Cover art for the blog titled "Why the Most Dangerous AI-Enabled Attacks Look Ordinary to Your SOC" by D3 Security

Why the Most Dangerous AI-Enabled Attacks Look Ordinary to Your SOC

Three alerts land in your queue within a few minutes. A credential dump on a file server. A new SSH login on a build machine. A large archive job on a database host. Each one is medium severity. Each one goes to a different analyst, or waits.

Together, they might be a single AI-driven attack moving through your network.

That’s the problem this post is about. The most dangerous AI-enabled attackers don’t stand out because of any single thing they do. They stand out because of how they string it together. An AI agent can find accounts, steal credentials, move between systems and package data for theft, and every step can look routine on its own. A SOC that reviews alerts one at a time won’t see the attack. To catch it, you have to investigate the chain, and you have to do it as fast as the attacker’s AI is moving.

The research behind this

In June 2026, Anthropic published a year-long study of 832 threat actors it banned for misusing its AI models in cyber operations. It mapped their activity to MITRE ATT&CK and scored each actor for risk from 0 to 100. Some results also appear in Verizon’s 2026 Data Breach Investigations Report. It’s the most detailed public look yet at how attackers actually use AI.

What the data shows

More attackers are getting more dangerous. The share of actors rated medium risk or higher rose from 33% to 56% in a single year.

Most attackers use AI to prepare. The top uses were writing malware, hiding it from detection and weakening security tools.

The riskiest attackers use AI once they’re inside. Only 54 of the 832 actors used AI for lateral movement, meaning moving from one system to the next inside a compromised network. That group scored clearly higher than everyone else, averaging 56.4 against an overall mean of 46.8. Five techniques showed up three to five times more often among the highest-risk actors:

TechniqueIn plain terms
T1021 Remote ServicesLogging into other machines over SSH or SMB
T1078.003 Valid AccountsUsing legitimate local accounts
T1003 OS Credential DumpingPulling passwords and hashes from systems
T1560 Archive Collected DataBundling stolen data to take out
T1505.003 Web ShellPlanting a backdoor on a web server

The usual warning signs don’t work well anymore. Security teams often judge attackers by how skilled they seem or how many techniques they use. In Anthropic’s data, neither said much about real risk. The typical actor used 16 techniques, a range that a few years ago would have suggested a serious, well-funded group.

The attack that looked average

The clearest example is GTG-1002, an espionage campaign Anthropic disrupted in November 2025. It earned the maximum risk score of 100. On paper, though, it used about as many techniques as dozens of medium-risk actors.

The danger was in the setup. The attacker connected an AI coding agent to standard hacking tools and let it work. The agent scanned for targets, broke into a web server, reached the internal cloud environment, collected keys and passwords, used them to go deeper and prepared data for theft. A person set the direction and made a few key calls. The AI did the rest.

Count this attacker’s techniques and you’d call them medium risk. Look at how the steps connected and you’d see the most dangerous actor in the dataset.

Why the sequence is the signal that lasts

Anthropic expects in-network techniques like lateral movement to become common as more attackers adopt AI. Once everyone does it, doing it stops being a useful warning sign. What keeps separating the dangerous attackers is orchestration: tooling that lets an AI chain attack stages together on its own.

MITRE ATT&CK doesn’t cover this yet. There’s no ID for an AI running the whole attack, and Anthropic says it’s working with MITRE to change that. Until then, the behavior your SOC most needs to catch is the one your framework can’t label. Detection built around individual techniques will keep missing it.

What SOC teams should change

Stop judging alerts in isolation. A credential dump, a new SSH login and a large archive job on three different hosts are one incident until proven otherwise.

Escalate post-compromise activity automatically. The five techniques above shouldn’t wait in a general queue.

Take attacker profiling out of your severity logic. How skilled an attacker looks, and how many techniques they use, now tells you very little.

Treat broken security tooling as an alert. More than half the actors used AI to disable or tamper with defenses. A silent EDR agent is a detection, not an IT ticket.

Match the attacker’s speed. Attackers now pair human direction with AI execution. Defenders can do the same: AI investigates every alert and assembles the full picture, and analysts make the final call on containment.

Quick checklist

  • Confirm you can detect the five high-risk techniques above
  • Make sure those detections escalate on their own
  • Connect alerts across identity, endpoint, network and cloud into one incident view
  • Alert on EDR tampering and telemetry gaps
  • Measure the time from the first inside-the-network signal to a containment decision
  • Decide which actions AI can take on its own and which need analyst sign-off

How D3 Morpheus investigates the chain

D3 Morpheus is an agentic AI SOC platform built around the problem described above. Its core method, Attack Path Discovery, doesn’t examine alerts in isolation. It follows a threat across tools to track lateral movement, and through time to track privilege escalation and persistence, rebuilding the attack from initial access to objective.

Every alert gets an L2-depth investigation, across more than 800 integrations. Up to 95% of alerts are triaged and investigated in under two minutes. That’s the speed an AI-run attack demands.

Morpheus also keeps people in charge of the decisions that matter. It investigates and drafts the response, your team signs off, and then it runs. When Morpheus is uncertain, it defers to a human. Every incident produces one audit trail showing what the AI found, what it recommended and why.

For MSSPs, this matters even more. As attackers move deeper into post-compromise work, more tenants generate high-stakes alerts at the same time. Investigating every alert at full depth, for every customer, is the only way to avoid missing the one that counts.

See how Morpheus traces an AI-driven attack path

FAQ

How do attackers use AI in cyberattacks?

Most use it to write malware, disguise it and weaken defenses before an attack. A smaller, more dangerous group uses it inside compromised networks to move between systems and steal credentials.

What’s the biggest warning sign of a high-risk AI-enabled attacker?

In Anthropic’s study, it was using AI for lateral movement. Looking ahead, the stronger signal is orchestration, where an AI chains attack stages together with little human input.

Does MITRE ATT&CK cover AI-driven attacks?

It covers the individual techniques. It doesn’t yet have IDs for AI-run orchestration, which is what separates the most dangerous attacks from the rest.

How should a SOC respond to AI-orchestrated attacks?

Investigate connected activity as one incident, escalate post-compromise techniques automatically and use AI-driven investigation so analysts can decide quickly with the full picture.

Sources: Anthropic, “Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator” and “What we learned mapping a year’s worth of AI-enabled cyber threats,” June 3, 2026.

Learn More About Morpheus

Powering the World’s Best SecOps Teams

Ready to see Morpheus?