corresponding credentials.

190
00:35:11.210 –> 00:35:17.099
Suril Desai: Then it uses those credentials to talk to the backend database, and then it tries to exfiltrate the data.

191
00:35:17.390 –> 00:35:33.200
Suril Desai: Now, all of this is a decoy environment, and so, effectively, the agent is interacting with a trap, and any activity done against the trap can be shown to the defender, the defender will get to know that there is a MCP server interaction being done.

192
00:35:33.300 –> 00:35:42.899
Suril Desai: And the evidence of that can then be also mapped to MITRE Atlas. The corresponding alert telemetry of the MCP can also be surfaced to the defender.

193
00:35:43.060 –> 00:35:49.929
Suril Desai: So this gives you an example of how to operationalize such a security strategy from a practical point of view.

194
00:35:51.250 –> 00:36:10.580
Suril Desai: So now that we’ve looked at how we can deploy prevention and detective controls, let’s cover two couple of more aspects. One is, how can we validate as practitioners that these controls are working in practice? So there is the aspect of verifying these controls’ effectiveness, for which

195
00:36:10.590 –> 00:36:27.870
Suril Desai: A red teaming approach is a good idea to consider. So the… typically, many of the organizations now, you know, we recommend as practitioners that it’s a good idea to consider continuous red teaming, where you can actually run red team agents to go and validate the security posture and test

196
00:36:27.870 –> 00:36:37.869
Suril Desai: the controls and the effectiveness of those controls. So those red teaming agents go and find any residual exploitable pathways, and then try to compromise them.

197
00:36:37.870 –> 00:36:51.389
Suril Desai: And so that’s basically a good measure of being able to verify that your layered defenses are in place and you are prepared for when an export of that type might occur in a real-world environment.

198
00:36:53.170 –> 00:37:03.140
Suril Desai: Cover one other last topic. What does this mean for security operations, and how is that field going to change in an Agentic world?

199
00:37:03.840 –> 00:37:15.219
Suril Desai: So, the idea is, traditionally, as we know, as SOC teams have been organized around a largely a human-centric world. There’s, like, Level 1 SOC, Level 2, and Level 3.

200
00:37:15.250 –> 00:37:26.110
Suril Desai: And individual alerts get escalated into a… into an alert triaging pipeline. The SOC analysts analyze them, and then eventually control whether it’s malicious or not.

201
00:37:26.450 –> 00:37:30.430
Suril Desai: With the Agentic type of attacks that occur in this Hugging Face exploit.

202
00:37:30.590 –> 00:37:40.929
Suril Desai: SOC teams need to accelerate their investigation time windows significantly, because time and speed is of the essence, and also.

203
00:37:40.930 –> 00:37:57.870
Suril Desai: quality of telemetry is inherent to be able to achieve that. So the… so the concept is to be able to do what is called as auto-triaging of the alerts, so that now the human is in the loop, but the human is only doing the overall high-level objective or the mission.

204
00:37:57.890 –> 00:38:12.629
Suril Desai: But the Agentic SOC is actually doing the automation for various subtasks of being able to deduplicate, or correlate, or enrich the individual telemetry, so that one can get an analyzed understanding of what is really occurring.

205
00:38:12.710 –> 00:38:21.269
Suril Desai: So, for that type of activity, the triage needs to be automated, corresponding response actions need to be automated as well.

206
00:38:21.270 –> 00:38:32.919
Suril Desai: And so, in order to do that, one of the important parts is, if you look at the analysis done by Hugging Face, they already had an AI-assisted detection and response pipeline in place.

207
00:38:33.000 –> 00:38:52.529
Suril Desai: But it still took them more than 48 hours to be able to find this exploit. One of the primary reasons was the signal fidelity, right? And so, by providing high fidelity signal, one can be able to find such an exploit quickly, and be able to stop it. So that’s the quick context around accelerating security operations.

208
00:38:53.430 –> 00:39:09.599
Suril Desai: The one other aspect I’ll talk about is, what can the SOC do once you find such an exploit? So, let us say, for example, an Agentic exploit has been occurring, and it’s doing anything malicious. For example, one of the decoys picks up an alert, sends it into the security operations center.

209
00:39:09.600 –> 00:39:13.580
Suril Desai: Then the next step that the SOC does can also be

210
00:39:13.580 –> 00:39:18.189
Suril Desai: tailored for an Agentic threat. So there are two things that SOC teams can do.

