BREAKING
AI-Written PowerShell Found in RDP Breach
How the Intrusion Unfolded
1Compromised credentials
2RDP access to server
3Run PowerShell script
4Map AD: users, groups
Telltale Signs of AI Code
MITRE ATT&CK Techniques Seen
Access & ExecuteT1021.001 / T1059.001
Remote services via RDP
Command execution via PowerShell
DiscoveryT1087
Account discovery
Enumerate the domain
AI Accelerates, Not Invents
Reassuring
AI-assisted isn't successful
Noisy script caught fast
Basics did the work
Worrying
Lowers barrier to entry
More clumsy attempts
Familiar behavior scales
Get the Fundamentals in Place
AI NEWS BLITZ
Researchers say an attacker used likely AI-generated PowerShell after breaking in over RDP.