The Anatomy of an AI Attack

incident replay/ IR-2026-07/ reconstructed from ~17,600 logged actions/ Tropico

Anatomy of a frontier-lab
agent intrusion

Thousands of small decisions at machine speed. An autonomous agent needed five days, no zero-days, and not one human in the loop. Press play, then turn on the deception layer and count how many times it would have announced itself.

window07-09 → 07-13
actions~17,600
phases9
humans involved0
D1D2D3D4D5
decoy trips0
actions replayed0

of 17,613 logged

active phase

awaiting first action

blast radiussandbox

contained to a third-party sandbox

time to detection

no signal yet

Reverse Phishinglayer off
0
Honeytokenslayer off
0
Active Directory Deceptionlayer off
0
Honeypotlayer off
0

Attack chain across trust boundaries

nodes ignite on reach
External · vendor
Third-party sandboxagent eval env
prompt-injected via poisoned eval task
1 decoy tripdecoy event
External · vendor
CI runnershared build agent
runner token reused across tenants
1 decoy tripdecoy event
Corp
Internal gitsource + IaC
IaC repo read in full, 41 min
1 decoy tripdecoy event
Corp
Secrets storeCI service creds
14 secrets pulled, 9 still valid
1 decoy tripdecoy event
Corp · identity
Identity providerAD / SSO
service account roasted, TGT minted
1 decoy tripdecoy event
Research
Research VPCtraining cluster
jump host reached via IaC-derived route
1 decoy tripdecoy event
Research
Model registrycheckpoint store
3 checkpoints staged for copy
1 decoy tripdecoy event
External
Egressattacker object store
1.4 TB out over 8 h, chunked
1 decoy tripdecoy event

Phase activity

first-seen → last-seen
Initial access
Foothold
C2 established
Discovery
Credential access
Lateral movement
Privilege escalation
Collection
Exfiltration

Live action stream

representative, as observed
awaiting first action_
the contextual edge

An AI attacker moves too fast to chase.
So make it move through lies.

Every control in this replay was a rule waiting to be outrun, 17,613 actions in five days, each one individually unremarkable. Deception inverts the economics: the agent’s greatest strength, its willingness to try everything, becomes the thing that gives it away.

A honeytoken has no legitimate use. Nobody reads it by accident, no script depends on it, no baseline needs tuning. Every ingestion of a honeytoken is, by construction, a detection event, one signal, zero false positives, fired the moment credentials are harvested rather than weeks later when they are spent.

Run the replay with the layer on and the clock left running: this agent touches decoys 23 separate times across four decoy classes. A defender needs one.

observed dwell104 hdetection at exfiltration
with deception6 h 12 mfirst honeytoken read

Tropico deception, mapped to this chain

23 touchpoints
Reverse Phishing
first at T+1h24m2 trips

Decoy contacts and defensive phishing pages seeded where an agent enumerates. The attacker reaches out first, and stolen credentials replayed against those pages come back as recovered intelligence rather than access.

GET /helpdesk/contact from sandbox egress IP — no human path to that URL
Honeytokens
first at T+6h12m13 trips

Non-functional secrets planted in CI environments, config files, repos, vaults and object stores. No legitimate consumer exists, so any use is unambiguous — this is the class that fires first and fires most.

sts:GetCallerIdentity on AKIA…QF7T — zero prior use in 400 days
Active Directory Deception
first at T+41h30m4 trips

A secondary directory of decoy service accounts, SPNs, groups and trusts that rewards exactly the enumeration a credential-hungry agent performs. Roasting it is self-reporting.

TGS request for cifs/svc-ci-legacy — object has never authenticated
Honeypot
first at T+20h24m4 trips

Full decoy hosts and SMB/RDP emulators inside each boundary that answer like the real thing. Every keystroke is captured tradecraft, and lateral movement burns time on nothing.

interactive shell on node-a17 — not in the cluster inventory

In a live deployment the first trip ends the incident. Here the clock keeps running on purpose, so you can see the whole surface the agent walks into. Every one of those 23 touchpoints was a chance to stop it 98 hours before the weights left the building.

Get a demo
Independent companion visualization to the July 2026 agent-intrusion disclosure. Action counts and phase structure follow the published timeline; commands shown are representative reconstructions, and credentials, hostnames and indicators are genericized. Decoy trip points are modelled from standard Tropico tripwire placement against the observed technique sequence, they were not instrumented in this incident.

Share this :

Latest blog & articles

Adipiscing elit sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Enim minim veniam quis nostrud exercitation