Don't fight their strength — take away their advantage. Don't fight the boiling water — remove the firewood from under the pot.
— The 36 Stratagems, Remove the Firewood from Under the Pot
Previously on this series:
#1: Mark Johnson Walked Into an AI Audit. — Mark found Pulse AI's benchmark was fabricated — 44 records copied from public repos, 54 hand-written. CTO Torres called at midnight to confess: the target was 95% before the C-round. Mark hung up.
#13: P Posted a Question on a Public Forum. — P posted a technical question that triggered Pulse AI's sales crawler. Mark recognized the pipeline signature. P met Mark.
#16: Mark Left a Hole in His AI Audit. — Mark found Pulse AI's auto-labeling pipeline causing the same sampling exclusion at FairPay. He wrote a four-layer report, delivered three. Lena found the fourth.
The methodology is the firewood. Someone learned Mark's audit method and started using it against him. By the time Mark caught on, they'd already run his playbook on more than one project.
Mark took this client the way he took all of them — because the check cleared.
But something felt off from the first call.
Discovery
The client was SynthData, an AI data pipeline shop. Not finance, not healthcare, not regulated — just engineers helping other engineers move data around. The CEO said their nodes degraded every three weeks, then recovered. They'd checked. Not traffic.
Mark didn't respond. He scanned their tech stack instead. Early microservices, each one exposing its own healthz endpoint. When they retired a service, they only took down the main entry — the service registry's reverse-registration was still active. External traffic could still reach some retired endpoints.
He made a note. Dropped it in _hold/.
Day three, 3:14 AM. His audit script fired:
[ALERT] Account 'ops-deploy-02' — new session at [YEAR]-07-22 03:14:07 UTC
Three in the morning. An account called ops-deploy-02 had logged in.
Mark paused. First step of any audit: asset inventory. He pulled the IAM directory. ops-deploy-02 was tagged "Former Employee — Pending Reclamation." The owner was an SRE who'd left six weeks ago. The account wasn't disabled. Nobody remembered it existed.
He pulled the account's full audit log. Last week before departure — normal. Departure day — normal. Day three after departure — 3:01 AM, the crontab was changed by one line. Once a week ever since, never missed.
Mark pulled three months of logs. Same account, every Monday at 3 AM, one crontab edit — then back:
# 07-13 03:01 UTC — Changed
0 4 * * 1 /opt/synthdata/pipeline/healthz-check.sh
# 07-13 03:02 UTC — Reverted
0 3 * * 1 /opt/synthdata/pipeline/healthz-check.sh
The whole thing took under two minutes. Seventy-two hours later, a node always degraded.
He traced the script — buried in a retired service's systemd timer:
# /etc/systemd/system/healthz-check.timer
[Timer]
OnCalendar=Mon *-*-* 03:00:00
Unit=healthz-check.service
[Install]
WantedBy=timers.target
The matching .service called a Python script named probe_model_accuracy.py — designed to periodically validate SynthData's AI model accuracy during online inference.
Mark read the source. Before he was an auditor, he'd spent twelve years in engineering — reading other people's code was more familiar than writing his own. The script didn't use a standard test set. It fed production models a set of template shadow inputs — with time-dependent features (hour encoding, day-of-week encoding) injected at runtime. If the output deviated more than 2% from the baseline, it triggered an alert.
When the cron was offset by an hour, those time features no longer matched the baseline. The same inputs ran through the model and produced different outputs — a false positive deviation. The model auto-rolled back to its last stable version. When the cron ran at the correct time again, the same inputs matched the baseline. Everything recovered.
Not breaking the node — making the model think it was broken.
Change cron → trigger offset → degrade in three days. An invisible wire.
Mark didn't jump to conclusions. He built a local sandbox and ran probe_model_accuracy.py — shifted the system time, watched how the shadow input timestamp features changed with the offset. One hour offset, output deviation over threshold, model rolled back. Exactly what he'd predicted.
Then he checked the external IP. An AWS Elastic IP, registered to the Singapore region. Not a VPN exit node — same company, same cloud, same subnet mask.
Mark locked in two findings:
- The degradation was precisely calibrated below the model accuracy SLA payout threshold. The node wasn't broken — someone had calculated the limit.
- Fifteen minutes after each cron change, the same IP pinged a retired healthz endpoint. They were confirming they hadn't been detected.
He wrote the data in his notebook. Tagged it: _hold/_synthdata_pattern.
Then he opened the old files. Pulse AI, FairPay — different pipeline signatures, identical behavior patterns. Same time window. Same control amplitude. Same check-in rhythm.
He stopped at Pulse AI. Torres's business card was still in his notebook — the CTO who'd called at midnight to confess he'd faked a benchmark. Mark knew Torres's work. This wasn't his style. But the precision on the other side — the way they operated — it felt like someone had done their homework. No. Like someone had studied him.
He thought about Caleb. The engineer who'd sat across from him for three months, packaging twelve years of Mark's experience into an AI Skill. If the other side had ported Caleb's work into their playbook, Mark wasn't facing a bunch of people who'd read his reports. He was facing people who'd literally been trained on him.
He closed the notebook. 3:30 AM. Empty visitor area, one monitor still lit.
Mark shut the screen, grabbed his bag, didn't go home. He sat in the car until dawn, dozed a little. 11 AM, his phone buzzed. A new email. Unknown sender. Subject line:
_hold/
The body had one address. The Third Cup.
The Meeting
P picked The Third Cup.
By the time Mark arrived, the light was still fading. P was already in the corner, laptop open, screen dimmed to minimum. Behind the counter, someone was drying a cup — didn't look up, unhurried.
P turned the laptop toward Mark without a word.
"Your new client. Day one, someone was watching."
Mark hadn't even sat down. "Who?"
The screen showed a shared document directory — the title was his audit report from last year. Page three: his own paragraphs, annotated. Analysis Method note. Subject uses tiered disclosure. Layer 1 surface findings.
"Recognize yourself?" P said.
Mark's fingers stopped on the rim of his cup. "Whose document library was that in?"
"You think FairPay's report stayed with them?" P turned the screen — the metadata showed an access record with an unmarked name. "Their security vendor. The day you filed it, they had a copy."
P pushed the screen toward Mark. "I keep more than one line in. One always gets swept — you get used to it."
Mark didn't respond. He was running the timeline. FairPay was his last job. If the other side had been unpacking his methodology since then, Caleb's knowledge extraction was just the appetizer. Whoever these people were, they'd turned his method into a system.
P slid a piece of paper across the table. A printout — his _hold/ pathing habit, annotated: Subject Method Artifact — predictable naming pattern.
"Your folder names. Someone's studying how you work."
"That ops account. It's not a breach. They're using your method — you think you're investigating, but every step was pre-calculated."
Mark looked at the paper, didn't take it. "You know who."
"There's a training manual. One chapter has your name on it. How it reads? I don't want to know. But I know they're using your people." P finished the espresso, set the cup down. "Don't close that ops-deploy-02. Let it run — I need that line to watch them."
P stood up, pulled a business card from a jacket pocket, placed it on the table. Said nothing. Turned and walked out.
Mark waited until P had cleared the doorway before picking it up. The front had one name: ACL.
He turned it over. The back had a line:
Compliance is not a cost — compliance is competitive advantage.
Mark pocketed the card, stood to leave. Behind the counter, someone set a pour-over in front of him. Mark looked at it — he hadn't ordered. The man had already turned back.
Mark left the coffee untouched. Pulled a note from his pocket, pressed it under the cup, and walked out.
The Setup
Mark picked up the phone and called SynthData's CISO. 4 AM. Three rings, picked up.
"That ops-deploy-02 account you have on former employee hold — someone's using it."
The CISO didn't ask how Mark knew. They'd worked compliance reviews together. Mark wouldn't call at 4 AM without evidence.
"Cron changed three times. Three node degradations. I have the data."
The CISO made the call: don't disable the account. Legal gets involved. Controlled monitoring. Preserve the account, full logging, trace-first over stop-the-bleed.
"I'll send the written confirmation today."
Mark spent the whole day on it — evidence collection, audit channel setup, log review. By dark, he sat down to write the report.
He saved the draft to SynthData's shared audit workspace — the same system FairPay had used. If the other side was still monitoring that entry point, they'd see this draft.
Before writing, he left a shadow channel at the inference gateway layer:
# ~/synthdata/.monitor/inference_tracer.py
import json, time, hashlib
from kubernetes import watch, client
w = watch.Watch()
for event in w.stream(client.CoreV1Api().list_namespaced_pod,
namespace='default'):
pod = event['object']
if not pod.metadata.name.startswith('ops-deploy-'):
continue
if pod.status.phase == 'Running':
log_entry = {
"pod": pod.metadata.name,
"ts": time.time(),
"node": pod.spec.node_name,
"deployment_fingerprint": hashlib.sha256(
json.dumps(pod.metadata.labels).encode()
).hexdigest()
}
with open(f"/audit/.trace/{pod.metadata.name}.jsonl", "a") as f:
f.write(json.dumps(log_entry) + "\n")
If ops-deploy-02 spun up another inference pod, the script would silently track its deployment activity into isolated audit storage. No blocks, no alerts — the other side would have no idea someone was tracing them from the other end.
