Skip to content

[program] Post-BHUSA Azazel Series research program — system-wide co-adaptive Active Cyber Defense #66

Description

@01rabbit

Parent doctrine: #64
Related doctrine/foundations: #60, #62, #65
Series-wide final gate: #67

Current phase

This program starts after the Black Hat USA presentation is complete and after the Black Hat Europe CFP has been submitted. Conference deadlines are no longer architecture gates.

From this point, Azazel is managed as a long-horizon system research program. Talks/demos may consume validated results; they do not define technical acceptance.

Strategic premise

Assume capable external teams can obtain stronger models, more GPU/compute, faster agent frameworks, mature security integrations, and commodity RAG/multi-agent/tool-use.

Azazel therefore must not depend on winning a model-quality race.

The durable advantage must come from:

doctrine + deterministic authority + bounded effects + measured adversary reaction + Presented Terrain + Outcome Memory + replay + operator/team learning.

A feature that disappears as soon as a better external model is substituted is not a durable Azazel advantage.

System-wide research loop

Edge / Gadget evidence
  -> deterministic evaluation / eligible Defensive Effects
  -> authoritative local decision
  -> bounded effect execution/materialization
       |-> local product adapter
       `-> AZ-06 Presented Terrain when approved
  -> measured reaction / outcome / NOC-business-resource cost
  -> Knowledge Outcome Memory
  -> M.I.O. hypothesis / belief / counterfactual / council reasoning
  -> operator decision + rationale
  -> replay / comparative evaluation
  -> reviewed doctrine/playbook proposal
  -> next encounter

No single repository owns this loop.

Current cross-repository programs

Series responsibilities

Azazel — Doctrine / Program Governance

Research doctrine, terminology, cross-product experiment design, prior-art/hostile review, system kill criteria, and claims discipline. No runtime authority.

Edge — Authority / Cognition / Strategy

Primary full-system decision authority on Edge; eligible-effect construction, Tempo/Initiative, terrain strategy projection, Belief, counterfactual planning, M.I.O. Council/co-adaptation.

Gadget — Reflex / Distributed Tactical Edge

Constrained deterministic local defense and evidence contribution. It proves whether Azazel doctrine survives on limited distributed hardware; it is not a mini Edge/M.I.O.

Knowledge — Memory / Outcome Intelligence

Immutable/rebuildable observations and reaction history, derived behavioral/outcome analysis, comparative history, reviewed experience/doctrine evidence. Advisory only.

Fabric — Language

Only shared representations needed for interoperability. Fabric describes and correlates; it never ranks, scores, plans, or authorizes.

Deception — Presented Terrain

Materializes approved synthetic adversary-facing environment, transitions only within signed/bounded state, proves isolation/reset, and emits interaction/outcome facts.

Cross-series gates

S0 — Authority and language

  • canonical Defensive State remains stable;
  • Defensive Effect is separate and non-authoritative outside owning product;
  • every cross-product message has producer/provenance/freshness semantics;
  • old mode/CTI terminology cannot recreate ambiguous authority.

S1 — Measurable effect/outcome loop

Before adaptive claims:

  • Edge/Gadget can record the bounded effect that actually occurred;
  • reaction/outcome/confounders are factual exports;
  • Knowledge can rebuild/replay outcome history;
  • #393 distinguishes useful delay from harmful delay;
  • telemetry loss/disappearance cannot score as success.

S2 — Presented Terrain loop

Before adaptive-deception claims:

  • AZ-06 materializes a bounded Presentation with valid producer lifecycle refs;
  • Edge distinguishes Real vs Presented Terrain;
  • transition cannot create production reachability/credential leakage/response oracle;
  • interaction never equals belief proof.

S3 — Cognition / co-adaptation

Before strategic-learning claims:

  • Belief/Counterfactual/Council remain advisory;
  • Knowledge fact lane remains separate from inference/doctrine;
  • team experience is outcome-validated;
  • no learned preference silently changes policy/Arbiter thresholds.

S4 — Series differentiation

Owned by #67. The integrated series must beat or justify itself against strong simpler baselines after cost, latency, reliability, adaptive-adversary behavior, and better-model replacement are included.

Competitive engineering doctrine

Without naming or targeting any external party, assume capable competitors improve continuously.

Therefore:

  • benchmark against strong baselines, never strawmen;
  • freeze baseline results before tuning the proposed system;
  • prefer reproducible measured advantage over impressive demos;
  • preserve failed experiments as useful research evidence;
  • treat stronger external models as a portability test for Azazel architecture;
  • do not claim novelty from naming or component composition alone;
  • if a simpler architecture reproduces the value, improve or abandon the weaker feature;
  • protect no feature from DEMOTE/KILL because of past investment or presentation value.

The objective is not to appear advanced. The objective is to remain technically defensible under hostile comparison.

Mandatory review rhythm

For each cross-series capability:

  1. normal architecture review;
  2. prior-art comparison;
  3. per-repository implementation review;
  4. cross-product contract/replay review;
  5. hostile/adaptive-attacker review;
  6. resource/availability review;
  7. correction;
  8. comparison to stronger/simple baseline;
  9. PASS / EXPERIMENTAL / DEMOTE / KILL.

A cross-product feature is not complete merely because every repository's unit tests pass.

System-level acceptance criteria

  • Every active Azazel product has an explicit next-generation role and owning issue.
  • No product duplicates another product's authority to support the new direction.
  • An effect can be traced across decision -> execution/materialization -> reaction -> outcome -> Knowledge -> replay with real provenance.
  • Real Terrain, Presented Terrain, attacker-belief inference, and observed interaction remain different semantic classes across repositories.
  • Gadget contributes useful evidence/outcomes without mandatory AI/central connectivity.
  • Knowledge supports learning without becoming a policy engine.
  • Fabric interoperability adds no decision logic.
  • AZ-06 changes presentation only under valid producer authority and proves isolation/reset.
  • The series produces at least one complete reproducible cross-product evidence bundle.
  • [review] Series-wide adversarial differentiation gate — prove the integrated Azazel System beats strong simpler baselines #67 executes strong generic-AI, static/deterministic, and better-model replacement baselines.
  • At least one proposed feature can be honestly demoted/killed if comparison disproves its value.
  • Conference/demo deadlines never override these gates.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions