Skip to content

[research doctrine] Azazel 2027–2028: Dual-Terrain Co-Adaptive Active Cyber Defense #64

Description

@01rabbit

Current phase

This doctrine is the long-horizon research north star after the Black Hat USA presentation and after Black Hat Europe CFP submission. Conference schedules may consume results but do not define technical acceptance gates.

System-wide execution is coordinated by #66.

Purpose

Define the next research north star for the Azazel Series, not only Azazel-Edge, without discarding its origin as a Cyber Scapegoat Gateway that translates delaying action into cybersecurity.

The problem is strategic obsolescence: local LLMs, RAG, multi-agent orchestration, hypothesis generation, human approval, and governed closed-loop response are becoming commodity capabilities. Azazel must therefore avoid competing on model scale or generic AI-SOC features.

North-star hypothesis

Azazel should evolve into a co-adaptive Active Cyber Defense system that shapes real and adversary-facing Presented Terrain, manipulates adversary tempo, and creates measurable defensive initiative across distributed deterministic products.

M.I.O. remains an important cognition component, but is not the product moat. Models are replaceable inputs. Durable Azazel assets should be doctrine, state, effects, evidence, outcome trajectories, replay, controlled terrain, and human-AI team learning.

Research lineage that MUST be preserved

Cyber Scapegoat Gateway
  -> Delaying Action
  -> Delay / Divert / Observe
  -> time + observation advantage
  -> evidence advantage
  -> defensive decision advantage
  -> Active Cyber Defense
  -> AI-assisted reasoning
  -> governed defensive effects
  -> cross-series measured outcome memory
  -> co-adaptive tempo / terrain control

AI is a consequence of increasing defensive decision complexity, not the origin of Azazel.

Core research objects

1. Real Terrain

Authoritative defended environment: assets, identity, routes, services, trust, availability, mission criticality, and current defensive state.

2. Presented Terrain

The bounded adversary-facing environment the defender intentionally presents/exposes, including approved decoys, synthetic identity/credentials, exposed surfaces, route presentation, and deception state.

Presented Terrain is not a claim about what the adversary actually perceives or believes. Attacker perception/belief is an uncertain inference handled separately by Adversary Belief State.

The implementation term Perceived Terrain is rejected because it overstates defender knowledge of the adversary's internal state.

3. Adversary Tempo

Evidence-bounded measures of progression/change such as reconnaissance cadence, retry intervals, service/technique switching, lateral progression, interaction depth, and time between meaningful attacker actions.

Tempo must be evaluated as a change relative to evidence/baseline. It is not a universal attacker-speed score.

4. Adversary Belief State

A bounded uncertainty model over plausible goals/strategies/next moves. It must preserve unknown and competing alternatives and must never become unsupported actor identity, human-vs-AI attribution, or proof that deception was believed.

5. Defensive Effects

Tool-independent intended effects such as OBSERVE, DELAY/FRICTION, DIVERT, INSTRUMENT, CONTAIN, ISOLATE, RESTORE. Concrete tc/nft/EDR/cloud/deception actions are product-local adapters beneath this layer.

The existing canonical Defensive State vocabulary remains separate; this research must not silently redefine #62.

6. Defensive Initiative / Utility

Azazel should evaluate a multi-dimensional outcome rather than block = success or dwell time = success.

Candidate dimensions:

  • time gained;
  • evidence gained;
  • attacker progression/option reduction;
  • defender optionality preserved;
  • production exposure reduced;
  • decision quality / uncertainty reduction;
  • business/NOC impact;
  • action/safety risk;
  • operator workload;
  • compute/resource cost.

No scalar formula is accepted until empirically calibrated and reviewed.

7. Outcome Memory

The series must preserve a factual, replayable chain:

what was observed
-> what authoritative effect actually occurred
-> what terrain was materialized
-> what reaction/outcome was observed
-> what cost/confounders existed

Knowledge owns durable outcome memory/advisory retrieval; it does not become policy authority.

8. Human-AI Co-Adaptation

M.I.O. may learn from validated trajectories:

Situation
+ M.I.O. recommendation
+ operator decision and rationale
+ authoritative effect
+ actual outcome
+ business impact / confounders

It must learn doctrine from outcomes, not simply imitate operator preferences. Any learned doctrine change is proposed/versioned/reviewed; it does not self-modify live policy.

9. Independent Strategic Council

MAGI-inspired multi-perspective reasoning may be explored through independent roles such as Intelligence / Operations / Preservation. Initial reasoning remains blinded from peer outputs; dissent is preserved; simple majority vote must never be authority. Deterministic product-local authority remains final.