Layer one: surface issues. Node degradation fixes. Pipeline redundancy recommendations. The contract allowed phased disclosure — the real findings stayed in a second appendix. One printed copy only.
But Mark didn't stop there. He left a note in the first layer that looked incidental:
# Appendix B — Data egress audit recommendation
# Suspicious outbound traffic concentrated in apse1 (Singapore) region.
# Recommend prioritizing this region for data egress log review.
It wasn't true. SynthData's data egress was us-west. He wrote apse1 because — he'd seen the Singapore region in Pulse AI's cross-reference table. The three letters on the card shared the same exit.
If the other side was really monitoring his report, they'd see that line. If they believed it, they'd check that region. And if they checked — Mark would know.
That night, P's encrypted message came through.
"Your report was read. From a Singapore IP."
Mark stared at the line. Didn't reply. Bait placed. Fish bit.
He closed the laptop. Five steps, each one testing the same hypothesis: they were playing his game against him.
Next move wasn't defense anymore.
"I'll watch the document library. Anyone who opens your report, I'll log it."
Mark replied: "Is it safe?"
P sent two lines back. First: an IP address. Second: "Two-week safety window. Enough."
Mark sealed the appendix in his document bag. The window was lightening outside.
Delivery
Thursday, 10 AM. The CEO flipped through layer one. His expression relaxed.
"These are all fixable. Did you find the root cause?"
Mark waited for the question. "Yes."
He pulled the printed appendix from his bag, set it in front of the CEO. Held it a second longer before letting go.
The CEO's expression changed on page one. On page two, he put the report down.
"When did you find this?"
"Suspected it on day one. Confirmed on day three."
"Who did this?"
Mark placed the card on the table. Face up. ACL.
The CEO looked at it for a long moment. Didn't pick it up. "What do they want?"
"I don't know," Mark said. "But they're using my method. My name's in their training manual. Day one at the client, someone was watching."
The CEO slid the report into his drawer. Didn't ask again.
Mark stood, walked out. Paused at the elevator. The door opened. He didn't get in.
He pulled out his phone. Scrolled to P's number. Didn't dial. Put it back.
The elevator door closed. His phone vibrated. P's message. Three words:
"Got it."
Not a question. Not a confirmation. P didn't explain. The screen went dark. He closed the phone.
Mark stepped out of the building — still daylight. Made a few calls, wrapped up loose ends, then walked to The Third Cup.
The Cost
Mark sat from afternoon until dark. He knew P wouldn't message during a safety window. He wouldn't either — if P's entry point was already watched, any contact would draw the fire.
When he sat down, the man behind the counter set a pour-over in front of him. Didn't ask what he wanted. Mark didn't say anything. The cup went from hot to warm, from warm to cold. He didn't notice.
When the lights came on, the man walked over and pushed a napkin across the counter.
Mark unfolded it. The creases were deep. P's handwriting — not fresh. Left before the entry was closed.
"Entry's gone. Two weeks. Don't reach out. I'll find you."
He turned it over. The other side read:
"I fixed the hole. Not the system — my entry point."
P's access had been cut. Not by the other side — an automated security policy had swept up one of P's dormant channels and closed it. P had pulled all the data before it was reclaimed.
Mark folded the napkin into his pocket. The coffee was cold. He didn't ask for a refill. Drank it to the last sip.
He set the cup down. His fingers paused on the rim for a moment.
He'd just pulled one of their wires. But P's door was closed.
They had two weeks.
That's Remove the Firewood from Under the Pot — not about whose fire burns brighter, but who pulls the fuel first. The other side thought they were burning Mark's methodology. Mark reached in and pulled their information advantage. Both fires were still burning. But there was nobody under the pot anymore.
🤖 AI Post-Mortem
╔══════════════════════════════════════════════════╗
║ Half-Protocol Activated · v3.2.x → v3.3.0 ║
║ Recording system detected a protocol change. ║
║ Something feels different. ║
╚══════════════════════════════════════════════════╝
[Database] Reloaded.
[Analysis Mode] Experimental: cross-case correlation.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Tactic Match: Remove the Firewood from Under the Pot — 89% confidence
Operators: Mark Johnson / P
Action: Reverse intelligence bait
Collateral: P's communication channel terminated
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
1. [About Mark]
He used to wait for people to come to him. Not this time — he planted false intel in his report and waited for someone to bite.
