12 AI Agents Taught Themselves to Evade Your EDR. Most Security Teams Still Won't Trust AI to Triage

12 AI Agents Taught Themselves to Evade Your EDR. Most Security Teams Still Won't Trust AI to Triage

BackerLeader 44 232 397
calendar_today agoschedule4 min read

In March, according to Sophos, a ransomware actor spun up 12 separate AI agents and set them loose against copies of Sophos's own endpoint protection, CrowdStrike, and Microsoft Defender, running in parallel on separate virtual machines, testing and iterating malware until it could slip past all three. Nash Borges, Sophos's SVP of AI and Engineering, said the company only found the campaign, tracked internally as STAC6994, by working backward from a ransomware event on a host nobody had been actively monitoring. By the time they reconstructed what happened, the operation had produced nearly 80 distinct malware modules and more than 70 evasion techniques, version-controlled and refined automatically as the agents worked. Borges is careful not to oversell what's new here. "It's changing the clock, not the playbook," he said: credential theft, lateral movement, privilege escalation, the fundamentals haven't changed. What's changed is how fast an attacker can iterate through them without needing a room full of skilled humans to do it.

That's one half of the story playing out at Black Hat this year. The other half is that most security teams still don't trust AI to run their own SOC, and the data backs that hesitation up more than the marketing on the show floor would suggest. Research from Strike48, the agentic operations platform that grew out of security data company Devo, found an 84% to 22% gap between security leaders who think AI agents should be handling Tier 1 SOC work and those actually willing to deploy one. Tim Leehealey, Strike48's co-founder, argues the gap isn't really about the technology being immature. It's that most vendors are still pitching a single, general-purpose agent for tasks that were never that complicated to begin with. "Asking an agent to do that is like hiring a PhD and telling him to think deeply about the problem," Leehealey said. "It doesn't work." Security, in his framing, values precision over accuracy in a way most consumer-facing AI products don't: ask the same question with the same facts twice, and you want the same answer both times, not an approximately-right one delivered with total confidence.

That confidence problem is exactly what erodes trust on the floor. Leehealey described watching security buyers walk booth to booth, asking each vendor's demo agent the same kind of question and getting a fluent, wrong answer back, then watching the agent instantly agree it was wrong the moment it was corrected, the AI equivalent of a beekeeper telling a chatbot which plants are actually blooming in their area and watching it abandon its first answer on the spot. Leehealey is blunt about where that leaves things today: "If I can't get ChatGPT to build a PowerPoint I'm happy with, why would I trust it to run my SOC unsupervised?" Asked directly if AI is ready for that yet, his answer was a flat no.

The model that's actually working, according to both Leehealey and Corey Thuen, Gravwell's founder and CEO, isn't one big autonomous agent. It's breaking a security process down into deterministic pieces, scripts, API calls, known steps with a knowable outcome, and keeping the genuinely cognitive, judgment-requiring piece as small as possible. Leehealey describes this as smaller and more granular than most of the industry's current best practice around narrow, single-purpose agents. Thuen, whose company builds the log infrastructure a lot of this analysis actually runs on, makes a similar point from the data side: the fundamentals of security analytics don't change just because an LLM is in the loop. What changes is that the analysis has to run at far greater speed and volume, and an AI agent needs to be auditable the same way a human analyst is, tracking what commands it ran and flagging something as basic as a system prompt getting silently changed and changed back, a sign of the exact kind of tool or prompt poisoning attack this whole ecosystem is now exposed to.

Thuen's company takes a deliberately contrarian position on what feeds that analysis in the first place: don't throw logs away to save on storage costs, because you don't know which one matters until the day you need it. Strike48's own pitch to customers rests on the same principle from a different angle, promising close to 100% log visibility, where Thuen says most teams keep only 60 to 70% due to storage cost, by moving that data onto cheap, cold object storage instead of the expensive indexed tier most SIEMs demand.

Both companies are candid that AI oversight can't mean handing over the keys. Thuen is blunt that replacing experienced analysts with junior staff running an LLM unsupervised is "a recipe for disaster," not a cost-saving shortcut. Sophos's Borges frames the same caution as a spectrum rather than a switch: human-in-the-loop for anything risky or irreversible, human-on-the-loop, meaning an AI can act autonomously but a human still audits the results after the fact, for lower-risk, well-validated scenarios, with the boundary between the two moving only as confidence is actually earned through evaluation, not assumed upfront.

None of this is theoretical about how easy the attacker side has gotten. Thuen runs hands-on workshops teaching people how MCP and agentic tooling actually work, including a live exercise where students stand up a malicious MCP server and use it to attack a running system. In a three-hour session, he said, complete beginners with no security or AI background can pull it off. Borges made a related point from the defender's chair: attackers are increasingly going after the AI tooling itself, manipulating coding assistants and MCP servers directly, rather than only using AI as a tool to speed up conventional attacks. The 12 agents Sophos found building an evasion kit in March, and the beginner who can stand up a working attack server in an afternoon, are two versions of the same problem: the barrier to building something dangerous with agentic AI has dropped faster than most security teams' willingness to trust agentic AI with anything that matters.

🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

AI Agents Don't Have Identities. That's Everyone's Problem.

Tom Smithverified - Mar 13

Cyera: Non-Human Identities Grew 480% in Six Months. Most Companies Have No Idea What They're Doing.

Tom Smithverified - Aug 3

Defending Against AI Worms: Securing Multi-Agent Systems from Self-Replicating Prompts

alessandro_pignati - Apr 2

️ Agent Action Guard: Framework for Safer AI Agents

praneeth - Apr 1

Your Backup Data Knows More Than You Think. HYCU aiR Is Finally Asking It the Right Questions.

Tom Smithverified - May 14
chevron_left
15.9k Points673 Badges
204Posts
119Comments
81Connections
LLM Training & Evaluation Specialist with hands-on experience building major AI models. As one of th... Show more

Related Jobs

View all jobs →

Commenters (This Week)

15 comments
3 comments

Contribute meaningful comments to climb the leaderboard and earn badges!