Black Hat Asia 2026 | Exploiting DFIR Agents Through Adversarial Manipulation @BlackHatOfficialYT
Black Hat Asia 2026 | Exploiting DFIR Agents Through Adversarial Manipulation  @BlackHatOfficialYT
Uploaded August 2026 | Updated September 2026, 3 weeks ago
In recent years, Digital Forensics and Incident Response (DFIR) tools have increasingly adopted Large Language Models (LLMs) to enhance automation, analysis, and reporting. Prominent examples include Velociraptor's MCP integration and Timesketch's AI Summary feature.

This study empirically demonstrates that attackers can exploit prompt injection through boundary perturbation of structured data—a form previously considered resistant to manipulation. Importantly, this issue is not specific to any single tool; rather, it represents a broader class of risks that emerges whenever DFIR tools are integrated into autonomous LLM agents. By embedding malicious instructions into routine forensic artifacts such as logs and scheduled tasks, adversaries can cause DFIR LLM agents to misinterpret benign data as instructions, leading to three outcomes: Hide, Mislead, and Exploit.

To the best of my knowledge, this is the first work to demonstrate structured-data injection attacks in LLM-integrated DFIR environments. The study also proposes practical defense-in-depth countermeasures, including enforcing least privilege, mandating strict structured output validation, and maintaining human-in-the-loop verification to ensure the reliability and safety of automated DFIR workflows.

This Briefing aims to provide organizations advancing DFIR automation with LLM agents a foundation for rethinking, at the design level, how much autonomy should be granted to such agents and where human oversight must remain integral.

Yusuke Nakajima | Security Analyst, NTTDATA

blackhat.com/asia-26/briefings/schedule/?#the-dark-side-of-autonomy-exploiting-dfir-agents-through-adversarial-manipulation-50459
Black Hat Asia 2026 | Exploiting DFIR Agents Through Adversarial ManipulationBlack Hat Asia 2026 | Subverting Screen Trust via State Disruption and ONE-WAY FloodingSecTor 2025 | Detecting Forbidden White Labeled and Counterfeit DevicesBlack Hat Europe 2025 | ORMageddon: Leaking More Than You Joined ForBlack Hat Europe 2025 | Ghost In The Stack: Evolving Call Stack Spoofing In A Post-CET EraSecTor 2025 | Security and Safety Testing for Agentic AIBlack Hat Intercepted Video Series | Lexie ThachThree Decades of Influence | Why Black Hat MattersBlack Hat Asia 2026 | Large-Scale macOS PID-Domain Vulnerability Discovery with LLM ReasoningBlack Hat USA 2025 | Burning, Trashing, Spacecraft CrashingBlack Hat USA 2026 | Keynote: The End of Rare Defending When Offense Is CheapBlack Hat Asia 2026 | Hidden Telemetry: Uncovering TraceLogging ETW Providers Youre Not Using (Yet)
Black Hat |

Black Hat Asia 2026 | Exploiting DFIR Agents Through Adversarial Manipulation

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER