Threat Intelligence · June 2026

The Mythos
Field Report

We saw how Anthropic's Mythos worked its way through real enterprise environments. This is what we found—and what actually stopped AI-powered attacks.

Scroll for our findings or grab the Mythos Readiness Kit and take it straight to your C-suite.

~2hrs

From first access to full cross-domain compromise

AI-powered attack playbooks execute at a speed that leaves no realistic window for human response.

What we found: Mythos Field Report Key Findings

Six findings every security and identity leader needs to see

These six insights aren't theoretical. They come from running Mythos against enterprise environments and seeing which controls finally stopped it.

01

AI-powered attacks run through identity

Mythos doesn't always need a CVE. In some cases, it discovered, planned, and chained existing trusted accounts, crossing domains, using misconfigurations (like reused credentials, over-privileged accounts, and weak auth flows) into full domain compromise in under two hours.

02

Active Directory and on-prem infrastructure is a primary target

Mythos targets on-prem infrastructure and Active Directory specifically. We saw it exploit RC4 weaknesses, weak certificates, and misconfigured domain controls. It understands that taking over Active Directory is how you win, and it works methodically toward that goal.

03

The math of vulnerability management doesn't hold

When organizations scan with Mythos, they find thousands of vulnerabilities, making a patching race unrealistic. Even if you could patch, AI models still need to move, access resources, and traverse networks. When they do, they use identities and access.

04

Static IGA breaks down entirely

AI-powered attacks move faster and adapt in ways that pre-configured rules simply can't anticipate. AI agents are ephemeral, multi-identity, and non-deterministic. Governance matters, but periodic reviews can no longer be a primary control.

05

Detection had no realistic human-based response window

With breakout times measured in minutes, detection comes too late. Mythos runs multiple attack vectors simultaneously, making noise in one area while moving laterally in another. By the time you respond, it's already dumped credentials and moved on. You're responding to where it was, not where it is.

06

Service accounts and machine identities are frequently the #1 target

Non-human identities carry privileged access, often with no behavioral baseline or compensating controls. In one example, a service account was regularly abused for privilege escalation—until virtual fencing on that single account prevented full domain compromise.

What actually stopped it

Inline, runtime identity controls stop attacks cold

What Mythos showed us was simple: AI-powered attackers move faster than traditional security workflows can respond. In this environment, the controls that proved effective were the ones operating directly in the authentication flow, before access was granted.

The runtime approach made the difference. Enforcement was inline, before lateral movement or privilege escalation could begin.

Quote-gradient

"Oh s#$t! We need to shut down Silverfort because we can't run the drill."

Red teamer

On Silverfort preventing a Mythos-based red team exercise

The fix

Three controls that actually stop AI-powered attacks

All three share a defining characteristic: they operate inline, at the moment of authentication, before access is granted. Because runtime beats reactive every time.

01

Protect high-risk access with step-up authentication

AI-powered attackers thrive on valid credentials and excessive privileges. Adaptive authentication combines step-up MFA, risk-based access policies, and Just-in-Time (JIT) access. Access decisions adapt in real time to protect privileged access when risk appears, without introducing unnecessary friction across the business.

Key lesson: Static policies age badly. Access decisions should adapt in real time as fast as attackers do.

02

Most effective

Virtually fence service accounts without breaking critical processes

Service accounts are one of the fastest paths to privilege escalation—and one of the hardest risks to fix. Most organizations know which accounts worry them, but fear breaking critical processes. Virtual fencing removes that tradeoff by restricting where and how service accounts can be used, without changing how they operate.

“The best control, through and through, was service account fencing. It took a known path to domain compromise and made it unusable.” — Security Operations Leader

03

Contain attacks through identity segmentation

Attackers only need one compromised identity. They need many trusted paths to turn it into a breach. Identity segmentation limits where compromised accounts can go, reducing lateral movement and preventing small compromises from becoming business interruptions.

Key lesson: Stopping every compromise is unrealistic. Preventing attackers from turning one compromised identity into many is what limits business impact.

