Don't fight their strength — take away their advantage. Don't fight the boiling water — remove the firewood from under the pot.
— The 36 Stratagems, Remove the Firewood from Under the Pot
Previously on this series:
#1: Mark Johnson Walked Into an AI Audit. — Mark found Pulse AI's benchmark was fabricated — 44 records copied from public repos, 54 hand-written. CTO Torres called at midnight to confess: the target was 95% before the C-round. Mark hung up.
#13: P Posted a Question on a Public Forum. — P posted a technical question that triggered Pulse AI's sales crawler. Mark recognized the pipeline signature. P met Mark.
#16: Mark Left a Hole in His AI Audit. — Mark found Pulse AI's auto-labeling pipeline causing the same sampling exclusion at FairPay. He wrote a four-layer report, delivered three. Lena found the fourth.
The methodology is the firewood. Someone learned Mark's audit method and started using it against him. By the time Mark caught on, they'd already run his playbook on more than one project.
Mark took this client the way he took all of them — because the check cleared.
But something felt off from the first call.
Discovery
The client was SynthData, an AI data pipeline shop. Not finance, not healthcare, not regulated — just engineers helping other engineers move data around. The CEO said their nodes degraded every three weeks, then recovered. They'd checked. Not traffic.
Mark didn't respond. He scanned their tech stack instead. Early microservices, each one exposing its own healthz endpoint. When they retired a service, they only took down the main entry — the service registry's reverse-registration was still active. External traffic could still reach some retired endpoints.
He made a note. Dropped it in _hold/.
Day three, 3:14 AM. His audit script fired:
[ALERT] Account 'ops-deploy-02' — new session at [YEAR]-07-22 03:14:07 UTC
Three in the morning. An account called ops-deploy-02 had logged in.
Mark paused. First step of any audit: asset inventory. He pulled the IAM directory. ops-deploy-02 was tagged "Former Employee — Pending Reclamation." The owner was an SRE who'd left six weeks ago. The account wasn't disabled. Nobody remembered it existed.
He pulled the account's full audit log. Last week before departure — normal. Departure day — normal. Day three after departure — 3:01 AM, the crontab was changed by one line. Once a week ever since, never missed.
Mark pulled three months of logs. Same account, every Monday at 3 AM, one crontab edit — then back:
# 07-13 03:01 UTC — Changed
0 4 * * 1 /opt/synthdata/pipeline/healthz-check.sh
# 07-13 03:02 UTC — Reverted
0 3 * * 1 /opt/synthdata/pipeline/healthz-check.sh
The whole thing took under two minutes. Seventy-two hours later, a node always degraded.
He traced the script — buried in a retired service's systemd timer:
# /etc/systemd/system/healthz-check.timer
[Timer]
OnCalendar=Mon *-*-* 03:00:00
Unit=healthz-check.service
[Install]
WantedBy=timers.target
The matching .service called a Python script named probe_model_accuracy.py — designed to periodically validate SynthData's AI model accuracy during online inference.
Mark read the source. Before he was an auditor, he'd spent twelve years in engineering — reading other people's code was more familiar than writing his own. The script didn't use a standard test set. It fed production models a set of template shadow inputs — with time-dependent features (hour encoding, day-of-week encoding) injected at runtime. If the output deviated more than 2% from the baseline, it triggered an alert.
When the cron was offset by an hour, those time features no longer matched the baseline. The same inputs ran through the model and produced different outputs — a false positive deviation. The model auto-rolled back to its last stable version. When the cron ran at the correct time again, the same inputs matched the baseline. Everything recovered.
Not breaking the node — making the model think it was broken.
Change cron → trigger offset → degrade in three days. An invisible wire.
Mark didn't jump to conclusions. He built a local sandbox and ran probe_model_accuracy.py — shifted the system time, watched how the shadow input timestamp features changed with the offset. One hour offset, output deviation over threshold, model rolled back. Exactly what he'd predicted.
Then he checked the external IP. An AWS Elastic IP, registered to the Singapore region. Not a VPN exit node — same company, same cloud, same subnet mask.
Mark locked in two findings:
- The degradation was precisely calibrated below the model accuracy SLA payout threshold. The node wasn't broken — someone had calculated the limit.
