Uploaded August 2026 | Updated September 2026, 5 hours ago
Hiroaki Toyota (LAC Co., Ltd., JP)
Traditional defense models may soon face a formidable challenger: Self‑Modifying Agentic Malware, LLM‑guided code that continuously rewrites itself in response to local conditions, aiming to sidestep Endpoint Detection and Response (EDR). This talk presents a safe, containerized adversary‑emulation rig that demonstrates the observe–plan–act loop and showcases likely ATT&CK‑aligned techniques, from file‑less memory residence and process injection to polymorphic payloads and covert cloud‑based C2.
We then outline a Proactive EDR strategy built on five pillars, prominently featuring AI‑driven Intent‑Centric Correlation alongside sensor‑integrity checks, dynamic deception assets, moving‑target hardening, and risk‑based automated containment. Replayable telemetry, sample detection rules, and concise playbooks will be shared, enabling participants to reinforce their SOCs quickly with tool‑neutral methods and AI‑assisted analytics before this adaptive threat moves from laboratory proof‑of‑concept to real‑world incidents.
---
Hiroaki Toyota is an AI Researcher at LAC Co., Ltd., focusing on agentic AI and AI safety for cybersecurity. He leads R&D on AI-driven automation for security operations, AI red teaming, and safety evaluation. Previously, he developed machine learning and deep learning algorithms at an AI startup and has in-depth knowledge of AI architectures. His recent work on agentic AI for offensive security was presented at CODE BLUE 2025 in Tokyo.
Hiroaki Toyota (LAC Co., Ltd., JP)
Traditional defense models may soon face a formidable challenger: Self‑Modifying Agentic Malware, LLM‑guided code that continuously rewrites itself in response to local conditions, aiming to sidestep Endpoint Detection and Response (EDR). This talk presents a safe, containerized adversary‑emulation rig that demonstrates the observe–plan–act loop and showcases likely ATT&CK‑aligned techniques, from file‑less memory residence and process injection to polymorphic payloads and covert cloud‑based C2.
We then outline a Proactive EDR strategy built on five pillars, prominently featuring AI‑driven Intent‑Centric Correlation alongside sensor‑integrity checks, dynamic deception assets, moving‑target hardening, and risk‑based automated containment. Replayable telemetry, sample detection rules, and concise playbooks will be shared, enabling participants to reinforce their SOCs quickly with tool‑neutral methods and AI‑assisted analytics before this adaptive threat moves from laboratory proof‑of‑concept to real‑world incidents.
---
Hiroaki Toyota is an AI Researcher at LAC Co., Ltd., focusing on agentic AI and AI safety for cybersecurity. He leads R&D on AI-driven automation for security operations, AI red teaming, and safety evaluation. Previously, he developed machine learning and deep learning algorithms at an AI startup and has in-depth knowledge of AI architectures. His recent work on agentic AI for offensive security was presented at CODE BLUE 2025 in Tokyo.










