Here and Now: Exploiting the Human Layer at the Right Moment

Daniel Isler (Team Leader · Dreamlab Technologies)

DEF CON 33 · Day 1 · Main Stage

Overview

In a field often fixated on meticulously crafted plans and technical exploits, Daniel Isler's DEF CON talk, "Here and Now: Exploiting the Human Layer at the Right Moment," offers a profound paradigm shift for social engineers and red teamers. Isler, the team leader of the "friendly rats" social engineering unit at Dreamlab Technologies, argues that true success lies not in the perfection of a script, but in the instinctive ability to adapt and improvise in real-time, leveraging the "perfect moment" that the environment itself provides. This approach challenges the deeply rooted belief that exhaustive pretexts and OSINT are the sole determinants of infiltration success.

Watch on YouTube

Visual summary for Here and Now: Exploiting the Human Layer at the Right Moment by Daniel Isler
Visual summary for Here and Now: Exploiting the Human Layer at the Right Moment by Daniel Isler

Key moments

  1. 0:00 Introduction: The perfect moment to drop the script
  2. 3:55 Why rigidity kills instinct in social engineering
  3. 4:15 Case study: Exploiting a real-time water leak incident
  4. 7:00 "The Rehearsal" analogy: Reality always changes
  5. 9:00 Introducing the PERCEIVE-VALUE-DECIDE-ACT framework
  6. 10:30 Applying P-V-D-A: Navigating the DEF CON maze

Here and Now: Exploiting the Human Layer at the Right Moment

Speakers: Daniel Isler, Team Leader, Dreamlab Technologies

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=vvDostysRAU

Overview

In a field often fixated on meticulously crafted plans and technical exploits, Daniel Isler's DEF CON talk, "Here and Now: Exploiting the Human Layer at the Right Moment," offers a profound paradigm shift for social engineers and red teamers. Isler, the team leader of the "friendly rats" social engineering unit at Dreamlab Technologies, argues that true success lies not in the perfection of a script, but in the instinctive ability to adapt and improvise in real-time, leveraging the "perfect moment" that the environment itself provides. This approach challenges the deeply rooted belief that exhaustive pretexts and OSINT are the sole determinants of infiltration success.

Isler's presentation, delivered for the sixth time at DEF CON and celebrating his team's 10th anniversary, delves into the psychological underpinnings of human interaction, drawing parallels from photojournalism, military strategy, and even experimental reality television. He posits that the "red button" for social engineering success has always been the target themselves, and the key to influencing them is a dynamic responsiveness to unfolding situations. This talk is not merely about bypassing security controls; it's about understanding and manipulating the human perception of reality, making the impossible seem like a natural flow of events.

The significance of Isler's work extends beyond the red team community. For defenders, his insights illuminate the critical vulnerabilities inherent in human behavior and organizational rigidity. By showcasing how seemingly chaotic or mundane events can be weaponized by skilled social engineers, the talk provides a crucial framework for understanding advanced persistent threats that target the human element. It underscores the imperative for security awareness training to evolve beyond rote protocol adherence, fostering instead a culture of critical thinking and dynamic situational awareness.

Background

▶ Watch: Introduction: The perfect moment to drop the script (0:00)

The landscape of social engineering has traditionally been dominated by the pursuit of the perfect pretext. Conventional wisdom dictates that a meticulously researched cover story, complemented by appropriate attire, a convincing tone of voice, well-crafted communication (such as emails), the use of technical jargon, and extensive Open Source Intelligence (OSINT) on the target, collectively form the bedrock of a successful infiltration. This belief system emphasizes control: controlling the narrative, controlling the target's perception, and controlling the execution of a pre-planned script.

However, Isler contends that this rigid adherence to a script is precisely where many social engineering operations falter. The core problem, he explains, is that reality always changes. No amount of rehearsal or planning can account for every variable. What happens when the expected contact isn't present, when physical access protocols have unexpectedly shifted, or when a target explicitly states, "You are not in the company database"? In such scenarios, the "pentester who force a tool even though the environment has changed" or the "salesperson who keeps reading their pitch even after the customer already says yes" become analogues for social engineers who fail to adapt.

Isler vividly illustrates this rigidity, stating that "rigidity kills instinct." In the high-stakes environment of physical social engineering, instinct is the critical differentiator between success and failure. The speaker highlights that while elaborate planning is valuable, its effectiveness diminishes rapidly when confronted with the unpredictable nature of human interaction and dynamic environments. The challenge, therefore, is to move beyond the quest for an unassailable script and instead cultivate the ability to recognize and capitalize on spontaneous opportunities – the "perfect moment" – that emerge from the chaos of real-world operations. This shift in mindset from control to improvisation forms the foundational premise of his talk.

Key Findings

▶ Watch: Case study: Exploiting a real-time water leak incident (4:15)

The central revelation of Isler's talk is the assertion that the "perfect moment" to execute or adapt a social engineering plan is far more critical than the "perfect script" itself. This finding directly challenges the conventional wisdom that meticulous planning and unyielding adherence to a pretext are paramount. Instead, Isler advocates for improvisation with precision, a dynamic approach where the social engineer remains highly attuned to environmental cues and human reactions, ready to pivot at a moment's notice.

Isler's team, "friendly rats," has achieved an astounding success rate, experiencing only one failure in 10 years, a testament to the efficacy of their methodology. This success stems from two key frameworks they employ:

  1. The Perceive, Value, Decide, Act (PVDA) Framework: This iterative process enables real-time decision-making and adaptation. It acknowledges that every action, whether buying a drink or attempting a covert infiltration, follows a chain of internal and external signals.
  2. The "Is what I'm doing being accepted?" and "Iceberg Principle" Framework: This framework guides the social engineer in assessing the target's acceptance, identifying the decisive moment for intervention, and strategically controlling the information flow. It emphasizes saying just enough and allowing the target to fill in the blanks, thereby convincing themselves.

These frameworks underscore that the environment often "speaks first," presenting unexpected opportunities or challenges. A skilled social engineer, rather than being derailed by these changes, recognizes them as invitations to improvise, crafting new narratives that align seamlessly with the unfolding reality. The outcome is not merely access, but access gained without force, where the social engineer is perceived as a natural, integrated part of the environment, a concept Isler likens to Augusto Boal's Invisible Theater.

Technical Deep Dive

▶ Watch: "The Rehearsal" analogy: Reality always changes (7:00)

Isler’s methodology is not about technical exploits in the traditional sense, but rather a sophisticated application of psychology and situational awareness, framed by two distinct yet complementary frameworks. These frameworks allow the social engineer to operate with improvisation with precision, transforming unpredictable field conditions into strategic advantages.

The first framework is Perceive, Value, Decide, Act (PVDA). This process, rooted in both psychiatry and military tactics, describes how individuals respond to a chain of internal and external signals:

  1. Perceive: This initial stage involves actively observing and gathering information through all senses – seeing, hearing, smelling, and even recalling relevant memories or thoughts related to the current situation. It's about recognizing what is happening in the immediate environment.
  2. Value: Once perceived, the information is evaluated. The social engineer asks: "Does what I see work for me?" This involves assessing if the current situation aligns with the objective, or if a modification to their own behavior or an attempt to influence the other person is necessary. It's a quick risk-benefit analysis.
  3. Decide: Based on the valuation, a decision is made. This often means changing the existing plan, adapting the pretext, or formulating a new approach entirely.
  4. Act: Finally, the social engineer produces the response that the context demands, executing the modified plan or new action.

Isler illustrates PVDA with a spontaneous example from the conference itself: finding himself in a restricted, empty white maze at the convention center and encountering two large security personnel. He perceives their presence, their red shirts, and patches. He values the situation, realizing he doesn't want to be ejected before his talk. When one guard asks, "Are you human?", Isler decides this is an opportunity to show vulnerability. He then acts by adopting a "Shrek's cat" tone and sincerely replying, "Yes, sir, I am human," which disarms the guards and leads to a gentle escort out. This demonstrates the framework's power in real-time, unplanned scenarios.

The talk’s core technical narrative revolves around a real-world physical infiltration case study, which highlights PVDA in action alongside the second framework. The team initially planned an infiltration as authorized suppliers, armed with fake credentials, props, and extensive OSINT. Their objective was to extract proximity card codes from an RFID reader. However, the environment "spoke first." While attempting to pull credentials, they perceived a technician rushing by, heard strange noises, and found a door half-open revealing chaos: ceiling pieces on the floor, water pouring from above the reception desk, and a technician on a ladder.

This unexpected development triggered an immediate application of the PVDA framework. They valued this chaos not as a deterrent, but as an invitation to improvise. They decided to completely abandon their original plan. On the spot, they crafted a new pretext: headquarter staff responding to an alert about a water leak potentially affecting the electrical system and preventing an operational outage. To support this, they quickly produced fake email threads on a tablet (disguised as a local HTML browser) and new lanyards. They then acted on this new pretext.

