Parts I through IV established the architecture of sHUMINT: behavioral profiling, probing, consistency testing, and attribution. Each pillar operates on the assumption that an AI-driven attack carries structural seams technical, logical, and motivational that allow an analyst to move from "this is automated" to "this is automated by someone specific, toward a specific end."

This part addresses the layer beneath that architecture. Not the seams in the machine's reasoning, but the residue of the human operator baked into the machine's behavior. For the next one to two years, AI conducting multi-stage attacks will not operate as an independent strategist. It will operate as a proxy executing borrowed TTPs, yes, but also inheriting the operator's stylometric habits, temporal rhythms, and lexical preferences in ways that survive automation. The machine is the instrument. The human residue is the signal.

This is where HUMINT meets synthetic execution.

A single operator running a multi-stage AI-driven attack against a company does not simply deploy a tool and step back. They configure it, prompt it, correct it, and approve its outputs at decision points. Each intervention leaves a trace. More importantly, even when the operator is not actively steering, the AI's training data, fine-tuning, and operational framing were shaped by human choices which historical attacks to emulate, which tone to adopt, which targets to prioritize.