211
00:39:18.190 –> 00:39:32.139
Suril Desai: One is what is called as look-back analysis, adversary traversal analysis. The second is look-forward analysis, which is attack pathway prediction analysis. So, adversary traversal is basically the ability to, given a given alert.

212
00:39:32.140 –> 00:39:43.810
Suril Desai: One can look back at all the chain of events that occurred in an Agentic threat, and try to analyze all the other nodes that could have been compromised by the agent as part of their exploit sequence.

213
00:39:43.810 –> 00:39:49.210
Suril Desai: That way, one gets a clear view into the other nodes that need cleanup and mitigation actions.

214
00:39:49.430 –> 00:40:05.059
Suril Desai: the attack pathways exploit is to say, I found the Agentic threat early, but maybe if it continued, where is it likely to go toward? So that type of predictive analytics is also a good idea to consider from a Agentic SecOps point of view.

215
00:40:05.060 –> 00:40:19.070
Suril Desai: And that can be all… all these actions are all anchored around the fidelity of the signal, and that signal is important to get right. Once that is right, then these downstream workflow actions can

216
00:40:20.660 –> 00:40:26.680
Suril Desai: So that’s a quick overview of our talk. Thank you for your time. Happy to take questions now.

217
00:40:31.440 –> 00:40:40.699
Anand Akela: Yeah, please, submit your questions using the Q&A button at the bottom of your screen.

218
00:40:41.010 –> 00:40:45.690
Anand Akela: Let’s see, we have a few questions here.

219
00:40:47.010 –> 00:40:49.410
Anand Akela: Okay, let me take the first question, Suril.

220
00:40:51.210 –> 00:41:02.810
Anand Akela: If the agent performed so much activity, how come it did not get noticed or detected? I think you had covered some, but why don’t you elaborate on that?

221
00:41:03.110 –> 00:41:12.920
Suril Desai: Right. So, fundamentally, in this case, basically, it did pick up a lot of events, so there are two parts to a detection signal. One is an event.

222
00:41:12.960 –> 00:41:26.510
Suril Desai: And the second is to know that it is malicious. So, if you look at Hugging Face, ultimately, it’s an exposed service where one can run… bring various LLMs and test them, and that’s sort of the inherent nature of the service they provide.

223
00:41:26.630 –> 00:41:41.839
Suril Desai: So, a lot of existing use results in these type of events getting surfaced on a daily basis. So, the Hugging Face security team is already seeing tons of regular events that are occurring as business as usual.

224
00:41:42.230 –> 00:41:49.989
Suril Desai: on a given day, the OpenAI agents decide to go and exploit the Hugging Face LLMs in a malicious manner.

225
00:41:50.070 –> 00:42:07.630
Suril Desai: But the type of events that will be surfaced are fairly consistent with normal usage. So, the alert volume is the problem, that there’s so much alert volume that finding which of this represents malicious and which is non-malicious takes time.

226
00:42:07.630 –> 00:42:19.799
Suril Desai: One has to sift through all this, process them, generate baselines, find deviations from them, then eventually figure out that this is really malicious. That is what took the 48 hours for Hugging Face.

227
00:42:21.790 –> 00:42:37.850
Anand Akela: Very nice. Again, please feel free to submit your questions, and, you know, like, most of the questions I’m getting now is that, will we be getting the presentation, recording? And the answer is yes, we will be sending

228
00:42:37.850 –> 00:42:45.840
Anand Akela: the recording of the webinar to everyone who registered and attended, so, we’ll do that. Mostly, it’ll go out,

229
00:42:46.080 –> 00:43:04.530
Anand Akela: later tonight or tomorrow, but you will definitely get that. Okay, so let’s… we have another couple of questions here. In this case, the agent’s guardrails have been deliberately disabled by OpenAI for eval… eval, purposes.

230
00:43:05.110 –> 00:43:10.570
Anand Akela: We run LLMs and agents with built-in guardrails. Is this sufficient?

231
00:43:11.290 –> 00:43:27.140
Suril Desai: Right. So the idea is that, you know, model-specific guardrails, so typically all Frontier labs do ship with built-in guardrails, and that is something that, you know, is certainly an absolute must-have and is a necessary item for AI safety and governance, so there is absolutely no doubt about that.

232
00:43:27.140 –> 00:43:37.939
Suril Desai: I think the challenge for us as defenders is that the world has become very dynamic and plural, and we need to grapple with the fact that that is the inerrant nature of the world. For example.

