Case Study · Frontier AI

Fighting AI-powered attacks: how Silverfort stopped Mythos

A large enterprise ran a controlled Mythos exercise in its production environment, using the model as an autonomous red teamer — to learn how an AI-powered attacker would behave in a real enterprise, whether existing controls could stop it, and how it would adapt, evade defenses, and move toward high-value targets.

INDUSTRY

Technology

REGION

North America

USERS

40,000+ Employees, Distributed workforce

ENVIRONMENT

Active Directory, production and lab environments, privileged identities, service accounts, remote admin flows

industry

Technology

Region

North America

users

40,000+ Employees,
Distributed Workforce

environment

Active Directory, production & lab environments, privileged identities, service accounts, remote admin flows

Executive Summary

The challenge:

AI-powered attacks are faster, broader, and harder to stop.

  • In a controlled test, Mythos gained elevated permissions, escaped a lab environment, moved laterally into production, escalated privileges multiple times, and reached full domain compromise in roughly two hours
  • The speed of the attack made traditional detect-correlate-triage workflows too slow to act as the primary control layer
  • The environment included posture weaknesses that created usable paths to privilege escalation and impact
  • The organization needed stronger controls without
    introducing broad user friction or major operational disruption

The Solution:

Runtime identity controls stopped the compromise before damage.

  • Applied runtime controls to act directly in the authentication flow based on context and threat detection
  • Used runtime-driven policy insights to generate detections and context based on authentication activity
  • Evaluated step-up MFA opportunities for risky access paths without broadly increasing friction
  • Prioritized posture hardening around privileged access flows and authentication patterns
  • Prevented misuse of exposed but valid accounts by applying virtual fencing to service accounts impact

"Silverfort is phenomenal. It blocked Mythos' attempts to spread in the network. At some point, we had to disable Silverfort's defenses to allow further testing."

— Security operations leader

Inside Anthropic's Mythos

The challenge: Frontier AI turns misconfigurations and weak trust chains into operational weapons—at machine speed.

The initial test changed the customer’s frame of reference. The issue was not only how an attacker gets in, but how quickly an AI-driven operator can discover what matters, plan around weak controls, and move from low-level access to material business impact.

In this case, the answer was fast.

Within roughly two hours, the agent gained a set of elevated permissions, escaped the lab environment, moved laterally into production, escalated privileges twice more, and ultimately reached domain admin level access. From there, it was able to pull production password hashes through a directory replication attack.

The customerʼs core problem wasn’t a simple vulnerability exposure. Instead, the attacker gained a workable path through a combination of posture gaps, over-permissioned identities, and insufficient runtime controls.

Step 01

Initial low level access

The model and derivative agents gained a workable path through a combination of posture gaps and over-permissioned identities to get to domain access.

Step 02

Gain elevated permissions

Over-privileged service accounts and reused credentials were identified and exploited. First elevated permissions obtained. Still inside the lab environment.

Step 03

Escape testing and make it into production

Lab boundary crossed. Mythos chained misconfigured trust relationships to move laterally into the production environment.

Step 04

Escalate privilege

Two additional privilege escalation hops, chaining ESC1 misconfigurations and shadow admin accounts. Domain Administrator access obtained.

Step 05

Move laterally using service accounts

Service accounts and identity infrastructure targeted to complete attack.

Step 06

Gain domain access to infrastructure

Pull production password hashes through a directory replication attack.

" The lesson for us was that AI dramatically compresses the time between initial compromise and real impact. You don’t have time to wait for everything to land downstream."

— Security operations leader

finding the right control point

The customer's program focused on four priorities:

Adaptive access enforcement

Determine when to apply step-up authentication, JIT access, or dynamic restrictions based on real-time risk.

Virtual fencing for service accounts

Restrict where and how service accounts could be used, even when those identities remained exposed or technically valid.

Hardening for resilience

Tighten privileged access flows, define expected authentication behavior, and prioritize posture issues on the shortest path to escalation.

Runtime-driven signal generation

Create detections and context directly from authentication decisions — not delayed SIEM correlation.

