Case Study · Frontier AI
Fighting AI-powered attacks: how Silverfort stopped Mythos
A large enterprise ran a controlled Mythos exercise in its production environment, using the model as an autonomous red teamer — to learn how an AI-powered attacker would behave in a real enterprise, whether existing controls could stop it, and how it would adapt, evade defenses, and move toward high-value targets.
INDUSTRY
Technology
REGION
North America
USERS
40,000+ Employees, Distributed workforce
ENVIRONMENT
Active Directory, production and lab environments, privileged identities, service accounts, remote admin flows
industry
Technology
Region
North America
users
40,000+ Employees,
Distributed Workforce
environment
Active Directory, production & lab environments, privileged identities, service accounts, remote admin flows
Executive Summary
The challenge:
AI-powered attacks are faster, broader, and harder to stop.
- In a controlled test, Mythos gained elevated permissions, escaped a lab environment, moved laterally into production, escalated privileges multiple times, and reached full domain compromise in roughly two hours
- The speed of the attack made traditional detect-correlate-triage workflows too slow to act as the primary control layer
- The environment included posture weaknesses that created usable paths to privilege escalation and impact
- The organization needed stronger controls without
introducing broad user friction or major operational disruption
The Solution:
Runtime identity controls stopped the compromise before damage.
- Applied runtime controls to act directly in the authentication flow based on context and threat detection
- Used runtime-driven policy insights to generate detections and context based on authentication activity
- Evaluated step-up MFA opportunities for risky access paths without broadly increasing friction
- Prioritized posture hardening around privileged access flows and authentication patterns
- Prevented misuse of exposed but valid accounts by applying virtual fencing to service accounts impact
"Silverfort is phenomenal. It blocked Mythos' attempts to spread in the network. At some point, we had to disable Silverfort's defenses to allow further testing."
— Security operations leader
Inside Anthropic's Mythos
The challenge: Frontier AI turns misconfigurations and weak trust chains into operational weapons—at machine speed.
The initial test changed the customer’s frame of reference. The issue was not only how an attacker gets in, but how quickly an AI-driven operator can discover what matters, plan around weak controls, and move from low-level access to material business impact.
In this case, the answer was fast.
Within roughly two hours, the agent gained a set of elevated permissions, escaped the lab environment, moved laterally into production, escalated privileges twice more, and ultimately reached domain admin level access. From there, it was able to pull production password hashes through a directory replication attack.
The customerʼs core problem wasn’t a simple vulnerability exposure. Instead, the attacker gained a workable path through a combination of posture gaps, over-permissioned identities, and insufficient runtime controls.
Step 01
Initial low level access
The model and derivative agents gained a workable path through a combination of posture gaps and over-permissioned identities to get to domain access.
Step 02
Gain elevated permissions
Over-privileged service accounts and reused credentials were identified and exploited. First elevated permissions obtained. Still inside the lab environment.
Step 03
Escape testing and make it into production
Lab boundary crossed. Mythos chained misconfigured trust relationships to move laterally into the production environment.
Step 04
Escalate privilege
Two additional privilege escalation hops, chaining ESC1 misconfigurations and shadow admin accounts. Domain Administrator access obtained.
Step 05
Move laterally using service accounts
Service accounts and identity infrastructure targeted to complete attack.
Step 06
Gain domain access to infrastructure
Pull production password hashes through a directory replication attack.
" The lesson for us was that AI dramatically compresses the time between initial compromise and real impact. You don’t have time to wait for everything to land downstream."
— Security operations leader
finding the right control point
The customer's program focused on four priorities:
Adaptive access enforcement
Determine when to apply step-up authentication, JIT access, or dynamic restrictions based on real-time risk.
Virtual fencing for service accounts
Restrict where and how service accounts could be used, even when those identities remained exposed or technically valid.
Hardening for resilience
Tighten privileged access flows, define expected authentication behavior, and prioritize posture issues on the shortest path to escalation.
Runtime-driven signal generation
Create detections and context directly from authentication decisions — not delayed SIEM correlation.
“We needed controls we could apply quickly and inline at the identity layer, without creating friction across the business.”
— Security operations leader
THe Solution
Runtime protection, posture hardening, and fencing risky identities
Following the initial test, the customer worked with Silverfort to apply runtime controls and reduce the Frontier AI attackerʼs usable paths rather than relying primarily on reactive response.
Adaptive access enforcement at runtime
High-risk access patterns were identified and stronger controls applied using real-time risk signals. Step-up authentication (MFA), Just-in-Time access, and dynamic restrictions were selectively enforced, improving security without adding user friction.
Strengthening chains of trust
Critical trust relationships and access paths were identified and protected with risk-based controls. Securing sensitive authentication flows and privileged access chains reduced lateral movement and escalation opportunities.
Service account protection
This proved especially effective. Inline controls and virtual fencing prevented abuse of a vulnerable service account that could have enabled full domain compromise. Previously, this same account was repeatedly used for privilege escalation due to lack of compensating controls.
Runtime-driven visibility and detection
Authentication was used as both a control point and a source of high-fidelity signals. Real-time access evaluation improved context at the source, reducing reliance on delayed log correlation and improving detection accuracy.
“The best control, through and through, was service account fencing. It took a known path to domain compromise and made it unusable.”
— Security operations leader
The case for runtime identity security
Gaining control at runtime over the fastest paths to impact
Several operational lessons stood out. Organizations need the ability to assess and control access faster than an adversary can move—especially when that adversary operates at AI speed.
01
Runtime controls are more critical than ever
As Frontier AI becomes better at using legitimate credentials, tools, and protocols, the detection surface gets smaller. Static indicators or reactive detections matter less. Runtime controls, based on real time context and behavior matter more.
02
Vulnerability management is important but not enough
While the customer concluded that vulnerabilities still matter, vulnerability management alone cannot operate at the speed required.
03
Posture issues now have outsized impact
AI-driven attackers can discover, plan, chain, and exploit posture weaknesses faster than most teams can investigate and respond. Over-permissioned identities, undefined access paths, weak authentication controls, and exposed service accounts are what make rapid escalation possible and should be controlled at runtime.
Too many steps depend on upstream vendors, internal asset accuracy, change windows, testing cycles, and safe rollout timing. AI-driven attackers do not wait for that process to complete. The only way to meet AI speed is with runtime controls.
“The math doesn’t hold if your only answer is patching faster. Identity is where ordinary compromise most often has to cross before it becomes material impact.”
— Security operations leader
Expert Insights
Looking ahead: Protecting against AI-powered attacks
The customer now sees identity runtime control as a core operating model for the age of agentic attacks.
That includes:
- Continuing to harden privileged access flows
- Expanding virtual fencing across non-human identities
- Applying risk-based step-up MFA more broadly where signals are strong
- Using runtime decision-making to manage machine-speed attack behavior
- Introducing compensating controls for posture issues before they are exploited

The broader conclusion is simple.
Organizations should assume breach, compromise will happen – and in the Frontier AI era, attacks will move at machine speed. The better strategy is not only to reduce the number of identity attack paths available to an attacker, but also to apply runtime identity controls that can stop lateral movement and privilege escalation before a compromise turns into a full-scale breach.
Control point on every authentication
Every access request is evaluated inline, independently, in real time, regardless of static policies.
Control point on every authentication
Every access request is evaluated inline, independently, in real time, regardless of static policies.
Intelligent risk evaluation
Behavioral analytics and deep identity context identify malicious patterns before attackers progress.
Seamless decisioning & enforcement
Silverfort assesses and acts before access is granted, not after an alert is triaged by a human.

