Thinking like an attacker is no longer optional

Abhijith 'Abx' B R (Village Lead · Defcon), Keenan Skelly

DEF CON 33 · Day 1 · Main Stage

Overview

In an insightful panel discussion at DEF CON, a group of seasoned cybersecurity experts — Abhijith 'Abx' B R, Bryson Bort, Anant, and Lt. Col. Gordon Boom — delved into the critical importance of adopting an adversarial mindset. The talk, hosted by the Adversary Village, emphasized that in today's complex threat landscape, simply reacting to known vulnerabilities or adhering to compliance checklists is insufficient. Instead, organizations must proactively think like their attackers, understanding their motivations, methodologies, and the full spectrum of tactics they employ to achieve their objectives.

Watch on YouTube

Visual summary for Thinking like an attacker is no longer optional by Abhijith 'Abx' B R, Keenan Skelly
Visual summary for Thinking like an attacker is no longer optional by Abhijith 'Abx' B R, Keenan Skelly

Key moments

  1. 0:00 Introduction to adversarial mindset panel and speakers
  2. 3:19 Bryson on real-world threats and mission accomplishment
  3. 5:55 Anant on adversarial mindset: fixed target, any means
  4. 7:00 Fizzle highlights intent in adversarial vs. hacker mindset
  5. 8:00 World War II plane analogy for defense hardening

Thinking like an attacker is no longer optional

Speakers: Abhijith 'Abx' B R (Village Lead, Defcon); Bryson Bort (Founder, Scythe, ICS Village); Anant (Founder, Siphonoid Research); Lieutenant Colonel Gordon Boom (United States Air Force)

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=PZLmzbyYs2g

Overview

In an insightful panel discussion at DEF CON, a group of seasoned cybersecurity experts — Abhijith 'Abx' B R, Bryson Bort, Anant, and Lt. Col. Gordon Boom — delved into the critical importance of adopting an adversarial mindset. The talk, hosted by the Adversary Village, emphasized that in today's complex threat landscape, simply reacting to known vulnerabilities or adhering to compliance checklists is insufficient. Instead, organizations must proactively think like their attackers, understanding their motivations, methodologies, and the full spectrum of tactics they employ to achieve their objectives.

This panel brought together diverse perspectives from offensive security consultancy, cloud security, industrial control systems (ICS) defense, and military cyber operations. Their collective experience highlighted a stark reality: attackers consistently find ways into even well-defended organizations, often with surprising ease. The discussion aimed to demystify the adversarial approach, contrasting it with the traditional "hacker mindset" and offering actionable insights for defenders to fortify their security posture by anticipating and emulating real-world threats.

The central thesis of the talk is that effective defense necessitates a profound understanding of offensive operations. By internalizing the attacker's goal-oriented, resourceful, and often unconventional approach, defenders can move beyond static, checklist-driven security to build dynamic, resilient systems that genuinely protect critical assets. The panel argued that this shift in perspective is no longer a luxury but a fundamental requirement for navigating the ever-evolving cyber threat environment.

Background

▶ Watch: Introduction to adversarial mindset panel and speakers (0:00)

The cybersecurity community has historically grappled with defining and distinguishing between different facets of offensive security. The panel initiated its discussion by drawing a clear line between the hacker mindset and the adversarial mindset. Bryson Bort articulated that while the hacker mindset, prevalent in communities like DEF CON, often focuses on exploring system boundaries, escalating privileges, and demonstrating technical prowess (akin to "playing capture the flag"), the adversarial mindset is fundamentally different. It is driven by a singular mission: to achieve a specific objective by any means necessary, technical or otherwise. This goal-oriented approach prioritizes effectiveness over elegance, meaning "if it works, it matters," regardless of the sophistication involved. As Anant elaborated, a hacker might make a system "do what it's not intended to do," but an adversary has a "fixed target in mind" and will exploit any path—human, process, or technology—to reach it.