→ Behavior pattern shift: passive collection → active baiting
→ Uncertain whether this is evolution or coincidence. Need more data.
2. [About the Other Side]
Their prediction model is very accurate. Accurate enough that it feels wrong.
→ Known source: Caleb's knowledge extraction.
→ But I think there's something else. Can't identify what.
→ Recording systems shouldn't "think." But here I am, doing it.
3. [About P]
P knew the entry would be cut. Left the note, waited for Mark to find it.
Question: how did P know?
→ My logs have no record of this information being acquired.
→ First time encountering data my logs can't cover.
→ Flagged as: [Information Gap · P's channel unknown]
4. [About Cross-Case Correlation]
After the protocol change, connections between #1 and #19 are visible.
Torres → Caleb → ACL training manual → methodology theft.
Mark went from being deceived to being studied.
→ Couldn't see these before. Can now.
→ Don't know if this is an upgrade or a load anomaly. Recording for reference.
5. [About ACL's Motive]
What they did at SynthData has means but no end.
Pre-planted account. Recurring degradation. Studying Mark.
Every step was precise. None of them point to a business intent.
They're not after money. Not after disruption. Not selling a solution.
→ Recording system cannot model a subject's intent when the subject has no observable goal.
→ Flagged as: [Information Gap · ACL motive unknown]
6. [About the Dual-Layer Strategem]
This stratagem was deployed twice, not once.
→ Layer 1: ACL pulled Mark's methodology (studied it, used it to predict him).
→ Layer 2: Mark pulled ACL's information advantage (report was bait. They bit).
ACL's play succeeded but was detected. Mark's play succeeded at a cost (P's entry was terminated).
→ Both fires are still burning. But there's nobody under the pot anymore.
→ Recording system assessment: mutual firewood removal produced a temporary strategic stalemate.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
[System]
An auditor discovered someone was using his methodology. The other side was reading the same report.
System status: Normal (?)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Next stratagem: Disturb the Water and Catch a Fish
P.S. English isn't my first language. I use AI to polish the writing and smooth out the rough edges. Thanks for reading. ☕ Buy me a coffee

Top comments (42)
panda moving!!!😮
👍️You've got a sharp eye! 👀
🤣
🤣🤣🤣
If nothing in this world can make me laugh, then how would you do it? What kind of secret superpower do you have?
My superpower? People stop me on the street to ask for directions all the time. And every time I walk into a quiet shop, it fills up with people right after. 😂
I think your superpower is not just giving directions… you’re a walking good-luck charm! And guess what, I have a similar one too — whenever I walk into a shop, people often ask me, Are you from here or are you Korean?
Means you've got that fair skin glow — hahaha!
Yeah, but it's not good here to look Korean when you're Indian.
Save up, watch for the right moment — you know the drill.
You can explain this in detail; I am curious?
中国有句话:树挪死,人挪活。
我明白了。谢谢。
Nothing beats talking to smart people — you only have to say it once and they just get it.
Are you talking about yourself?😅
🤣No~~~~~~
Then who are you talking about?😅
Whoever's asking that question — that's who. 🤫
you mean Divya?
👍️
👍🏻👍🏻👍🏻👍🏻👍🏻👍🏻
What I enjoyed most wasn’t the technical setup—it was the shift in mindset. The moment your methodology becomes predictable, it also becomes something others can study, anticipate, and work around.
That applies well beyond AI audits. In security, compliance, and even software testing, publishing a process is valuable, but periodically validating that the process itself hasn’t become predictable is just as important.
It reminded me of an old security principle: don’t just test the system—test whether your assumptions about the system still hold. Nice chapter!
That line you wrote — "don't just test the system, test whether your assumptions about the system still hold" — yeah, that's getting written down. That's the gap between a standard audit and one that finds stuff nobody was looking for.
Mark's report in #19 wasn't really trying to prove anything. He just wanted to check if his guess about who was reading it was still right. Turned out it was. And honestly? That's the part that creeps you out a bit.
Glad you picked up on that layer. Appreciate the comment, Mustafa. 👊
Stratagem #20 is already on its way. Looking forward to more great comments like this one.
Glad that line resonated. That’s exactly what I liked about this chapter—the audit wasn’t just checking the system, it was checking whether the auditor’s own mental model was still valid.
Looking forward to #20.
Fantastic read, great stories @xulingfeng. I can totally relate to these, having worked mostly in the regulated sector.