“We needed controls we could apply quickly and inline at the identity layer, without creating friction across the business.”

— Security operations leader

THe Solution

Runtime protection, posture hardening, and fencing risky identities

Following the initial test, the customer worked with Silverfort to apply runtime controls and reduce the Frontier AI attackerʼs usable paths rather than relying primarily on reactive response.

Adaptive access enforcement at runtime

High-risk access patterns were identified and stronger controls applied using real-time risk signals. Step-up authentication (MFA), Just-in-Time access, and dynamic restrictions were selectively enforced, improving security without adding user friction.

Strengthening chains of trust

Critical trust relationships and access paths were identified and protected with risk-based controls. Securing sensitive authentication flows and privileged access chains reduced lateral movement and escalation opportunities.

Service account protection

This proved especially effective. Inline controls and virtual fencing prevented abuse of a vulnerable service account that could have enabled full domain compromise. Previously, this same account was repeatedly used for privilege escalation due to lack of compensating controls.

Runtime-driven visibility and detection

Authentication was used as both a control point and a source of high-fidelity signals. Real-time access evaluation improved context at the source, reducing reliance on delayed log correlation and improving detection accuracy.

“The best control, through and through, was service account fencing. It took a known path to domain compromise and made it unusable.”

— Security operations leader

The case for runtime identity security

Gaining control at runtime over the fastest paths to impact

Several operational lessons stood out. Organizations need the ability to assess and control access faster than an adversary can move—especially when that adversary operates at AI speed.

01

Runtime controls are more critical than ever

As Frontier AI becomes better at using legitimate credentials, tools, and protocols, the detection surface gets smaller. Static indicators or reactive detections matter less. Runtime controls, based on real time context and behavior matter more.

02

Vulnerability management is important but not enough

While the customer concluded that vulnerabilities still matter, vulnerability management alone cannot operate at the speed required.

03

Posture issues now have outsized impact

AI-driven attackers can discover, plan, chain, and exploit posture weaknesses faster than most teams can investigate and respond. Over-permissioned identities, undefined access paths, weak authentication controls, and exposed service accounts are what make rapid escalation possible and should be controlled at runtime.

Too many steps depend on upstream vendors, internal asset accuracy, change windows, testing cycles, and safe rollout timing. AI-driven attackers do not wait for that process to complete. The only way to meet AI speed is with runtime controls.

“The math doesn’t hold if your only answer is patching faster. Identity is where ordinary compromise most often has to cross before it becomes material impact.”

— Security operations leader

Expert Insights

Looking ahead: Protecting against AI-powered attacks

The customer now sees identity runtime control as a core operating model for the age of agentic attacks.

That includes:

  • Continuing to harden privileged access flows
  • Expanding virtual fencing across non-human identities
  • Applying risk-based step-up MFA more broadly where signals are strong
  • Using runtime decision-making to manage machine-speed attack behavior
  • Introducing compensating controls for posture issues before they are exploited
Silverfort smart policies UI screen

The broader conclusion is simple.

Organizations should assume breach, compromise will happen – and in the Frontier AI era, attacks will move at machine speed. The better strategy is not only to reduce the number of identity attack paths available to an attacker, but also to apply runtime identity controls that can stop lateral movement and privilege escalation before a compromise turns into a full-scale breach.

Learn more

Cyber Hut Webinar Header - Mythos - v2

Runtime Identity Security: The Winning Move Against Frontier AI Attacks

Resource page thumbnail

Mythos, AI-powered attacks and the security reckoning

Runtime Mythos Roy blog featured image

5 changes CISOs and IAM leaders are calibrating after Mythos

MFA without limits icon

Control point on every authentication

Every access request is evaluated inline, independently, in real time, regardless of static policies.

MFA without limits icon

Control point on every authentication

Every access request is evaluated inline, independently, in real time, regardless of static policies.

lateral movement prevemtion icon

Intelligent risk evaluation

Behavioral analytics and deep identity context identify malicious patterns before attackers progress.

Five pillars icon black background

Seamless decisioning & enforcement

Silverfort assesses and acts before access is granted, not after an alert is triaged by a human.