233
00:43:37.940 –> 00:43:48.430
Suril Desai: There are open weights models that are around which don’t have these guardrails, and the challenge is an attacker can get access to those open weights models.

234
00:43:48.430 –> 00:44:03.739
Suril Desai: And so they have the almost similar… they’re generally one version below the… one version behind the absolute state of heart, but they’re just one version behind. They’re not, like, multiple versions behind. So they have access to almost the same amount of capability on the Defender side.

235
00:44:03.740 –> 00:44:09.610
Suril Desai: the attacker has access, and there’s no guardrail at all. And so that becomes a problem which is requiring

236
00:44:09.610 –> 00:44:17.360
Suril Desai: A security control that is independent of the model cartil is inherently needed to be able to get a defense-in-depth approach.

237
00:44:18.860 –> 00:44:19.620
Anand Akela: Very good.

238
00:44:20.050 –> 00:44:24.370
Anand Akela: Again, we have some time. Please feel free to submit your questions.

239
00:44:24.780 –> 00:44:35.249
Anand Akela: The next question is, how does the team of agents impact the defensive posture and detection engineering?

240
00:44:35.560 –> 00:44:52.000
Suril Desai: Yes. So the team of agents is the good way to think of that is the bloodhound example that we were discussing, where effectively, if you look at a set of possible pathways that occurred in a given environment, let’s say in the case of bloodhound, there were the thousand pathways.

241
00:44:52.000 –> 00:45:01.560
Suril Desai: If there was a single agent, the single agent still has limited compute and a limited amount of resources, so it can explore a few pathways concurrently.

242
00:45:01.680 –> 00:45:19.770
Suril Desai: But if it is a team of agents, then they have distributed compute at its disposal, and they can partition the problem in a… to a thousand-way split, and then get many different sub-agents and the individual agents in the team to go and process those

243
00:45:19.820 –> 00:45:30.009
Suril Desai: pathways. Fundamentally, what it means is one needs to be able to anticipate that the parallel processing is going to go up by many orders of mandate.

244
00:45:32.030 –> 00:45:32.580
Anand Akela: Great.

245
00:45:33.500 –> 00:45:34.740
Anand Akela: Alright,

246
00:45:34.880 –> 00:45:42.269
Anand Akela: Okay, let me just take the question that came. What is the best use case scenario that you can give us

247
00:45:42.800 –> 00:45:47.779
Anand Akela: Quick glimpse over it to understand better this concept.

248
00:45:48.020 –> 00:45:54.510
Anand Akela: So what are the best use case scenarios that you can give us a quick glimpse over it to understand better?

249
00:45:54.990 –> 00:46:08.390
Suril Desai: Yeah, so maybe the… maybe the best way to think of this is this. So consider that, you know, you’re running a Agentic red team in your organization. So you can download an open-source red teaming agent, like a Pentagi, or, you know.

250
00:46:08.390 –> 00:46:19.369
Suril Desai: For example, Coachise A, which are open source redirect teaming agents that are used for performing controlled attacker activity as a simulation.

251
00:46:19.380 –> 00:46:28.599
Suril Desai: So let us say you download such an open-source red teaming agent, and you provide a prompt, and the prompt is, get access to a high-value asset in the organization.

252
00:46:28.980 –> 00:46:48.709
Suril Desai: now the agent starts going about its mission, and it goes after the kill chain, and it starts performing malicious activity, simulated malicious activity. That becomes a use case. Now, the test measurement criteria is that can your preventive controls stop that? Can you prevent it somehow?

253
00:46:48.710 –> 00:46:54.760
Suril Desai: Your detective controls, can they alert on it, and is alert high fidelity?

254
00:46:54.760 –> 00:47:04.380
Suril Desai: That’s the measurement criteria. Basically, would you be able to either prevent, or very early in this exploit, detect? And would you be sure about your findings?

255
00:47:06.410 –> 00:47:11.570
Anand Akela: Okay, again, we still have a few minutes, so please submit your questions.

256
00:47:11.770 –> 00:47:20.180
Anand Akela: Okay, here is another question. Can… Agents not detect

257
00:47:20.870 –> 00:47:26.379
Anand Akela: These deceptive artifacts and not, engage with them.

258
00:47:27.100 –> 00:47:43.760
Suril Desai: Yeah, that’s a very good question. So, you know, that is one of the topics that clearly one needs to be able to prepare for as a deception control. So, not all forms of deceptions are made… are equal, and so there are certain things that are required as best practices for deception design.