Upon entering, they encountered a receptionist and a floor manager, "Anna," who was a temporary replacement and thus unknown to their OSINT. When Anna expressed surprise at their unannounced visit, the second framework came into play: "Is what I'm doing being accepted?" The answer, initially, was no, indicating a need for a "shot" – a decisive moment of intervention. They showed Anna the fake email threads, "stuffed with big names" she recognized. This was a critical application of the Iceberg Principle: they didn't explain everything, allowing Anna to fill in the blanks, inferring their legitimacy from the familiar names and the urgency of the situation. She unknowingly validated them, asked to be included in future visits, and granted them free access.

The climax arrived at the server room, guarded by a serious, focused individual. He checked their credentials, hesitated, and began dialing his phone – the decisive moment. They immediately interrupted him, stating, "You can call Anna. She's now in charge and she can confirm our visit." This leveraged Anna's unwitting validation and the Iceberg Principle, as the guard's micro-expression shifted. He put down the phone, smiled, and personally escorted them through critical areas. They had become, as Isler explains, part of the natural flow, much like actors in Augusto Boal's Invisible Theater, where the audience accepts the staged reality without realizing it's a performance. The key was not to explain too much, letting the surface show while the rest remained beneath, thereby achieving the "impossible."

Demo / Proof of Concept

▶ Watch: Introducing the PERCEIVE-VALUE-DECIDE-ACT framework (9:00)

While Daniel Isler's talk does not feature a traditional software or hardware demonstration, it masterfully presents two detailed, real-world operational case studies as compelling proofs of concept for his dynamic social engineering frameworks. These narratives serve as vivid "demos" of how the Perceive, Value, Decide, Act (PVDA) and "Is what I'm doing being accepted?" / The Iceberg Principle frameworks are applied in high-stakes physical infiltration scenarios.

The primary demonstration is the "Water Leak Infiltration" scenario. Isler walks the audience through the entire process:

  • Initial Setup: The team had prepared an elaborate pretext as authorized suppliers, complete with fake credentials, props, and extensive OSINT. They intended to extract RFID card codes. This initial planning phase, though later abandoned, showcases the typical level of preparation.
  • Environmental Trigger: The "demo" truly begins when the team encounters an unexpected water leak, chaos, and a technician during their reconnaissance. This unplanned event, rather than derailing them, becomes the catalyst for the adaptive strategy.
  • Real-time Adaptation (PVDA in action): Isler details how they rapidly shifted their entire plan. They improvised a new pretext as headquarter staff responding to an emergency, fabricated email threads on a tablet (local HTML), and created new lanyards on the spot. This segment effectively demonstrates the agility and creative problem-solving central to their approach.
  • Infiltration and Validation: The narrative continues with their interaction with the receptionist and the temporary manager, Anna. Their use of the fake email threads (with "big names") and the strategic mention of Anna's name to the server room guard illustrates the practical application of the Iceberg Principle and the "Is what I'm doing being accepted?" framework. The guard's eventual acceptance and escort, driven by subtle cues and minimal explanation, serves as the ultimate proof of concept for the frameworks' effectiveness in gaining access without force.

Isler also includes a brief clip from Nathan Fielder's TV show, "The Rehearsal," as an analogous concept. This serves not as a technical demo, but as a conceptual illustration that "no matter how much we try to control reality, reality always change." This analogy reinforces the core message that attempting to pre-script every possibility is futile, and thus, improvisation is essential.

These detailed narratives, presented as step-by-step accounts of successful operations, function as powerful demonstrations of the talk's central thesis: that dynamic adaptation and leveraging the perfect moment are paramount in social engineering. They prove that the frameworks are not merely theoretical constructs but practical, highly effective tools for achieving infiltration goals in complex, unpredictable environments.

Defensive Implications

▶ Watch: Applying P-V-D-A: Navigating the DEF CON maze (10:30)

Daniel Isler’s insights offer profound implications for organizational defense, shifting the focus from purely technical safeguards to the often-overlooked vulnerabilities within the human layer. Defenders must recognize that the "red button" for social engineering is the human element itself, and traditional security awareness training, which often emphasizes rigid adherence to protocols, may inadvertently foster the very rigidity that attackers exploit.

