Research
Ph.D. candidate in Cybersecurity and AI at The University of Texas at San Antonio.
Areas of focus
- Evidence-grounded attack attribution
- Mapping system telemetry to MITRE ATT&CK techniques, and separating what evidence was available, what was retrieved, and what the system committed to.
- Temporal knowledge graphs for threat intelligence
- Linking events, entities, and techniques over time so that attributions can be traced back to their evidence.
- Commitment across the delegation chain
- How one system’s decision to commit or withhold shapes the judgment of the next agent downstream.
- Bounded autonomy for AI agents
- As autonomous as possible, as bounded as necessary.
- LLM-enabled phishing
- How large language models change phishing inside large organizations, and how to defend against it.
Publications
Lateral phishing with large language models: A large organization comparative study
Bethany, M., Galiopoulos, A., Bethany, E., Karkevandi, M. B., Beebe, N., Vishwamitra, N., & Najafirad, P.