BREAKING
AI-Written PowerShell Found in RDP Breach
How the Intrusion Unfolded
1
Compromised credentials
↓
2
RDP access to server
↓
3
Run PowerShell script
↓
4
Map AD: users, groups
Telltale Signs of AI Code
MITRE ATT&CK Techniques Seen
Access & Execute
T1021.001 / T1059.001
●
Remote services via RDP
●
Command execution via PowerShell
Discovery
T1087
●
Account discovery
●
Enumerate the domain
AI Accelerates, Not Invents
Reassuring
●
AI-assisted isn't successful
●
Noisy script caught fast
●
Basics did the work
Worrying
●
Lowers barrier to entry
●
More clumsy attempts
●
Familiar behavior scales
Get the Fundamentals in Place
AI NEWS BLITZ
Researchers say an attacker used likely AI-generated PowerShell after breaking in over RDP.