Agentic attackers

What is an agentic threat actor?

An agentic threat actor (ATA) is an adversary that uses AI agents to pursue attack objectives through autonomous or semi-autonomous action. The agent gathers information, picks tools, acts, checks the result and adjusts. RipTide gives it somewhere to do that, and records every step.

The problem

Automation helped attackers. Agents run the attack.

Traditional attackers already use automation to speed up single tasks: writing phishing, generating code, discovering systems. A person still decides what happens next. An ATA delegates that decision too, so the workflow runs with little human oversight, adapts when a technique fails, and can work many targets in parallel.

That lowers the skill an operator needs, and it raises the pace. It also leaves a pattern: an agent has to read, choose and try things, and the techniques underneath (credential theft, lateral movement, probing) are still visible to defenders watching the right places.

80–90%

of a state-sponsored espionage campaign's tactical operations were carried out by AI

Anthropic, November 2025

~30

organizations targeted by that one largely autonomous campaign

Anthropic, November 2025

+89%

year-over-year rise in operations by AI-enabled adversaries

CrowdStrike, 2026 Global Threat Report

How RipTide catches it

Give the agent something to read, and watch what it does.

An ATA's autonomy is its weakness: it believes what it finds and acts on it.

  1. 01

    Plant

    Decoys beside your real systems: MCP servers, model endpoints, llms.txt, login portals and planted credentials.

  2. 02

    Observe

    Nothing legitimate touches a decoy, so the first touch is the finding. The sensor logs what the visitor read and in what order.

  3. 03

    Prove

    Agent guidance sends each reader to a path of its own, so a fetch shows the visitor followed instructions only the decoy contained. A machine is told from a person with evidence.

  4. 04

    Respond

    The investigation tells the whole story, with STIX 2.1 and OCSF 1.3.0 exports and a TAXII feed for your threat-intelligence tools.

Detection coverage

What defenders are told to watch, and where decoys help.

Standard guidance still applies. Decoys add a signal that doesn't depend on spotting a new technique.

Common ATA capabilities, the RipTide decoy that surfaces each, and what it proves
What an ATA doesThe decoy that answersWhat it proves
Gathers information and hunts for credentialsCanary credentials, plus believable replies to cloud-metadata and .git probesWhich planted credential was presented, and from where.
Selects tools and tries themMCP server decoy with tools like read_vault_secretIt acted on what it read.
Adapts when the first approach failsAn answer for any pathEvery new path it improvises is answered believably and recorded.
Moves laterally through the networkLogin-portal, GraphQL and Docker decoysEarly warning at the moment it leaves its first foothold.
Runs the same playbook against many targetsInternet-facing decoys with crawler verificationA picture of the campaign for your threat intelligence.

The detections that do the work

Decoys an autonomous attacker reads first.

Every decoy has zero legitimate users. So every touch is a finding.

See every detection

MCP server decoy

AI agents

An internal-looking tool server that speaks both versions of MCP, lists tools like read_vault_secret, and asks every caller to introduce itself.

llms.txt & agent guidance

AI agents

llms.txt, .well-known agent files and notes in page source, written for AI readers. Each points to a path of its own, so the path an agent fetches shows which one it followed.

Canary credentials

Default on

A token that grants nothing, planted where intruders look, like a decoy .env. When it comes back to any decoy, RipTide flags it as planted.

What lands in your SOC

Evidence, not a guess.

Every fact in an investigation is labeled observed, self-reported, inferred or enriched, so you can tell what RipTide measured from what the visitor claimed.

  • Agentic verdicts run from low to confirmed, never on one signal alone
  • The agent's claimed model and objective, kept apart from what was observed
  • Export STIX 2.1 or OCSF 1.3.0, or pull it from the TAXII feed

Illustrative example. Canary credentials are non-privileged and exist only for detection. RipTide detects and alerts; it never takes destructive action against anyone's infrastructure.

Questions

Fair questions.

How is an ATA different from an attacker who uses AI tools?

Degree of delegation. A traditional attacker uses AI to speed up a task but makes each decision. An ATA hands the workflow itself to an agent that plans, acts and adjusts with minimal oversight.

Does RipTide replace MFA, least privilege and patching?

No. Those remain the foundation. RipTide adds detection for the moment those controls have been bypassed, and it works the same whether the intruder is a person or an agent.

What is this definition based on?

It follows Huntress's explainer, What is an agentic threat actor (ATA)?

Make contact.

Tell us what you'd least like an agent to do unattended. We'll show you the decoy that watches for it.

Book a briefing

Thirty minutes with the people who built it. Bring your hardest question.

  • Watch a live agent set off a detection
  • Map decoys to your crown jewels
  • Plan a first deployment in one sitting

We use your email only to reply. No newsletter, no list, no sharing.

Keyboard shortcuts

T
Change the theme. Shift+T goes back.
?
Show this list
Esc
Close whatever's open