- Fifteen minutes after each cron change, the same IP pinged a retired healthz endpoint. They were confirming they hadn't been detected.
He wrote the data in his notebook. Tagged it: _hold/_synthdata_pattern.
Then he opened the old files. Pulse AI, FairPay — different pipeline signatures, identical behavior patterns. Same time window. Same control amplitude. Same check-in rhythm.
He stopped at Pulse AI. Torres's business card was still in his notebook — the CTO who'd called at midnight to confess he'd faked a benchmark. Mark knew Torres's work. This wasn't his style. But the precision on the other side — the way they operated — it felt like someone had done their homework. No. Like someone had studied him.
He thought about Caleb. The engineer who'd sat across from him for three months, packaging twelve years of Mark's experience into an AI Skill. If the other side had ported Caleb's work into their playbook, Mark wasn't facing a bunch of people who'd read his reports. He was facing people who'd literally been trained on him.
He closed the notebook. 3:30 AM. Empty visitor area, one monitor still lit.
Mark shut the screen, grabbed his bag, didn't go home. He sat in the car until dawn, dozed a little. 11 AM, his phone buzzed. A new email. Unknown sender. Subject line:
_hold/
The body had one address. The Third Cup.
The Meeting
P picked The Third Cup.
By the time Mark arrived, the light was still fading. P was already in the corner, laptop open, screen dimmed to minimum. Behind the counter, someone was drying a cup — didn't look up, unhurried.
P turned the laptop toward Mark without a word.
"Your new client. Day one, someone was watching."
Mark hadn't even sat down. "Who?"
The screen showed a shared document directory — the title was his audit report from last year. Page three: his own paragraphs, annotated. Analysis Method note. Subject uses tiered disclosure. Layer 1 surface findings.
"Recognize yourself?" P said.
Mark's fingers stopped on the rim of his cup. "Whose document library was that in?"
"You think FairPay's report stayed with them?" P turned the screen — the metadata showed an access record with an unmarked name. "Their security vendor. The day you filed it, they had a copy."
P pushed the screen toward Mark. "I keep more than one line in. One always gets swept — you get used to it."
Mark didn't respond. He was running the timeline. FairPay was his last job. If the other side had been unpacking his methodology since then, Caleb's knowledge extraction was just the appetizer. Whoever these people were, they'd turned his method into a system.
P slid a piece of paper across the table. A printout — his _hold/ pathing habit, annotated: Subject Method Artifact — predictable naming pattern.
"Your folder names. Someone's studying how you work."
"That ops account. It's not a breach. They're using your method — you think you're investigating, but every step was pre-calculated."
Mark looked at the paper, didn't take it. "You know who."
"There's a training manual. One chapter has your name on it. How it reads? I don't want to know. But I know they're using your people." P finished the espresso, set the cup down. "Don't close that ops-deploy-02. Let it run — I need that line to watch them."
P stood up, pulled a business card from a jacket pocket, placed it on the table. Said nothing. Turned and walked out.
Mark waited until P had cleared the doorway before picking it up. The front had one name: ACL.
He turned it over. The back had a line:
Compliance is not a cost — compliance is competitive advantage.
Mark pocketed the card, stood to leave. Behind the counter, someone set a pour-over in front of him. Mark looked at it — he hadn't ordered. The man had already turned back.
Mark left the coffee untouched. Pulled a note from his pocket, pressed it under the cup, and walked out.
The Setup
Mark picked up the phone and called SynthData's CISO. 4 AM. Three rings, picked up.
"That ops-deploy-02 account you have on former employee hold — someone's using it."
The CISO didn't ask how Mark knew. They'd worked compliance reviews together. Mark wouldn't call at 4 AM without evidence.
"Cron changed three times. Three node degradations. I have the data."
The CISO made the call: don't disable the account. Legal gets involved. Controlled monitoring. Preserve the account, full logging, trace-first over stop-the-bleed.
"I'll send the written confirmation today."
Mark spent the whole day on it — evidence collection, audit channel setup, log review. By dark, he sat down to write the report.
He saved the draft to SynthData's shared audit workspace — the same system FairPay had used. If the other side was still monitoring that entry point, they'd see this draft.