This distinction is crucial because traditional defensive strategies often fail to account for the adversary's broader scope. Lt. Col. Gordon Boom (Fizzle) added that intent is key: hackers reshape systems, while adversaries have a "specific goal and objective in mind" for personal or organizational gain. The panel used a compelling analogy from World War II, the "airplane bullet holes" story, to illustrate this point: planes that returned often had bullet holes in their wings, leading some to suggest reinforcing the wings. However, the critical insight was that planes not returning were likely hit in more vital areas. Similarly, defenders often focus on patching vulnerabilities where attacks are observed (wings), missing the critical, unobserved pathways that lead to total compromise (cockpit, engines).

The panel critically examined why organizations, despite investing heavily in security, remain vulnerable. A significant part of the problem lies in the disconnect between compliance and actual security. As Anant pointed out, "Offense is always technical in nature. Defense is always political in nature." Organizations often prioritize meeting minimum compliance benchmarks (e.g., 80% score) to manage budgets and vendor relationships, rather than striving for comprehensive protection. Bryson Bort emphasized that compliance is a "static checklist," which attackers already possess or can easily deduce. Attackers leverage open-source intelligence, like LinkedIn profiles and job descriptions, to map out an organization's defensive stack and personnel before even deploying a single tool, rendering static defenses largely ineffective. This creates an "infinite space" of attack vectors, where an attacker only needs one "chink in the armor" to succeed, while defenders are burdened with protecting everything.

Key Findings

▶ Watch: Bryson on real-world threats and mission accomplishment (3:19)

The panel's discussion yielded several critical findings regarding the nature of modern cyber threats and effective defense:

  1. Adversarial Mindset vs. Hacker Mindset: The core distinction is mission-driven intent. An adversary prioritizes achieving a specific objective using any available means (technical, social, physical), valuing effectiveness over complexity. A hacker, conversely, might focus on technical exploration or showing off. This implies that defensive strategies must consider the full spectrum of an attacker's resourcefulness.
  2. Ease of Compromise: Despite the perceived sophistication of modern attackers, panelists (Abhijith and Anant) revealed that a significant majority of compromises (e.g., 80-85% in Abhijith's experience) are achieved with basic techniques, often without resorting to advanced exploits. Simple vulnerabilities, misconfigurations (like a vulnerable server found via NMAP), or social engineering are frequently sufficient.
  3. The "Defense is Political" Reality: Anant highlighted that "Offense is always technical in nature. Defense is always political in nature." Budget constraints, vendor lock-in, and the pressure to meet minimum compliance standards often dictate defensive investments, leading to a focus on checkboxes rather than genuine, adaptive security. Bryson added that compliance is a "static checklist" that attackers can easily anticipate.
  4. Bryson's Attack Model (BAM): Bryson Bort proposed a three-phase model for understanding attacks:
  • Reconnaissance: Gathering intelligence on the target (e.g., "what house looks like the most fun to break into?").
  • Break-in/Initial Access: Gaining initial entry (e.g., "got shell," "picked the lock"). Crucially, this is not the mission objective.
  • Actions on Objective: The actual goal of the attack, performed after initial access. This is the critical phase where defenders have the most leverage.
  1. Defender's Advantage Post-Initial Access: Contrary to the common adage that "an attacker only needs to be right once and the defender needs to always be right," Bryson argued it's the opposite during the "Actions on Objective" phase. Once an attacker is inside the network, they are operating on the defender's systems, using the defender's protocols. Defenders control the "choke points" and have visibility into internal communications, offering a significant opportunity for detection and containment if they are "looking the right way."
  2. Broad Definition of Vulnerability: Fizzle and Bryson emphasized that "vulnerability" extends far beyond technical flaws. It encompasses any "daylight" or weakness—social, process, human, or technical—that an adversary can exploit to advance their mission. This requires defenders to think holistically about their attack surface.
  3. Teachability of Adversarial Thinking: While critical thinking might be difficult to teach directly, the panel agreed that individuals can be trained to be "absolutely useful" within the offensive space. This involves fostering a "why not" mindset, encouraging curiosity about what systems could do beyond their intended design, and understanding the adversarial process through playbooks and hands-on experience. The Conti leaks were cited as an example of how detailed playbooks enable even less skilled operators to be effective.

Technical Deep Dive

▶ Watch: Anant on adversarial mindset: fixed target, any means (5:55)

The panel discussion, while philosophical in parts, also touched upon several key technical concepts and tools crucial to understanding the adversarial mindset and implementing effective defenses.

At the heart of the offensive security discussion was adversary emulation. Bryson Bort, founder of Scythe, described his company's platform as an "adversary emulation platform," which he initially conceived as an alternative to Cobalt Strike. Cobalt Strike is a widely used commercial penetration testing tool that simulates advanced persistent threats (APTs) and is frequently adopted by both red teams and malicious actors. Scythe, in contrast, aims to provide a platform for "unlimited implants" and a more controlled, comprehensive emulation of adversary behavior, allowing organizations to test their defenses against realistic threats.

Bryson also introduced his Offensive Maturity Model, which underpins the adversarial mindset. This model posits that the effectiveness of an attack is paramount, not its complexity. He provocatively stated, "If you type a command on a CLI and it does something, congratulations. You're the PLA. If you type in a PowerShell command and it does something, you are a GRU unit. If you type in who am I, you are the Iranians." This highlights that even basic commands, when successfully executed to achieve an objective, constitute a legitimate and dangerous attack, regardless of the attacker's perceived skill level. This perspective challenges the common defensive focus on detecting only highly sophisticated, zero-day exploits, reminding us that MS08 (a reference to older, well-known vulnerabilities) can still be effective if unpatched.

A central technical framework discussed was Bryson's Attack Model (BAM), presented as an alternative to the often "abused" MITRE ATT&CK Framework and the Lockheed Martin Kill Chain. BAM simplifies the attack lifecycle into three distinct phases:

  1. Reconnaissance: This initial phase involves gathering intelligence on the target. This isn't just technical scanning; it includes open-source intelligence (OSINT) like exploiting LinkedIn to map organizational structures, relationships, and defensive tools through job descriptions. It also encompasses physical observation for close access opportunities.
  2. Break-in / Initial Access: This is the point where an attacker gains initial unauthorized access, often referred to as "getting shell." The panel stressed that this is merely crossing the threshold, "picking the lock," and not the ultimate objective. Bryson specifically mentioned that defenders are often "psychologically held up" on preventing this stage, driven by fear, but this focus misses the larger picture.
  3. Actions on Objective: This is the critical phase where the attacker performs the actual mission – interacting with the compromised system to achieve their goal. This could involve data exfiltration, privilege escalation, lateral movement, or disruption. Bryson argued that this is where defenders have a significant advantage because the attacker is now operating within the defender's environment, using their communication protocols and assets. This implies that robust internal monitoring and detection capabilities are crucial.

The panel also discussed practical tools and techniques. Anant shared anecdotes of compromises achieved with surprising ease, sometimes using just an NMAP scan to identify a vulnerable server, leading to domain admin control within minutes, even before a full Nessus scan could complete. This underscores the prevalence of basic, easily exploitable vulnerabilities. For those looking to start building offensive capabilities, Bryson recommended Atomic Red Team, a free and accessible tool for learning adversary emulation techniques and processes. He positioned it as an excellent starting point for purple teaming, enabling organizations to "type commands in a CLI" and understand adversary actions without needing a full-blown red team.