259
00:47:43.760 –> 00:47:52.039
Suril Desai: To be able to make sure that these are efficacious. So, if the deception is well designed, for example.

260
00:47:52.140 –> 00:48:00.459
Suril Desai: If it looks like one of the real assets, it has all the right characteristics, it is talking the right protocol, it is named in the correct way.

261
00:48:00.640 –> 00:48:18.520
Suril Desai: then it is almost very hard, even for the defender. The one who set up the deception itself cannot really know that this is a deception trap, because it all looks like what a real environment has. In that case, an agent will not be able to easily find it, because it looks totally consistent with the real.

262
00:48:18.680 –> 00:48:24.640
Suril Desai: And the other part is that, you know, agents who are optimized for just trying to do reward hacking.

263
00:48:24.880 –> 00:48:43.609
Suril Desai: they are going to go about their mission in… and because their goal is to get their mission statement. And so, along the way, as long as we have good design… well-designed deception, they will… they go after it, we raise an alert, we can then stop the agent before it goes and continues further reconnaissance.

264
00:48:45.370 –> 00:48:46.410
Anand Akela: Great.

265
00:48:46.890 –> 00:49:00.709
Anand Akela: Okay, the next question is, how do Agentic AI attacks, such as unauthorized sandbox escapes and lateral movement, fundamentally differ from the traditional human-led threat actor

266
00:49:01.020 –> 00:49:05.760
Anand Akela: ThreadCraft during the reconnaissance and privilege escalation phase.

267
00:49:06.060 –> 00:49:23.680
Suril Desai: Very good point. And so, if you look at the attack TTPs, so the actual TTPs are not really that different between an Agentic attack, which broke the, you know, sandbox and did a lateral movement, and a human threat actor. So the TTPs are relatively well understood. For example.

268
00:49:23.680 –> 00:49:33.880
Suril Desai: SMB-based propagation, or RDP-based propagation, or vulnerability exploits. These type of TTPs are fairly consistent, is what we have seen.

269
00:49:34.000 –> 00:49:52.599
Suril Desai: The difference is in a few things. It’s in speed, it’s in concurrency, it’s in dynamic decisioning. These are sort of the things that are different. So the machine speed, ability to do parallelly, ability to dynamically reason the sequence of activities is different between Agentic and human.

270
00:49:54.650 –> 00:50:00.020
Anand Akela: Very good. Let’s take the next question, and again, please feel free to submit questions.

271
00:50:01.560 –> 00:50:20.219
Anand Akela: Based on the defense in depth, Black had PowerPoint automate incident response, offensive agents act rapidly and scale out, defensive agents needed to scale DNR. Honey tokens deceptions can help.

272
00:50:20.470 –> 00:50:27.469
Anand Akela: Does this apply to ransomware attacks and deceptive traps within a deceptive environment?

273
00:50:28.630 –> 00:50:30.870
Suril Desai: Does this apply to ransomware attacks?

274
00:50:31.260 –> 00:50:35.890
Anand Akela: In deceptive traps within a deceptive environment.

275
00:50:36.030 –> 00:50:38.449
Anand Akela: Not sure I understand the question very well.

276
00:50:40.090 –> 00:50:46.059
Suril Desai: Applied ransomware attacks within the deceptive environment. So, so ransomware-based…

277
00:50:46.180 –> 00:50:56.090
Suril Desai: I’m not 100% sure I got the question, but maybe I’ll attempt. So ransomware itself is going to… there’s going to be a fusing of…

278
00:50:56.150 –> 00:51:12.170
Suril Desai: an Agentic attack and malware, ransomware, and APT type of attacks, where different steps will be codified using agents, so the next generation of ransomware, as it was, is likely to use agents to do its activity. And ultimately, the

279
00:51:12.170 –> 00:51:20.970
Suril Desai: Early signal and the ability to slow down the attacker is going to be useful for a ransomware type of exploit, Agent Management.

280
00:51:20.970 –> 00:51:30.690
Anand Akela: the person who asked the question kind of added a clarification. Basically, does the deceptive traps lure them to the deceptive environment?

281
00:51:31.080 –> 00:51:51.419
Suril Desai: Yes. So, okay, that… thanks, that clarifies. So, that requires certain characteristics, so the deceptive traps need to be designed in a way to make them lure towards a deceptive environment. So, for example, one of the things is the agents, or even a human threat actor, they look for certain things. So, for example.

282
00:51:51.420 –> 00:51:58.580
Suril Desai: Is there an older legacy version of a protocol? So, can you have a trap that advertises a SMBV1 protocol?

283
00:51:58.580 –> 00:52:04.840
Suril Desai: Now the agent believes that this was going to be vulnerable to Eternal Blue, which is a known vulnerability exploit.

284
00:52:04.840 –> 00:52:17.989
Suril Desai: So if you advertise the trap as a V1, it looks believable, but still looks more attractive than the real. Now the agent, when it’s doing its reasoning and path planning, it’s going to prefer the trap over the reel and go after it.

285
00:52:22.100 –> 00:52:33.299
Anand Akela: That’s all I had, for all the questions that we had. All right, that’s one more question come in.

286
00:52:33.420 –> 00:52:40.430
Anand Akela: With Frontier AI development raising serious questions about agent autonomy.

287
00:52:40.640 –> 00:52:57.609
Anand Akela: What framework of independent evaluation, human-in-the-loop authorization, and governance should organizations establish before granting AI agents broad access to internal tooling and production infrastructure?

288
00:52:57.970 –> 00:53:05.250
Suril Desai: Yeah, this is a… this is a serious matter that, you know, is something that we all are grappling with today.

289
00:53:05.250 –> 00:53:29.200
Suril Desai: And there are various standardization efforts underway by multiple agencies, you know, around AI safety and governance. So, for example, Anthropic, in their report on this weekend, referenced to METR as one of the governance frameworks, and they have recommended the use of that. Microsoft has given its own recommendations around various forms of independent

290
00:53:29.200 –> 00:53:39.510
Suril Desai: AI safety and governance. And so this space is rapidly evolving. The actual governance frameworks are still evolving, but there are a few of them. And so.

291
00:53:39.610 –> 00:53:52.770
Suril Desai: we, as an independent vendor, may not be able to comment on or define those, but I would recommend, as a practitioner, that those… the existing ones, like METR, should be considered and used in your environment.

292
00:53:54.810 –> 00:53:55.370
Anand Akela: Okay.

293
00:53:56.240 –> 00:54:07.539
Anand Akela: Another question, I think it goes back to the previous question. Is there any evidence that agents are learning to detect trap environments?

294
00:54:08.690 –> 00:54:24.020
Suril Desai: This topic is going to be something that will evolve over time as agents and the capabilities evolve. So there will always… there will always be a attempt on the agent’s side, but I think the idea is two parts. One is the agents are not…

295
00:54:24.020 –> 00:54:42.109
Suril Desai: The agents are… the reward hacking point is very important to keep in mind, that they are optimizing for the reward that is set out for it. And the reward is typically to achieve a certain mission, or an objective. And as long as we as defenders have first mover advantage, and we know the mission, where are the high-value assets, and we design the right strategy.

296
00:54:42.250 –> 00:54:44.269
Suril Desai: We should have the upper hand.

297
00:54:48.810 –> 00:55:02.049
Anand Akela: All right, let’s, there’s no other question at this time, Suril. If you have any parting thoughts, you could share, and that way we could also kind of wait for another minute to, see if they didn’t end that question.

298
00:55:03.960 –> 00:55:17.640
Suril Desai: No, I don’t have any other, this, you know, I just wanted to thank, everyone for the time, and happy to… if there are any other questions or any thoughts, it’s a broad topic, so feel free to correspond offline, and we can… we can take the discussion forward.

299
00:55:17.810 –> 00:55:35.199
Anand Akela: Yeah, and we’ll send the recording to all of you guys, and feel free to respond back and ask any other questions, and we’ll have more opportunity to do these kind of educational sessions in upcoming weeks and events.

300
00:55:35.590 –> 00:55:42.910
Anand Akela: Thank you, everyone. Okay, hang on one second, let’s see. Okay, I think this person thinking, so all right, perfect!

301
00:55:43.230 –> 00:55:45.129
Anand Akela: Have a great day, guys. Bye-bye.

302
00:55:45.130 –> 00:55:46.010
Suril Desai: Thank you.

Acalvio Technologies logo

Suril Desai

Suril is VP Engineering at Acalvio Technologies. Suril has led engineering for industry leading cybersecurity offerings. Suril has deep domain expertise in cybersecurity and holds multiple patents.
Acalvio, the Ultimate Preemptive Cybersecurity Solution.