Firstly, organizations must move beyond static security awareness campaigns. Instead of merely teaching employees what to do, training should focus on developing critical thinking and situational awareness. Isler's frameworks highlight that attackers exploit unexpected situations and the natural human tendency to fill in information gaps. Employees need to be trained to identify and question inconsistencies, even when an individual appears to be legitimate or is responding to an apparent crisis. The "water leak" scenario demonstrates how a real-world emergency can be weaponized; employees must be equipped to verify identities and mandates even under pressure, not just during routine operations.

Secondly, verification protocols must be robust and universally applied, particularly in dynamic or high-stress environments. The fact that "Anna," a temporary replacement, was not in the OSINT and unknowingly validated the attackers underscores a critical vulnerability. Organizations need strict, multi-factor verification processes for all visitors, contractors, and even internal personnel claiming to be from other departments, especially when they cite urgency or unusual circumstances. These protocols should be ingrained to the point where they are instinctive, counteracting the "Invisible Theater" effect where attackers blend into the natural flow.

Thirdly, internal communication during emergencies needs to be exceptionally clear, rapid, and verifiable. If a real water leak or similar crisis occurs, all relevant personnel, especially those at reception or in security-sensitive areas, should receive immediate, authenticated alerts detailing who is authorized to respond and what their expected actions are. This preempts social engineers from leveraging information vacuums or the general confusion of a crisis to establish false legitimacy.

Finally, defenders should consider dynamic threat modeling that specifically accounts for human improvisation. Instead of solely focusing on technical attack vectors, security teams should simulate scenarios where social engineers exploit unexpected events, leveraging psychological principles like urgency, authority, and perceived legitimacy. This includes training security personnel and critical staff on recognizing micro-expressions and subtle behavioral cues that indicate hesitation or doubt, as demonstrated by the server room guard's reaction. By understanding the "applied art" of social engineering, organizations can build more resilient human defenses that prioritize adaptability and critical questioning over blind compliance.

Key Takeaways

  • Prioritize the "Perfect Moment" over the "Perfect Script": Effective social engineering hinges on dynamic adaptation to real-time environmental changes and human reactions, rather than rigid adherence to a pre-conceived plan. Rigidity kills instinct, which is paramount in the field.
  • Embrace Improvisation with Precision: Social engineers must cultivate the ability to pivot rapidly and strategically, leveraging unexpected events as opportunities. This means being deeply attuned to the environment and the target's responses.
  • Utilize the Perceive, Value, Decide, Act (PVDA) Framework: This four-step process provides a structured approach for real-time decision-making, allowing social engineers to interpret signals, evaluate their utility, adapt their plan, and execute a context-appropriate response.
  • Master the "Iceberg Principle": By providing just enough information and allowing targets to fill in the blanks, social engineers can lead individuals to convince themselves of the attacker's legitimacy, making the infiltration appear as a natural part of the environment.
  • Defenders Must Foster Critical Thinking and Dynamic Verification: Organizations need to train employees to question seemingly legitimate or urgent situations, verify identities even under pressure, and recognize subtle inconsistencies, rather than simply following rigid protocols.
  • Social Engineering is an Applied Art: Beyond technical prowess, successful social engineering demands presence, rhythm, and composition – a deep understanding of human psychology and the ability to seamlessly integrate into the target's reality.

About the Speaker(s)

Daniel Isler is the Team Leader of "friendly rats," the dedicated social engineering unit at Dreamlab Technologies. A seasoned expert in the field, Isler is a familiar face at DEF CON, where this presentation marked his sixth time speaking. His team, "friendly rats," is celebrating its 10th anniversary, a decade during which they have exclusively focused on social engineering, eschewing even common tactics like phishing for the past two years in favor of a more "vintage style" approach. Isler emphasizes that their work is the result of significant effort, learning from failures, and a deep passion from his entire team.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Competent war-story talk with a clean framework and a genuinely good case study, but the conceptual scaffolding (PVDA, Iceberg Principle) is dressed-up common sense that any experienced SE practitioner already lives by. Solid slot-filler for a DEF CON Human Factors track; won't move the needle for anyone who's read Cialdini, trained with Chris Hadnagy, or run more than a handful of physical ops.

Heather Calloway (CISO) — WEAK

Isler presents a genuinely interesting operational philosophy — improvisation over script — backed by a compelling real-world case study. But the talk stays inside the red team lane and never crosses into institutional relevance. Defenders get a list of training recommendations, not a defensible program.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33