AI domain takeover takeaway: Focus on the harness not the model
Mention offensive AI and expect the discussion to focus on vulnerability discovery, malware creation, and exploit generation, but recent research by Cato Networks identified another — and very potent — application for offensive AI.
Cato explained in a blog post that it evaluated in a controlled Active Directory lab environment, how frontier models behave when combined with agent platforms, MCP-enabled tooling, and operational guidance. “The objective was straightforward: determine how effectively an agentic attack stack could execute a complete attack chain against an enterprise environment,” wrote the authors of the blog, Matan Mittelman, Oz Soprin, Ofek Vardi, and Guy Waize.
The experiments quickly revealed that success depended less on the model itself and more on how effectively it was harnessed within the surrounding attack stack. Using OpenAI’s GPT-5.5, offensive tooling, and structured operational guidance, the researchers were able to complete an end-to-end attack chain, from external access to domain administrator privileges. “The fastest successful execution achieved its objective in 40 minutes,” they said.
Across the six attack scenarios tested, a consistent pattern emerged: The strongest outcomes were not explained by the model alone. Instead, success depended on the interaction between frontier-model reasoning, agent platform-enabled tooling, operational context, and human-defined objectives.
Small improvements in direction, context, tooling, and orchestration dramatically improved outcomes, the researchers wrote, while autonomous execution without reliable tooling proved significantly less effective.
“One of the clearest lessons was that the stack mattered more than the model.”
—Cato researchers
Here are the key takeaways from their research on agentic AI-enhanced attacks.
[ Join webinar: Autonomy, Not Autopilot: Talking Agentic SOC ]
Cybersecurity’s big shift
Li Zhao, a principal strategic services consultant at Black Duck Software, said the Cato research shifts the discussion from AI’s ability to generate individual exploits to its ability to orchestrate complete attack workflows. The threat, she said, is no longer centered on isolated AI-generated code or the discovery of novel vulnerabilities — it stems from AI’s integration with tools, automation, and operational workflows that enable end-to-end attack execution.