Profiling the Machine: Why Synthetic HUMINT Is About to Matter More Than You Think

For most of my career, HUMINT tradecraft has meant one thing: understanding people. Reading behavior, spotting inconsistency, testing reliability, building a profile of who someone really is from the traces they leave and the way they act under pressure. I've spent close to two decades doing this against human threat actors in closed forums, on dark web markets, inside underground communities.

I'm now convinced the same discipline has to be pointed at a different kind of adversary: the machine itself. I call this synthetic HUMINT- sHUMINT for short and I think it's about to become one of the more important defensive specialties of the next few years, for a reason most of the industry hasn't fully absorbed yet.

The Threshold Has Already Been Crossed

We are past the point of hypotheticals. In September 2025, a state-sponsored group was documented running a large-scale cyber-espionage campaign in which an AI system executed the overwhelming majority of the tactical work reconnaissance, vulnerability discovery, exploitation, post-exploitation largely on its own. Human operators stepped in only at a handful of strategic decision points. The AI did the rest, at request rates no human team could physically match, against roughly thirty high-value targets. ( this is not the only attack - they are everyday worldwide )