Series role doctrine

Azazel

Doctrine, terminology, research governance, system evaluation and kill criteria.

Azazel-Edge (AZ-01)

Primary authority/cognition/strategy implementation: eligible effects, Tempo/Initiative, Real/Presented Terrain strategy projection, Belief, counterfactual planning, M.I.O. council/co-adaptation. Program: 01rabbit/Azazel-Edge#391.

Azazel-Gadget (AZ-02)

Distributed deterministic reflex and constrained local evidence/effect/outcome contribution. No mandatory M.I.O. Program: 01rabbit/Azazel-Gadget#19.

Azazel-Knowledge (AZ-04)

Behavioral memory + structured Outcome Memory + comparative historical evidence + reviewed team/doctrine evidence. Advisory only. Program: 01rabbit/Azazel-Knowledge#66.

Azazel-Fabric (AZ-05)

Minimum shared language for cross-product effect/outcome/Presented Terrain references. Never planning/scoring/authority. Program: 01rabbit/Azazel-Fabric#15.

Azazel-Deception (AZ-06)

Materialized Presented Terrain, bounded finite-state transitions, fingerprint/oracle testing, interaction/outcome evidence. Program: 01rabbit/Azazel-Deception#30.

System-wide loop

Edge / Gadget evidence
 -> local deterministic authority
 -> bounded Defensive Effect
 -> local adapter and/or AZ-06 Presented Terrain
 -> observed reaction/outcome + business/NOC/resource cost
 -> Knowledge Outcome Memory
 -> M.I.O. Belief / Counterfactual / Council
 -> operator decision/rationale
 -> replay / comparison / doctrine proposal
 -> next encounter

No repository may duplicate another repository's authority merely to complete this loop.

Historical-doctrine principle

Japanese Army/Navy doctrine may be translated into cyber research hypotheses where defensible, including:

  • delaying/endurance;
  • defense in depth;
  • progressive attrition / interception;
  • decoy / diversion / deception;
  • preservation of combat power / options.

Failures must be encoded as anti-patterns too: rigid enemy assumptions, decisive-battle fixation, irreversible sacrifice, resource/logistics blindness, and doctrine that cannot adapt to evidence.

No historical doctrine is accepted because it is historically interesting; each translation needs a measurable cyber hypothesis, safety boundary, and falsification condition. See #65.

Non-negotiable safety / architecture invariants

  • no hack-back or attacker-system compromise;
  • effects remain inside authorized/managed environments;
  • AI/model output never directly owns enforcement authority;
  • each product retains its explicit deterministic authority boundary;
  • Knowledge/Fabric never become hidden policy engines;
  • uncertainty and dissent must be representable;
  • interaction with deception is not proof of belief/intent/identity;
  • model absence reduces cognition, not baseline defensive availability;
  • every live effect is bounded, reversible where possible, auditable, and terminate-able;
  • business/NOC safety can preempt engagement/learning value;
  • cross-product failure must degrade safely rather than make optional components mandatory.

Competitive / prior-art discipline

Assume capable external teams have access to stronger models, more compute, faster agent frameworks, and comparable public research.

The series therefore must not rely on model prestige or novelty-by-composition.

This program assumes the following are not differentiators by themselves:

  • multi-agent LLMs;
  • voting/debate;
  • MTD;
  • adaptive deception;
  • honeypots;
  • digital twins;
  • Bayesian attacker models;
  • AI SOC triage;
  • human approval / bounded autonomy;
  • RAG/long-term memory;
  • generic agent tool use.

Every research claim must be compared against strong current baselines. Record baseline results before tuning the proposed system. If a simpler system reproduces the value, improve or abandon the weaker Azazel feature.

Do not use world first language without dedicated literature/patent review.

Kill criteria

A proposed Azazel feature should be stopped or demoted if:

  1. it is primarily a model-quality feature that an external model upgrade replaces;
  2. it cannot be evaluated independently of fluent LLM prose;
  3. it increases live authority without measurable defensive benefit;
  4. it is equivalent to static deception/MTD under a new name;
  5. it does not improve at least one measurable defender outcome without unacceptable business/safety cost;
  6. a simpler deterministic implementation achieves equivalent results;
  7. cross-product complexity costs more reliability/latency than the measured benefit;
  8. the outcome cannot be replayed or independently reviewed.

Required implementation programs

Current M.I.O. Cognitive Plane work remains the foundation track, not the long-term differentiation by itself.

Acceptance criteria

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions