{"id":26180,"date":"2026-09-21T15:13:39","date_gmt":"2026-09-21T23:13:39","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/ai-domain-takeover-takeaway-focus-on-the-harness-not-the-model\/"},"modified":"2026-09-21T15:13:39","modified_gmt":"2026-09-21T23:13:39","slug":"ai-domain-takeover-takeaway-focus-on-the-harness-not-the-model","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/21\/ai-domain-takeover-takeaway-focus-on-the-harness-not-the-model\/","title":{"rendered":"AI domain takeover takeaway: Focus on the harness not the model"},"content":{"rendered":"<div class=\"rich-text_richText__UyrDZ\" data-anchor-headings=\"true\" data-component=\"rich-text\" data-reader-view=\"false\">\n<div class=\"payload-richtext\">\n<p>Mention offensive AI and expect the discussion to focus on vulnerability discovery, malware creation, and exploit generation, but <a href=\"https:\/\/go.catonetworks.com\/rs\/245-RJK-441\/images\/The_Agentic_Attacker_the_long_blog.pdf\"><span style=\"text-decoration:underline\">recent research<\/span><\/a> by Cato Networks identified another \u2014 and very potent \u2014 application for offensive AI.<\/p>\n<p>Cato explained in a <a href=\"https:\/\/www.catonetworks.com\/blog\/the-agentic-attacker-one-objective-one-prompt-forty-minutes-domain-admin-game-over\/\"><span style=\"text-decoration:underline\">blog post<\/span><\/a> that it evaluated in a controlled Active Directory lab environment, how frontier models behave when combined with agent platforms, MCP-enabled tooling, and operational guidance. \u201cThe objective was straightforward: determine how effectively an agentic attack stack could execute a complete attack chain against an enterprise environment,\u201d wrote the authors of the blog, Matan Mittelman, Oz Soprin, Ofek Vardi, and Guy Waize.\u00a0<\/p>\n<p>The experiments quickly revealed that success depended less on the model itself and more on how effectively it was harnessed within the surrounding attack stack. Using OpenAI\u2019s GPT-5.5, offensive tooling, and structured operational guidance, the researchers were able to complete an end-to-end attack chain, from external access to domain administrator privileges. \u201cThe fastest successful execution achieved its objective in 40 minutes,\u201d they said.<\/p>\n<p>Across the six attack scenarios tested, a consistent pattern emerged: The strongest outcomes were not explained by the model alone. Instead, success depended on the interaction between frontier-model reasoning, agent platform-enabled tooling, operational context, and human-defined objectives.\u00a0<\/p>\n<p>Small improvements in direction, context, tooling, and orchestration dramatically improved outcomes, the researchers wrote, while autonomous execution without reliable tooling proved significantly less effective.\u00a0<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cOne of the clearest lessons was that the stack mattered more than the model.\u201d<\/em><br \/>\u2014Cato researchers<\/p>\n<p>Here are the key takeaways from their research on agentic AI-enhanced attacks.<\/p>\n<p><strong>[ Join webinar:\u00a0<\/strong><a href=\"https:\/\/www.reversinglabs.com\/events\/autonomy-not-autopilot-agentic-soc\"><strong>Autonomy, Not Autopilot: Talking Agentic SOC<\/strong><\/a><strong> ]<\/strong><\/p>\n<h2 id=\"cybersecuritys-big-shift\">Cybersecurity&#8217;s big shift<\/h2>\n<p>Li Zhao, a principal strategic services consultant at Black Duck Software, said the Cato research shifts the discussion from AI\u2019s ability to generate individual exploits to its ability to orchestrate complete attack workflows. The threat, she said, is no longer centered on isolated AI-generated code or the discovery of novel vulnerabilities \u2014 it stems from AI\u2019s integration with tools, automation, and operational workflows that enable end-to-end attack execution.<\/p>\n<p>For years, she said, the debate has focused on whether AI could independently develop new exploits, but this report reframes that discussion. &#8220;\u201dThe key advancement is not the model itself, but the attack stack it powers,\u201d she said. The findings, she added, show that the real threat lies in the coordinated orchestration of the attack lifecycle, not in the model alone.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cA practical takeaway is that defenders need to assume attackers can use AI to scale and compress familiar attack paths.\u201d<\/em><br \/><em>\u2014<\/em><a href=\"https:\/\/www.linkedin.com\/in\/lizhaobc\"><span style=\"text-decoration:underline\">Li Zhao<\/span><\/a><\/p>\n<p>Damon Small, a board member of Xcape, said future threats won\u2019t rely on novel techniques but on agentic systems\u2019 ability to execute known attack patterns at scale \u2014 meaning the stack, not the model, will keep driving outcomes.\u00a0<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cThis research highlights a shift in cybersecurity.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/damon-small-7400501\"><span style=\"text-decoration:underline\">Damon Small<\/span><\/a><\/p>\n<p>He added that the progression from failed attacks to successful compromises is rooted in better guidance, context, and tooling rather than any improvement in the model itself.<\/p>\n<p>Ryan McCurdy, vice president of marketing at Liquibase, said the biggest takeaway from the Cato research isn\u2019t that AI discovered a new way to compromise an enterprise.\u00a0<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201c[AI] dramatically compressed the time required to execute known attack techniques. That\u2019s a fundamental shift for defenders.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/ryanmccurdy\"><span style=\"text-decoration:underline\">Ryan McCurdy<\/span><\/a><\/p>\n<p>As AI accelerates both software delivery and cyberattacks, he continued, organizations have less time to determine whether a given change was authorized before it can affect business systems. \u201cThe advantage increasingly belongs to organizations that can govern change at machine speed, not just detect attacks after they\u2019ve occurred,\u201d he said.<\/p>\n<h2 id=\"the-domain-compromise-gap-is-closing\">The domain compromise gap is closing<\/h2>\n<p>Cato\u2019s demonstration that AI could be used to mount an end-to-end attack was less surprising to some experts than where that capability came from \u2014 not the model itself,\u00a0 but the reasoning layer, the agent platform, the MCP tooling, and a great deal of operational guidance working together. What that means for the rest of us is a timing problem, said Randolph Barr, CISO of Cequence Security..<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cAlmost everything we\u2019ve built \u2014 our response plans, our on-call rotations, the tabletops we run \u2014 quietly assumes an attacker needs days to get to domain admin. If that\u2019s turning into an hour, then our detection and response targets are calibrated to the wrong clock.\u201d<\/em><br \/><em>\u2014<\/em><a href=\"https:\/\/www.linkedin.com\/in\/randolphbarr\"><span style=\"text-decoration:underline\">Randolph Barr<\/span><\/a><\/p>\n<p>Attackers will move faster and automate many tasks that once required specialist skills, said <a href=\"https:\/\/www.linkedin.com\/in\/boris-cipot-58a0a620?originalSubdomain=de\"><span style=\"text-decoration:underline\">Boris Cipot<\/span><\/a>, a security engineer at Black Duck. In his view, the results aren\u2019t surprising, since AI is already effective at identifying potential weaknesses, testing them, and processing large volumes of information far faster than a human analyst can.<\/p>\n<p>Cato\u2019s research quantifies something security teams already suspected: The gap between initial access and full domain compromise is closing at machine speed, said Tim Freestone, chief strategy and marketing officer at Kiteworks.<\/p>\n<p>IBM\u2019s 2026 \u201cCost of a Data Breach Report\u201d found mean time to identify and contain a breach still sits at 247 days, six days worse than 2025, Freestone said. Kiteworks\u2019 \u201c2026 Annual Survey Report\u201d found that 80% of organizations already suffered a security or AI-related incident in the past year. Put those two figures side by side, he said, and the problem is obvious:\u00a0<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cThe defender\u2019s clock and the attacker\u2019s clock are running at wildly different speeds, and governance built for human-paced incident response can\u2019t close that gap on its own.\u201d<\/em><br \/><em>\u2014<\/em><a href=\"https:\/\/www.linkedin.com\/in\/freestone\"><span style=\"text-decoration:underline\">Tim Freestone<\/span><\/a><\/p>\n<p>Although the Cato researchers recorded only two fully successful attacks out of 10 attempts, Jacob Krell, senior director for secure AI solutions and cybersecurity at Suzu Labs, said success rates could be easily improved: A human operator stepping in at a handful of critical decision points across that 32-step chain would push the rate much higher.\u00a0<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cWhen I run LLM-driven offensive workflows, the model rarely fails on the individual steps. It fails on choosing which step to take next. That\u2019s exactly the kind of error a practitioner fixes in seconds.\u201d<\/em><br \/><em>\u2014<\/em><a href=\"https:\/\/www.linkedin.com\/in\/jacob-krell\"><span style=\"text-decoration:underline\">Jacob Krell<\/span><\/a><\/p>\n<h2 id=\"the-wisdom-of-ai-harness-investment\">The wisdom of AI harness investment<\/h2>\n<p>Jim Sherlock, vice president for AI and cybersecurity research and development at ProCircula, said Cato\u2019s gains across scenarios came from harness work rather than better models. \u201cThat finding is worth more than the 40-minute headline everyone is quoting,\u201d he said.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cWhat they built was an agent platform, MCP-wrapped versions of tools every penetration tester already has on a laptop, and a decision policy for what to do next. The model was the interchangeable part.\u201d<\/em><br \/><em>\u2014<\/em><a href=\"https:\/\/www.linkedin.com\/in\/jim-sherlock-727857\"><span style=\"text-decoration:underline\">Jim Sherlock<\/span><\/a><\/p>\n<p>That should change how defenders think about their own roadmap, because it\u2019s the same engineering problem on both sides, he said.<\/p>\n<p>Sherlock added that there\u2019s a strategic reason to invest in the harness rather than the model: Nobody knows what frontier-model access will look like in two years. Pricing and terms will likely shift, models will remain subject to export controls, and security use cases are among the most likely to face restrictions.\u00a0<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cIf an organization\u2019s capability is welded to a single vendor model, they\u2019re\u00a0 essentially building on rented ground. However, if it lives in the harness, they can swap the reasoning layer and keep working. Cato demonstrated how cheap that swap is. Attackers have already internalized it, and defenders should be building the same way.\u201d<\/em><br \/><em>\u2014<\/em>Jim Sherlock<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Mention offensive AI and expect the discussion to focus on vulnerability discovery, malware creation, and exploit generation, butrecent researchby Cato Networks identified another \u2014 and very potent \u2014 application for offensive AI.Cato explained in ablog postthat it evaluated in a controlled Active Directory lab environment, how frontier models behave when combined with agent platforms, MCP-enabled tooling, and operational guidance. \u201cThe objective was straightforward: determine how effectively an <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[32775],"tags":[],"class_list":["post-26180","post","type-post","status-publish","format-standard","hentry","category-reversinglabs"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26180","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26180"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26180\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26180"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26180"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26180"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}