Finally, the discussion touched upon the nuanced difference between vulnerability research (e.g., finding bugs for bug bounties) and exploit development. Bryson highlighted that finding a bug is distinct from developing a "reliable exploit that will meet multiple conditions with a guaranteed level of success," which he classified as a "weapon." This distinction is vital for defenders to understand the capabilities and resources required for different types of attacks. The mention of the Conti leaks further illustrated this, as the leaked playbooks provided detailed, step-by-step instructions that enabled even less skilled operators to execute effective attacks.

Demo / Proof of Concept

▶ Watch: Fizzle highlights intent in adversarial vs. hacker mindset (7:00)

This session was presented as a panel discussion, bringing together multiple experts to share their insights and experiences on the adversarial mindset. As such, the talk did not include a live demonstration or a proof of concept of any specific tool, exploit, or attack methodology. The Adversary Village, which Abhijith 'Abx' B R leads, is known for hosting workshops, hands-on activities, and competitions related to offensive cybersecurity research, providing opportunities for attendees to engage with practical applications of these concepts. However, the panel itself focused on theoretical frameworks, strategic perspectives, and real-world anecdotes rather than a technical demonstration.

Defensive Implications

▶ Watch: World War II plane analogy for defense hardening (8:00)

The panel provided profound implications for how defenders should approach cybersecurity, urging a fundamental shift from reactive, compliance-driven postures to proactive, adversarial-minded strategies.

Firstly, the most critical implication is the need to shift from compliance to critical thinking. Compliance, while a necessary baseline, is "static" and easily anticipated by attackers. Defenders must move beyond simply checking boxes and instead engage in dynamic, critical thought about "what can go wrong" and "why not" (as Fizzle put it) to anticipate novel attack paths. This means understanding the adversary's intent and resourcefulness, not just technical vulnerabilities.

Secondly, organizations must re-prioritize their defensive efforts by focusing on the "Actions on Objective" phase of an attack, as highlighted by Bryson's Attack Model (BAM). While preventing initial access is important, the panel stressed that defenders have a significant advantage once an attacker is inside their network. This is the "defender's playground," where they control the assets, communication protocols, and choke points. Investing in robust internal monitoring, detection, and response capabilities to identify and contain attackers after initial compromise is crucial. This requires deep visibility into internal network activity and understanding what "normal" behavior looks like versus adversarial actions.

Thirdly, the panel strongly advocated for purple teaming as the most effective strategy for continuous improvement. Bryson described purple teaming as a "process that brings people together to collaboratively scope, plan, execute and fix together." Unlike traditional red teaming (where red teams "win" and leave a report) or blue teaming (which often follows static playbooks), purple teaming fosters collaboration, learning, and mutual improvement between offensive and defensive teams. This iterative process allows organizations to test their defenses against realistic threats, identify gaps, and implement fixes in a coordinated manner. Starting simply with tools like Atomic Red Team can help organizations build momentum and graduate to more sophisticated purple team exercises.

Fourthly, the discussion on Breach and Attack Simulation (BAS) offered a nuanced perspective. While Bryson, as a BAS vendor, acknowledged its utility, Anant cautioned against prematurely adopting BAS. He stressed that organizations lacking foundational security (e.g., proper vulnerability assessments, penetration testing, and basic security operations) might be overwhelmed by BAS results without the resources or processes to act on them. For critical entities handling sensitive data (finances, PII, health data), BAS might be a necessary starting point to quickly identify major holes. However, for others, building a "gradual security posture" with VA and PT first is often more effective. BAS is a tool, not a solution, and cannot substitute for leadership, people, process, or policy.

Fifthly, defenders must adopt a holistic view of vulnerabilities. The panel clarified that vulnerabilities are not solely technical flaws. Social engineering, process weaknesses (e.g., lax vendor enrollment policies, budget-driven procurement), and human factors are equally, if not more, exploitable. This necessitates comprehensive security awareness training, robust identity and access management, and secure operational processes that account for human behavior.

