AI Driven Attack Automation in Security Operations
- Siwoo Lee

- Jun 9
- 6 min read
PAGO Gartner Security & Risk Management Summit On Site Report
PAGO attended the 2026 Gartner Security & Risk Management Summit in National Harbor, Maryland, and sharing key insights from the security sessions discussed on site. This report examines Use AI Like a Threat Actor and Other Strategies for AI in Cyber Defense, presented by Leigh McMullen. The session explored how threat actors are using AI to execute attacks faster and at greater scale, and how security teams can apply those lessons to security operations automation and MDR.

"The key is not improved capability. The key is expanded attack execution."
Leigh McMullen used this statement to describe how threat actors are using AI today.
Threat actors are not suddenly becoming more sophisticated experts through AI. Instead, they are using AI to execute techniques and procedures they already know more quickly and across a larger number of targets. This changes how organizations should view AI related threats. The challenge is often not the appearance of entirely new attack methods. The challenge is that familiar attack procedures can now be repeated, automated, and scaled within much shorter timeframes.
How Threat Actors Are Using AI
McMullen summarized the way threat actors use AI through four concepts: Upscaling, Target Selection, Obfuscate Attacks, and Accelerate and Automate Tasks.

These concepts are closely connected. Rather than creating entirely new attack strategies, threat actors are using AI to repeat familiar attack procedures more quickly, apply them across more targets, automate repetitive activities, and improve their ability to avoid detection.
This perspective helps explain the reality of AI driven threats. McMullen suggested that security professionals should learn from the way threat actors approach AI and return to a hacker mindset rather than relying solely on the default capabilities of security products. In this context, he made an interesting observation. "Script Kiddies are getting more value from AI than we are."
Traditionally, Script Kiddies combine existing tools and code created by others to achieve a specific objective. McMullen suggested that security professionals should adopt a similar mindset in the AI era. Instead of simply consuming AI as a finished product, teams should learn how to combine capabilities, connect workflows, and solve operational problems directly.
Target Selection: Deciding What to Protect and Investigate First
Among the four AI use cases discussed by McMullen, Target Selection has particular relevance for defenders. According to Gartner, threat actors use AI as a targeting engine to collect intelligence, identify potential victims, and rapidly execute known exploits against selected targets.
From a defensive perspective, organizations cannot treat every vulnerability and every alert with the same priority. What matters is understanding which threat actors are most likely to target the organization, which TTPs they commonly use, which vulnerabilities or misconfigurations they frequently exploit, and whether those exposures exist within the environment.

McMullen presented a structure that connects threat intelligence to organizational decision making. News Agents and Threat Agents collect external information, while RAG based prompts organize that information within the context of the organization. Security leaders can evaluate business impact and priorities, SOC teams can narrow investigation scope, and CTEM teams can assess exposed assets and determine remediation priorities.
This approach is equally important for MDR service providers. Knowing that a new vulnerability has been disclosed is not enough. Security teams must also understand which assets are affected, whether the vulnerability contributes to a realistic attack path, and whether related assets or accounts are already connected to existing detection activity. Understanding Target Selection means establishing a framework for deciding what should be protected first and what should be investigated first.
Obfuscate Attacks: Using AI to Bypass Traditional Detection
Threat actors are also using AI to modify tools and code in ways that make traditional detection more difficult. McMullen provided examples such as creating look alike websites and tools, rewriting malware patterns in different programming languages, and hiding backdoors inside open source software.
Gartner explained that these techniques appear through the creation of polymorphic malware, spoofed legitimate tools, and obfuscated backdoors designed to bypass traditional detection approaches.

This message extends beyond detection. It also affects how organizations validate development, deployment, and automation processes. AI generated code can improve productivity and at the same time, unvalidated code entering production environments or automation pipelines can introduce new supply chain risks. Organizations should verify that internal scripts, CI/CD pipelines, security automation tools, and open source dependencies are not performing unintended actions such as unauthorized communications, credential access, or privilege escalation.
Relying solely on file signatures and known malware patterns is becoming less effective. Security teams need to understand who performed an action, where it occurred, what privileges were involved, and how activities progressed over time. As Living off the Land techniques continue to grow, the surrounding context becomes as important as the file or tool being executed.
McMullen also described an interesting defensive application of AI. Security teams can generate synthetic data and use deception techniques to attract and occupy threat actors. By creating realistic decoys, defenders can observe attacker behavior, understand which tools are being used, identify exploration paths, and incorporate those observations into detection and response programs.
Accelerate and Automate Tasks: Repeating Familiar Attack Chains Faster
McMullen explained that even advanced threat actors are not always using AI in highly sophisticated ways. Gartner described this trend as "quiet scale." APT groups are often using AI in what McMullen called "the most boring way possible." Rather than creating entirely new attack strategies, they are automating and accelerating familiar attack procedures.

The Living off the Land kill chain provides a useful example. Initial access, establishing a foothold with built in tools, privilege escalation, internal reconnaissance, lateral movement, credential access, data collection and exfiltration, and persistence are not new attack stages. These are familiar activities that have appeared repeatedly across many real world attacks.
What changes is the speed of execution and the ability to repeat those activities across many environments.
Threat actors can use AI to complete individual stages more quickly and apply the same procedures to a larger number of targets. Security teams should therefore view AI driven attacks as an acceleration of existing kill chains rather than a separate category of threats.
Small Agents: Security Automation Begins with Small Roles
The final message of the session focused on how AI powered defense automation should be structured.
According to Gartner, effective AI operations are unlikely to come from a single large agent responsible for every task. Instead, they emerge from multiple small agents with clearly defined responsibilities working together within a broader ecosystem.
McMullen explained that this structure is important because of a simple question: How do organizations validate AI generated results?
When a single large agent attempts to manage an entire workflow, it may generate convincing outputs without thoroughly validating the underlying data. This increases the risk of inaccurate conclusions and hallucinated results. By contrast, when individual agents perform small, focused tasks and generate limited outputs, the overall process becomes easier to review and validate.

This model can be applied directly to security operations. A News Agent may collect external threat information. A Threat Agent may analyze threat actors and TTPs. A SOC Agent may prioritize alerts and investigations. The objective is not to have one AI system perform every action. The objective is to assign specific responsibilities to individual agents and connect their outputs into a larger workflow.
McMullen noted that this structure also makes monitoring easier. Organizations can observe how agents interact, review outputs at each stage, and identify areas where errors or unexpected behavior occur. This makes it easier to understand what work AI has actually performed and where inaccurate conclusions may have been introduced.
Ultimately, the value of AI driven automation comes from clearly defined responsibilities, connected workflows, and the ability to verify actual outcomes.
Conclusion
The AI era is increasing the speed, scale, and repeatability of existing attack methods.
Defenders should begin from the same reality. The focus should be on defining operational challenges, connecting the right data sources, and building processes that support validation.
From PAGO's MDR perspective, this is about more than adding AI capabilities to security operations. As threat actors use AI to execute attacks faster and across more targets, security teams need to identify meaningful signals, connect them to assets, accounts, exposures, and threat intelligence, and understand which actions should take priority.
AI driven cyber defense begins with operational improvement. Organizations can automate repetitive tasks, validate outcomes, and improve processes over time. As threat actors gain speed and scale through AI, security teams can use AI to improve operational consistency, support faster decisions, and respond more effectively.

Written by: Siwoo Lee Threat Analyst | DeepACT MDR Center



