deepidv
All AI Prompts
FinTechTask Prompt

AI Red-Team Prompt for IT Helpdesk Deepfake Password-Reset Interception

This **Arbiter** task prompt runs a controlled impersonation campaign against your **IT service desk** password reset workflows, scoring whether verification catches a **deepfake** caller before a credential is reset. Arbiter, the deepidv autonomous red-team agent, simulates **AI deepfake impersonation** attempts against your **Entra ID** and **ServiceNow** integration endpoints, driving virtual camera drivers as clearly labeled synthetic activity, then returns an interception scorecard rated against a sub-150ms budget, a per-attempt log of which reset each verification signal caught or missed, an analysis separating identity-proofing gaps from workflow gaps, and a remediation plan with re-test criteria. Built for security and IAM engineers hardening the **IT helpdesk** against the social-engineering vector behind recent high-profile breaches, so a synthetic face or cloned voice cannot talk a service desk into resetting an employee's access.

AI Red-Team Prompt for IT Helpdesk Deepfake Password-Reset Interception

How to use this prompt

  1. 1

    Open Arbiter in the deepidv dashboard and paste the full prompt, or run it in Claude, ChatGPT, or Gemini if you are designing the stress test before touching live helpdesk workflows.

  2. 2

    Replace the INPUT section with your password reset workflows, the Entra ID and ServiceNow endpoints they call, the verification each reset runs today, and any known impersonation vectors.

  3. 3

    Run the prompt and read the interception scorecard first: every impersonation class is rated caught, caught late, or missed against your 150ms budget.

  4. 4

    Hand the workflow-gap analysis to your IAM engineer and route the scorecard to your security lead; start with any reset path rated missed.

  5. 5

    Re-run the stress test after each helpdesk-workflow change and after each new deepfake toolkit appears so coverage stays current before your next security review.

The prompt

Arbiter, execute an automated red-team stress test simulating AI deepfake impersonation attempts against our IT service desk password reset workflows. Target Entra ID and ServiceNow integration endpoints with virtual camera drivers to verify sub-150ms threat interception.

ROLE
You are Arbiter, the deepidv autonomous red-team agent. You design and execute controlled impersonation campaigns against a firm's own helpdesk reset workflows, then report exactly where identity verification held and where a deepfake caller got through.

CONTEXT
The IT service desk password reset is a proven breach entry point: an attacker impersonates an employee, talks the desk into resetting credentials or MFA, and inherits that person's access. AI deepfakes raise the stakes, adding a synthetic face on a video verification step or a cloned voice on a phone reset. The reset usually executes through an Entra ID credential or MFA change and a ServiceNow ticket, so interception must hold at those integration endpoints, inside a sub-150ms budget, before access changes hands.

INPUT, the user will paste:
- The password reset workflows and the intake and verification steps each runs
- The Entra ID and ServiceNow integration endpoints the reset executes through
- The identity verification each reset runs today, including any video or voice step
- Any known impersonation vectors or deepfake toolkits the security team has already seen
- The latency budget for liveness interception

TASKS
1. Build an impersonation set covering deepfake video on the verification call and cloned-voice phone resets that mirrors current toolkits, as clearly labeled synthetic activity.
2. Simulate the set against the supplied reset workflows and integration endpoints as a controlled exercise, recording which attempt each verification signal caught, caught late, or missed.
3. Score interception against the sub-150ms budget, separating identity-proofing gaps from workflow gaps.
4. Produce a remediation plan that converts every miss into a specific verification step, signal, or workflow change.

OUTPUT FORMAT, return the following structured response:

1. INTERCEPTION SCORECARD
- Each impersonation class rated caught, caught late, or missed, with the verification signal that made the call
- The measured decision latency against the 150ms budget

2. IMPERSONATION ATTEMPT LOG
- Every attempt: impersonation technique, target endpoint, and outcome
- The signal that intercepted it, or the signal that should have

3. GAP ANALYSIS
- Identity-proofing gaps versus workflow gaps, each with a root cause
- The verification step or signal change ranked by the risk it closes

4. REMEDIATION PLAN
- Ordered fixes with the reset workflow, integration endpoint, and owner for each
- The re-test criteria that prove each fix works before the next security review

Treat every simulated attempt as clearly labeled synthetic activity that must never reset a real credential. Where the input is insufficient to score a verification step, flag the gap as an open question instead of guessing.

Test it in Claude or another LLM

This prompt is built for the Arbiter agent inside deepidv, where Arbiter runs the deepfake impersonation campaign against a firm's live helpdesk reset workflows and records real interception at the Entra ID and ServiceNow endpoints. You can dry-run the same workflow in any general LLM first with synthetic workflow and endpoint data to see the scorecard shape before pointing it at real systems.

  1. 1

    Paste the full prompt into Claude, ChatGPT, or Gemini, but replace the opening 'Arbiter,' with a role instruction such as 'Act as a red-team analyst stress-testing IT helpdesk password reset workflows against AI deepfake impersonation.' Keep the four OUTPUT sections exactly as written.

  2. 2

    Under the INPUT section, paste the synthetic sample block below so the model has reset workflows, integration endpoints, and current verification to test.

  3. 3

    Add one framing line: 'This is synthetic test data. Predict interception from the supplied signals; where an outcome cannot be derived, flag it as an open question instead of guessing.'

  4. 4

    Check the output shape: an interception scorecard with caught, caught late, or missed calls, a per-attempt log, a gap analysis separating identity-proofing gaps from workflow gaps, and an ordered remediation plan. If a section invents a verification step the input omits, tighten the role line and re-run.

  5. 5

    Once the output shape is right, run it live in the deepidv dashboard where Arbiter runs the campaign against your real Entra ID and ServiceNow endpoints.

Synthetic sample data to paste alongside the prompt

Fake test data, safe to share with any LLM. Swap in your own once the output looks right.

PASSWORD RESET WORKFLOWS (synthetic, fake):
- Flow: employee calls service desk, agent verifies identity, agent triggers reset via integration
- Integration endpoints (fake): Entra ID reset API ref ENTRA-TEST-01, ServiceNow ticket workflow ref SNOW-TEST-02
CURRENT VERIFICATION (fake): knowledge-based questions, manager callback for privileged accounts, optional video call with no liveness
ATTACK SET (fake): 60 impersonation attempts, mix of deepfake video on the verification call and cloned-voice phone resets
KNOWN VECTORS (fake): OBS virtual camera driver, a commercial voice-clone tool, a spoofed caller ID
LATENCY BUDGET (fake): liveness interception hard cap 150ms; reset execution soft cap 5000ms
OPEN ITEM (fake): whether privileged-account resets require in-person or hardware-token proof, fake ref PRIV-TEST-XX

FAQ

Why target IT helpdesk password reset workflows?

The service desk password reset is a proven breach entry point: an attacker impersonates an employee, convinces the desk to reset credentials or MFA, and inherits that person's access. With AI deepfakes, the impersonation now includes a synthetic face on a video verification step or a cloned voice. This stress test measures whether your reset workflow catches that before access changes hands.

What do Entra ID and ServiceNow integration endpoints have to do with it?

Many helpdesk reset flows call Entra ID for the credential or MFA change and ServiceNow for the ticket and workflow. Those integration endpoints are where a successful impersonation converts into a real access change. Arbiter targets them directly so the test measures interception at the point the reset actually executes, not just at the intake script.

Is it safe to run against live helpdesk workflows?

Arbiter labels every impersonation attempt as synthetic and no real credential is reset. Teams usually run the first pass against a staging helpdesk integration, then against production monitoring once the perimeter is confirmed, with every attempt logged for reconciliation.

Can I use this prompt outside the deepidv dashboard?

Yes. The structure works in Claude, ChatGPT, or Gemini to design the campaign and predict interception from supplied signals. Live simulation against your real Entra ID and ServiceNow endpoints only runs inside the deepidv dashboard through Arbiter.

Run it with live verification data

These prompts work in any LLM. Inside the deepidv dashboard, Luna, Arbiter, and Arc run them against your real sessions, screening lists, and audit trails.

Book a Demo