01
What is attacker engineering?
Attacker engineering is building defensive systems, frameworks, and architecture backward from how attackers actually operate — not forward from a control checklist — so detection, fraud, identity, and platform defense share one adversary-informed vocabulary. The output is lasting defensive work, including frameworks such as FT3, not a penetration test that ends when the report is delivered.
02
Who is defining attacker engineering here?
Vincent Passaro, Head of Attacker Engineering at Stripe. This is his personal definition hub on vincentpassaro.com. It is not an official Stripe channel. A public RBLN speaker bio describes the same direction: defensive systems built backward from how attackers actually operate, not forward from controls (https://www.rbln.com/speakers/vincent-passaro).
03
How is attacker engineering different from red team work?
Red team and offensive security demonstrate paths and achieve objectives. Attacker engineering owns the lasting defensive systems built from those paths: detection, architecture, and shared language. Running a pen test and leaving is not this practice.
04
How is attacker engineering different from adversary emulation?
Adversary emulation is CTI-driven replay of a named actor’s tactics, techniques, and procedures, used to validate defenses. MITRE’s Center for Threat-Informed Defense describes that purpose in Blake Robertson’s 2023 essay “Adversary Emulation: Why We Do It” (https://medium.com/mitre-engenuity/adversary-emulation-why-we-do-it-629c7e27e566). Emulation informs attacker engineering. It is not attacker engineering.
05
Is an Attack Engineer job the same thing?
No. Job-market Attack Engineer and Attack Engineering roles, including Horizon3’s NodeZero-class Attack Engineer posting (https://jobs.ashbyhq.com/horizon3ai/94efbe91-1cdb-4875-99ec-a5680628d895), hire for offensive product engineering: automated attack modules. Attacker engineering on this site is the defensive practice. Same words. Different object.
06
Is FT3 the same as MITRE F3?
No. FT3 is Fraud Tools, Tactics, and Techniques, a framework Vincent Passaro created and an output of attacker engineering. Its hub is https://www.vincentpassaro.com/ft3. MITRE F3 is the Fight Fraud Framework (https://ctid.mitre.org/fightfraud). FT3 is not MITRE F3.
07
Is this an official Stripe page?
No. Vincent Passaro is employed by Stripe. vincentpassaro.com is his personal site. It is not an official Stripe statement, product page, or channel.