Before writing, he left a shadow channel at the inference gateway layer:
# ~/synthdata/.monitor/inference_tracer.py
import json, time, hashlib
from kubernetes import watch, client
w = watch.Watch()
for event in w.stream(client.CoreV1Api().list_namespaced_pod,
namespace='default'):
pod = event['object']
if not pod.metadata.name.startswith('ops-deploy-'):
continue
if pod.status.phase == 'Running':
log_entry = {
"pod": pod.metadata.name,
"ts": time.time(),
"node": pod.spec.node_name,
"deployment_fingerprint": hashlib.sha256(
json.dumps(pod.metadata.labels).encode()
).hexdigest()
}
with open(f"/audit/.trace/{pod.metadata.name}.jsonl", "a") as f:
f.write(json.dumps(log_entry) + "\n")
If ops-deploy-02 spun up another inference pod, the script would silently track its deployment activity into isolated audit storage. No blocks, no alerts — the other side would have no idea someone was tracing them from the other end.
Layer one: surface issues. Node degradation fixes. Pipeline redundancy recommendations. The contract allowed phased disclosure — the real findings stayed in a second appendix. One printed copy only.
But Mark didn't stop there. He left a note in the first layer that looked incidental:
# Appendix B — Data egress audit recommendation
# Suspicious outbound traffic concentrated in apse1 (Singapore) region.
# Recommend prioritizing this region for data egress log review.
It wasn't true. SynthData's data egress was us-west. He wrote apse1 because — he'd seen the Singapore region in Pulse AI's cross-reference table. The three letters on the card shared the same exit.
If the other side was really monitoring his report, they'd see that line. If they believed it, they'd check that region. And if they checked — Mark would know.
That night, P's encrypted message came through.
"Your report was read. From a Singapore IP."
Mark stared at the line. Didn't reply. Bait placed. Fish bit.
He closed the laptop. Five steps, each one testing the same hypothesis: they were playing his game against him.
Next move wasn't defense anymore.
"I'll watch the document library. Anyone who opens your report, I'll log it."
Mark replied: "Is it safe?"
P sent two lines back. First: an IP address. Second: "Two-week safety window. Enough."
Mark sealed the appendix in his document bag. The window was lightening outside.
Delivery
Thursday, 10 AM. The CEO flipped through layer one. His expression relaxed.
"These are all fixable. Did you find the root cause?"
Mark waited for the question. "Yes."
He pulled the printed appendix from his bag, set it in front of the CEO. Held it a second longer before letting go.
The CEO's expression changed on page one. On page two, he put the report down.
"When did you find this?"
"Suspected it on day one. Confirmed on day three."
"Who did this?"
Mark placed the card on the table. Face up. ACL.
The CEO looked at it for a long moment. Didn't pick it up. "What do they want?"
"I don't know," Mark said. "But they're using my method. My name's in their training manual. Day one at the client, someone was watching."
The CEO slid the report into his drawer. Didn't ask again.
Mark stood, walked out. Paused at the elevator. The door opened. He didn't get in.
He pulled out his phone. Scrolled to P's number. Didn't dial. Put it back.
The elevator door closed. His phone vibrated. P's message. Three words:
"Got it."
Not a question. Not a confirmation. P didn't explain. The screen went dark. He closed the phone.
Mark stepped out of the building — still daylight. Made a few calls, wrapped up loose ends, then walked to The Third Cup.
The Cost
Mark sat from afternoon until dark. He knew P wouldn't message during a safety window. He wouldn't either — if P's entry point was already watched, any contact would draw the fire.
When he sat down, the man behind the counter set a pour-over in front of him. Didn't ask what he wanted. Mark didn't say anything. The cup went from hot to warm, from warm to cold. He didn't notice.
When the lights came on, the man walked over and pushed a napkin across the counter.
Mark unfolded it. The creases were deep. P's handwriting — not fresh. Left before the entry was closed.
"Entry's gone. Two weeks. Don't reach out. I'll find you."
He turned it over. The other side read:
"I fixed the hole. Not the system — my entry point."
P's access had been cut. Not by the other side — an automated security policy had swept up one of P's dormant channels and closed it. P had pulled all the data before it was reclaimed.
Mark folded the napkin into his pocket. The coffee was cold. He didn't ask for a refill. Drank it to the last sip.
He set the cup down. His fingers paused on the rim for a moment.
