Agentic AI is compressing attacker intrusion timelines to minutes

Agentic AI is compressing attacker intrusion timelines to minutes

The important shift here is not simply that attackers are using AI, but that intrusion economics are changing. If an agent can execute hundreds or thousands of actions in under an hour, many defensive models built around human review, staged escalation and sequential triage become too slow by design. For security teams, this pushes response architecture toward machine-speed containment rather than analyst-speed interpretation.

That has immediate design implications. Endpoint telemetry, identity signals, privileged access events and east-west network activity need to be correlated continuously enough to trigger automated decisions before an operator can manually investigate. Organizations with fragmented logging, delayed enrichment pipelines or loosely integrated EDR, IAM and network controls may discover that they are collecting useful evidence for a post-incident report, but not enough connected context for live interruption.

The operational question is therefore less about whether to adopt AI in defense and more about where to trust automation. The practical priority is to pre-authorize low-regret containment steps: isolate hosts, revoke tokens, force credential resets, block suspicious process chains and constrain lateral movement paths. That requires clean asset inventories, tested playbooks and confidence that automated action will not create worse business disruption than the intrusion itself.

For architects and SOC leaders, compressed attacker timelines also raise the bar for resilience engineering. If prevention fails quickly, recovery readiness matters more: immutable backups, segmented administration, hardened identity infrastructure and routine restoration drills become part of the same defense strategy. In short, agentic attackers turn minutes into the critical unit of cybersecurity planning, so detection quality, control integration and response automation now matter as much as raw alert volume.


 

 

Artificial intelligence has moved from a curiosity in the threat landscape to a working part of the intrusion, and agentic adversaries have infiltrated extortion campaigns, espionage operations and hacktivist activity alike. The speed of the tooling, more than any novel attack technique, is what leaves defenders far less time to respond.

That shift is measurable, not theoretical. Security teams that spent last year debating whether attackers would adopt AI are now watching them run entire operations with it, according to Adam Meyers (pictured), senior vice president of intelligence at CrowdStrike Holdings Inc.

“The stat that’s most interesting is we had something like 26 agentic adversaries that we were tracking in the last 30 days. That’s more than we were tracking in the year before that,” Meyers said. “REVENANT SPIDER is a group that we were tracking that was using an agent in the intrusion. AI agents are now part of ransomware operations.”

Meyers spoke with theCUBE’s Dave Vellante and Rebecca Knight at Fal.Con, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed agentic adversaries, intrusion speed and the Sality botnet takedown. (* Disclosure below.)

Agentic adversaries compress the intrusion timeline

Speed is the defining characteristic. CrowdStrike’s threat hunting research already found that exploitation windows are shrinking as AI works its way into adversary operations, and agent-driven intrusions are pushing that further still.

“In 58 minutes, VAULT PANDA had conducted 1,100 commands. It was an agent that was doing it, and we were watching it learn in real time,” Meyers said. “When I talk about breakout time from our global threat report, we were talking this year about 29 minutes on average, 27 seconds was the fastest. I’m talking about an entire intrusion operation conducted in minutes from start to finish.”

Defenders are pushing back with collective action. CrowdStrike worked with law enforcement on the Sality botnet disruption, an effort a decade in the making against a network that had run for 23 years, Meyers noted.

“Bluntly, we do need to bring the fight to the bad guys. I think we need to raise the cost of doing business for them,” Meyers said. “We need to do it in a responsible way”.

Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of Fal.Con:

[link VIDEO]

(* Disclosure: TheCUBE is a paid media partner for the Fal.Con event. Neither CrowdStrike, the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)

 

Agentic AI is compressing attacker intrusion timelines to minutes

Enjoyed this article? Sign up for our newsletter to receive regular insights and stay connected.

Leave a Reply