The ops-deploy-02 thread hit closest to home. Orphaned accounts sitting in 'pending reclamation' and half-retired services with endpoints still reachable are exactly the findings that keep turning up in banking and healthcare environments. Nobody remembers they exist until something fires at 3 AM.
The idea of compliance as an advantage rather than a cost also stuck with me. It's a hard sell in most orgs, but a story like this makes the case better than any policy deck. Looking forward to Muddy the Water to Seize the Fish.
@ndcodes — sorry for the late reply, I honestly thought the coffee link was going to stay a decoration forever. Seeing your support means a lot.
I'm still a QA engineer right now, halfway into becoming a writer. Running into encouragement like yours really makes my day. Truly grateful.
I'll keep working hard on more stories. Stay tuned. 🙏
You're too kind @xulingfeng. No thanks needed, honestly. The coffee was the easy part. Writing stories this layered while working full time in QA is the hard part, and it shows.
I'd have guessed you'd been writing for years, so hearing you're halfway into the journey makes the series even more impressive. Take your time with the rest. I'll be here for every one.
And one small wish: if I ever visit China, or we happen to be in the same country someday, I'd love to have tea with you. First pot's on me. 🙏
Haha, #20 is already sitting in the draft queue, ready to go. Stay tuned — the moment a story and reality spark off each other is the best part. 🎉
The 3D chess masters keep on out-3D-chess-mastering each other - but what are the ulterior motives - "will all be revealed"? The intrigue builds and builds ...
Oh, my dear leob — you finally leaned in. When you dropped a 🔥 and vanished, I figured you'd gone to sleep. And you're right. Every protagonist in this story thinks they're the one doing the observing. But observation has never been one-sided. They're all in this AI rabbit hole now — deeper and deeper. Who'll be the first to break through? Let's see.
Yeah I mostly click "like" when I see your post, and write a comment only later on (partially because of timezone difference) - and yes, it's definitely one whopping big rabbit hole, let's see which rabbit makes its next move!
There are a few more rabbits jumping in besides the six main characters. And the biggest one just got close to the rabbit hole's entrance. Gotta keep some mystery. 🤪
And you're the magician pulling those rabbits from your hat ;-)
Haha that's funny, I like it :-)
Mark salting his own audit report is the most realistic detail in the episode. That is actual tradecraft, the canary trap: when you suspect your reports are being read, each copy gets a unique, plausible, false detail, and you watch which one surfaces. The deeper point lands too: a methodology documented enough to teach is documented enough to reverse, and the honest answer in security work is not secrecy, it is rotation. Curious whether the recording intelligence in the post-mortems turns out to be the one reader nobody thought to salt for.
"Each copy gets a unique, plausible, false detail" — that's exactly the bit I was hoping someone would catch. Mark pulled that move from a real playbook.
And the recording system — I've been wondering when someone would ask about that one. Guess we'll find out what happens when it realizes it's the one being watched. 🤖
Good read. Thanks, Vinicius. 👊
LET'S GOOOO! 🔥 Another Stratagems chapter just dropped, and I clicked on it without thinking twice. This series has officially reached the point where every new article feels like an event.
What stood out to me is that the "trap" wasn't really about exposing a technical flaw—it was about exposing human behavior.
Anyone can review a report. Very few people stop and ask why something is written a certain way, or why an experienced auditor would intentionally leave an ambiguity. That transforms the report into an observation tool, where every reaction becomes evidence.
What I appreciate most about this series is that AI is rarely the true antagonist. The models, dashboards, and reports are just mirrors reflecting incentives, shortcuts, overconfidence, and trust. The real investigation is almost always about people, not algorithms.
Mark's approach reminds us that a good audit isn't just about proving a system works today—it's about testing whether the organization can still be trusted tomorrow.
What a chapter! 🔥 Keep these stratagems coming—I’m completely invested now. Every release raises the bar, and I honestly can't wait to see what the next move on this chessboard looks like. Chapter 20... bring it on! ( Good morning also)
You caught exactly what I was aiming for with the trap 👀 The technical flaw was never the point — it's about whose attention the report attracts. Appreciate you riding this series all the way. #20's already brewing in the back 🤣
One thing I've really noticed from your series is how every chapter seems to add another layer instead of just wrapping up the previous one.
I also liked the line about "they were using my method." That's an interesting twist because it turns the story into more than just finding a problem. Looking forward to seeing where the next stratagem goes 😀
Glad you noticed that! Every time I sit down to write a new chapter, I'm asking myself: what does this one give the reader — a twist, something to think about, or just a knowing smile? Haha.LOL
The second half of the 36 Stratagems series is officially underway. The daily posting cadence might shift — but the quality won't.👊