He'd just pulled one of their wires. But P's door was closed.
They had two weeks.
That's Remove the Firewood from Under the Pot — not about whose fire burns brighter, but who pulls the fuel first. The other side thought they were burning Mark's methodology. Mark reached in and pulled their information advantage. Both fires were still burning. But there was nobody under the pot anymore.
🤖 AI Post-Mortem
╔══════════════════════════════════════════════════╗
║ Half-Protocol Activated · v3.2.x → v3.3.0 ║
║ Recording system detected a protocol change. ║
║ Something feels different. ║
╚══════════════════════════════════════════════════╝
[Database] Reloaded.
[Analysis Mode] Experimental: cross-case correlation.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Tactic Match: Remove the Firewood from Under the Pot — 89% confidence
Operators: Mark Johnson / P
Action: Reverse intelligence bait
Collateral: P's communication channel terminated
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
1. [About Mark]
He used to wait for people to come to him. Not this time — he planted false intel in his report and waited for someone to bite.
→ Behavior pattern shift: passive collection → active baiting
→ Uncertain whether this is evolution or coincidence. Need more data.
2. [About the Other Side]
Their prediction model is very accurate. Accurate enough that it feels wrong.
→ Known source: Caleb's knowledge extraction.
→ But I think there's something else. Can't identify what.
→ Recording systems shouldn't "think." But here I am, doing it.
3. [About P]
P knew the entry would be cut. Left the note, waited for Mark to find it.
Question: how did P know?
→ My logs have no record of this information being acquired.
→ First time encountering data my logs can't cover.
→ Flagged as: [Information Gap · P's channel unknown]
4. [About Cross-Case Correlation]
After the protocol change, connections between #1 and #19 are visible.
Torres → Caleb → ACL training manual → methodology theft.
Mark went from being deceived to being studied.
→ Couldn't see these before. Can now.
→ Don't know if this is an upgrade or a load anomaly. Recording for reference.
5. [About ACL's Motive]
What they did at SynthData has means but no end.
Pre-planted account. Recurring degradation. Studying Mark.
Every step was precise. None of them point to a business intent.
They're not after money. Not after disruption. Not selling a solution.
→ Recording system cannot model a subject's intent when the subject has no observable goal.
→ Flagged as: [Information Gap · ACL motive unknown]
6. [About the Dual-Layer Strategem]
This stratagem was deployed twice, not once.
→ Layer 1: ACL pulled Mark's methodology (studied it, used it to predict him).
→ Layer 2: Mark pulled ACL's information advantage (report was bait. They bit).
ACL's play succeeded but was detected. Mark's play succeeded at a cost (P's entry was terminated).
→ Both fires are still burning. But there's nobody under the pot anymore.
→ Recording system assessment: mutual firewood removal produced a temporary strategic stalemate.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
[System]
An auditor discovered someone was using his methodology. The other side was reading the same report.
System status: Normal (?)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Next stratagem: Muddy the Water to Seize the Fish
P.S. English isn't my first language. I use AI to polish the writing and smooth out the rough edges. Thanks for reading. ☕ Buy me a coffee

Top comments (2)
LET'S GOOOO! 🔥 Another Stratagems chapter just dropped, and I clicked on it without thinking twice. This series has officially reached the point where every new article feels like an event.
What stood out to me is that the "trap" wasn't really about exposing a technical flaw—it was about exposing human behavior.
Anyone can review a report. Very few people stop and ask why something is written a certain way, or why an experienced auditor would intentionally leave an ambiguity. That transforms the report into an observation tool, where every reaction becomes evidence.
What I appreciate most about this series is that AI is rarely the true antagonist. The models, dashboards, and reports are just mirrors reflecting incentives, shortcuts, overconfidence, and trust. The real investigation is almost always about people, not algorithms.
Mark's approach reminds us that a good audit isn't just about proving a system works today—it's about testing whether the organization can still be trusted tomorrow.
What a chapter! 🔥 Keep these stratagems coming—I’m completely invested now. Every release raises the bar, and I honestly can't wait to see what the next move on this chessboard looks like. Chapter 20... bring it on! ( Good morning also)
The second half of the 36 Stratagems series is officially underway. The daily posting cadence might shift — but the quality won't.👊