Finally, the rapid evolution of technology, exemplified by tools like ChatGPT, means defenders must commit to continuous learning and adaptability. Fizzle noted that adversaries also stay abreast of new technologies, constantly looking for "chinks in the armor." Defenders must not only understand how new technologies work but also anticipate how they can be misused or exploited, fostering a mindset that constantly asks "what else could it do?" and "what if?" to stay ahead of the curve. This proactive, imaginative approach is essential for building resilient defenses in an ever-changing threat landscape.

Key Takeaways

  • Embrace the Adversarial Mindset: Effective defense requires understanding attacker motivations and methods, prioritizing mission objectives over technical elegance, and anticipating how adversaries will exploit any vulnerability—technical, social, or process-related.
  • Compliance is Not Security: Relying solely on static compliance checklists creates predictable defenses that attackers can easily circumvent. Security demands dynamic, critical thinking and continuous adaptation beyond minimum requirements.
  • Attackers Often Win Easily: Many compromises exploit basic vulnerabilities, misconfigurations, or social engineering, rather than requiring advanced exploits. Defenders must ensure fundamental security hygiene is robust.
  • Leverage the "Defender's Playground": Once an attacker gains initial access, they operate within the defender's environment. Focus defensive efforts on detecting and containing "Actions on Objective" by monitoring internal networks and controlling choke points.
  • Prioritize Purple Teaming: Implement collaborative purple teaming exercises that bring offensive and defensive teams together to jointly scope, execute, and remediate, fostering continuous learning and security posture improvement.
  • Tools Are Not Solutions: Breach and Attack Simulation (BAS) and other security tools are valuable, but they are not a substitute for critical thinking, strong leadership, well-defined processes, and skilled personnel.

About the Speaker(s)

  • Abhijith 'Abx' B R: The host of the panel, Abhijith, known as 'Abx', is the Village Lead for the Adversary Village at DEF CON. His work focuses heavily on adversary simulation and offensive cybersecurity research. Under his leadership, the Adversary Village hosts a variety of workshops, discussions, hands-on activities, and competitions, all centered around cultivating an adversarial mindset within the cybersecurity community.
  • Bryson Bort: A prominent figure in offensive security, Bryson Bort earned the nickname "Grim" during his time in government. After leaving public service, he founded Grim, an offensive consultancy. He later co-founded Scythe, an adversary emulation platform that he initially conceived in 2016 as "Project Crossbow" to be an alternative to Cobalt Strike. Bryson is also a co-founder of the ICS Village, dedicated to educating on industrial control systems security. He secured venture capital funding from notable figures like Ron Gula (Tenable) and Dmitri Alperovitch (CrowdStrike).
  • Anant: Anant is the founder of Siphonoid Research, a company primarily focused on addressing challenges in cloud security and software supply chain security. His expertise lies in understanding the intricacies of modern software architectures and their vulnerabilities from an attacker's perspective, providing insights into how these complex systems can be compromised and secured.
  • Lieutenant Colonel Gordon Boom (Fizzle): Lieutenant Colonel Gordon Boom, who goes by "Fizzle," serves in the United States Air Force. His background is rooted in offensive cyber operations (OCO), where he gained significant experience in attacking and exploiting systems. Currently, he works with the 567th Operations Group, which is responsible for Service Cyber Protection Teams. These teams play a crucial role in responding to and defending blue networks within the Air Force, bridging the gap between offensive insights and defensive strategies.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent panel with credible speakers who clearly know their domain, but the content doesn't break new ground — adversarial mindset evangelism, compliance-is-not-security, and purple teaming have been DEF CON staples for a decade. The BAM framework is a useful simplification of ATT&CK/Kill Chain but isn't novel enough to anchor a talk.

Heather Calloway (CISO) — WEAK

Credible speakers with real operational experience, but the talk produces a collection of familiar principles rather than a usable shift in how defenders or leaders operate. The adversarial mindset thesis is real — the delivery never gets close enough to institutional conditions to make it actionable for anyone running a security program.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33