AI-powered intrusions leave telltale pentest naming that defenders can search for

cyb3rops · x · 2026-09-13

Security researcher eyalsela notes AI-enabled attacks are detectable: threat actors tell their LLMs they're doing authorized pentests (even on open-weight models) or use harnesses like CyberStrikeAI, PentAGI and HexStrike, leaving explicit pentest artifacts. Real intrusion examples: SSH key labeled pentest-root, AWS Cognito pool <victim>[email protected], files like pentestprobe., deployment PENTESTPROBE, Keycloak user pentestkc01, ClusterRoleBinding pentest-admin, and user records changed to REDTEAM-OWNED. Searching for these explicit indicators can surface AI-assisted intrusions.

Original post →

More from coding & agent

coding & agent channel →