Uploaded August 2026 | Updated September 2026, 3 hours ago
Vishal Thakur (Atlassian, AU)
Cyber defense has always lagged behind adversarial innovation. Frameworks such as MITRE ATT&CK have revolutionized how defenders codify and respond to known tactics and techniques — but they remain retrospective by design. PR3TACK (Preemptive Tactics & Countermeasures Knowledgebase) challenges this paradigm by introducing a structured, openly accessible framework to catalogue plausible but unobserved or unreported adversary TTPs.
As opposed to documenting what has occurred, PR3TACK anticipates what could (and most likely will) occur. Drawing from technical plausibility, adversarial‑innovation patterns, and foresight methodologies, the framework bridges the gap between known vulnerabilities and emerging threat surfaces.
Developed within the Atlassian CSIRT and currently shared with select industry peers, PR3TACK was built to integrate directly into real‑world incident‑response and detection‑engineering programs. The framework will be released to the wider security community at the 38th Annual FIRST Conference, accompanied by an open application process for contributions, enabling researchers, defenders, and academic teams to propose and validate new tactics and countermeasures collaboratively. CSIRTs can also request membership to join the PR3TACK Members Team and the Core Team, gaining access to newly catalogued TTPs and preemptive‑defense mappings as they are added.
This talk will unveil PR3TACK’s conceptual foundations, including its novel tactic classes such as Pre‑Positioning, Resilience Erosion, Governance Subversion, Cognitive Manipulation, and Digital Exhaust Manipulation — domains that extend well beyond code execution into governance, cognition, and socio‑technical manipulation.
Participants will learn how to use PR3TACK’s interactive Seed Matrix and Navigator to map emerging TTPs, guide red and purple team exercises, and harden environments before exploitation occurs. We will also share how to get involved with the project and submit new TTPs for inclusion in the framework by becoming a PR3TACK Affiliated Researcher.
PR3TACK redefines cyber defense as a proactive discipline, empowering analysts, CSIRTs, and researchers to think one step ahead of the adversary.
The author's of this session include David Wearing, Niels Heijmans, and Vishal Thakur.
---
Vishal Thakur is a Regional Manager of CSIRT operations and security researcher based in Sydney, Australia. With over 13 years of experience leading incident response and cyber defense teams across Atlassian, Salesforce, TikTok USDS, Commonwealth Bank of Australia, he specializes in large-scale threat detection, malware analysis, and proactive cyber operations.
Vishal is the Founder of HackSydney and BSides Sydney, and a frequent speaker and trainer at FIRST, DEF CON, Black Hat, SANS conferences. His current research focuses on anticipatory threat modeling, AI-enabled adversarial simulation, and preemptive defense frameworks. He is the creator of PR3TACK, a next-generation threat modeling framework, and Warhead, a research project for offensive techniques that can be used for red-teaming operations. Vishal has also actively worked in the research field of cognitive malware and has published papers on that subject in academic and institutional journals.
Vishal Thakur (Atlassian, AU)
Cyber defense has always lagged behind adversarial innovation. Frameworks such as MITRE ATT&CK have revolutionized how defenders codify and respond to known tactics and techniques — but they remain retrospective by design. PR3TACK (Preemptive Tactics & Countermeasures Knowledgebase) challenges this paradigm by introducing a structured, openly accessible framework to catalogue plausible but unobserved or unreported adversary TTPs.
As opposed to documenting what has occurred, PR3TACK anticipates what could (and most likely will) occur. Drawing from technical plausibility, adversarial‑innovation patterns, and foresight methodologies, the framework bridges the gap between known vulnerabilities and emerging threat surfaces.
Developed within the Atlassian CSIRT and currently shared with select industry peers, PR3TACK was built to integrate directly into real‑world incident‑response and detection‑engineering programs. The framework will be released to the wider security community at the 38th Annual FIRST Conference, accompanied by an open application process for contributions, enabling researchers, defenders, and academic teams to propose and validate new tactics and countermeasures collaboratively. CSIRTs can also request membership to join the PR3TACK Members Team and the Core Team, gaining access to newly catalogued TTPs and preemptive‑defense mappings as they are added.
This talk will unveil PR3TACK’s conceptual foundations, including its novel tactic classes such as Pre‑Positioning, Resilience Erosion, Governance Subversion, Cognitive Manipulation, and Digital Exhaust Manipulation — domains that extend well beyond code execution into governance, cognition, and socio‑technical manipulation.
Participants will learn how to use PR3TACK’s interactive Seed Matrix and Navigator to map emerging TTPs, guide red and purple team exercises, and harden environments before exploitation occurs. We will also share how to get involved with the project and submit new TTPs for inclusion in the framework by becoming a PR3TACK Affiliated Researcher.
PR3TACK redefines cyber defense as a proactive discipline, empowering analysts, CSIRTs, and researchers to think one step ahead of the adversary.
The author's of this session include David Wearing, Niels Heijmans, and Vishal Thakur.
---
Vishal Thakur is a Regional Manager of CSIRT operations and security researcher based in Sydney, Australia. With over 13 years of experience leading incident response and cyber defense teams across Atlassian, Salesforce, TikTok USDS, Commonwealth Bank of Australia, he specializes in large-scale threat detection, malware analysis, and proactive cyber operations.
Vishal is the Founder of HackSydney and BSides Sydney, and a frequent speaker and trainer at FIRST, DEF CON, Black Hat, SANS conferences. His current research focuses on anticipatory threat modeling, AI-enabled adversarial simulation, and preemptive defense frameworks. He is the creator of PR3TACK, a next-generation threat modeling framework, and Warhead, a research project for offensive techniques that can be used for red-teaming operations. Vishal has also actively worked in the research field of cognitive malware and has published papers on that subject in academic and institutional journals.