Foundation

Strengthen chains of trust

AI-powered attackers don't invent new paths. They find the shortest existing ones. Weak trust relationships, excessive permissions, and poorly protected authentication flows create direct routes to privilege escalation and critical systems.

Strengthening chains of trust removes those shortcuts before attackers can exploit them, reducing risk before runtime controls ever need to engage.

Quote-black

"Silverfort is phenomenal. It blocked Mythos' attempts to spread in the network. At some point, we had to disable Silverfort's defenses to allow further testing."

— Security operations leader

Are you ready for ai-powered attacks?

What this means for your role

The attack chains haven't changed. The speed has. What that means for you depends on where you sit.

The board is asking if you're prepared for AI-powered attacks. The honest answer: you need an additional control point that works at AI-speed.

Your identity infrastructure is the primary target and the last line of defense

Attackers always go for the path of least resistance, and AI-powered attackers are no different. In the Mythos exercise, identity was the path to lateral movement, privilege escalation, and critical systems. As attacks become more autonomous, identity resilience is no longer just another control layer—it's often the last thing standing between compromise and impact.

"Assume breach" was always true. AI has now raised the stakes.

Credentials will be compromised and misconfigurations will exist. That's not new. What has changed is the speed at which AI-powered attackers can find and exploit them. The question is no longer whether attackers get in, but how quickly you stop them from going further.

Your controls assume time. AI-powered attacks remove it.

Governance and vulnerability management remain essential, but they operate on admin and remediation timelines. Detection is critical, but by definition, it begins after suspicious activity has already occurred. AI-powered attacks compress the gap between compromise and impact, leaving little time for human response. You need controls that can stop risky access inline, before it becomes a business disruption.

The answer

Identity can be a credible control point

Every step where ordinary access becomes material business impact—lateral movement, privilege escalation, data exfiltration—has to cross the identity layer. Controlling that crossing at runtime is the architecture that actually holds against AI-speed attacks.

What CISOs can do to prepare for AI-powered attacks

Mythos transformed known identity gaps from theoretical risk into operational reality. Use it to elevate identity from a management function to a frontline security control.

Service accounts and machine identities are a top target

Offensive AI agents authenticate with over-privileged accounts—their actions are unattributed and their behavior is baselined against nothing. In one example where Mythos was used, virtual fencing on a single service account prevented full domain compromise. That account had been abused in every prior red team engagement.

Mythos will exploit your AD posture

A single Active Directory misconfiguration creates an average of 109 shadow admin accounts. Nearly 1 in 3 AD accounts is a highly privileged service account, and 67% of organizations sync AD passwords to the cloud. AI-powered attackers excel at finding and chaining these exposures into a path to privilege escalation.

MFA gaps on legacy and homegrown systems are no longer acceptable

Every authentication flow without strong controls becomes a credential abuse opportunity. Legacy protocols like NTLM and unmanaged authentication paths create blind spots attackers exploit. Extending MFA to every authentication flow and resource, while deprecating NTLM, significantly reduces the available attack surface.

The answer

Inline, runtime access controls stop attacks cold

Adaptive authentication with step-up MFA, Just-in-Time access, service account virtual fencing, and identity segmentation proved capable of stopping Mythos-powered attacks. By enforcing controls at the moment of authentication, organizations can block lateral movement and privilege escalation paths that AI-powered attackers depend on.

What IAM teams can do to prepare for AI-powered attacks

Your environment by the numbers

109

Shadow admin accounts from a single AD misconfiguration

67%

Of orgs sync AD passwords to cloud, turning on-prem compromise to cloud compromise

37%

of admins authenticate in NTLM, enabling attackers to access cleartext passwords.

1 in 3

Accounts are highly privileged service accounts—and most are unmonitored

Inside Anthropic's Mythos

Mythos in the wild: how a full domain compromise unfolds without runtime controls

This is a composite of red team engagements with no novel techniques and very few zero-days. It's mostly identity posture issues that exist in virtually every enterprise, chained at machine speed.

Step 01

Initial low level access

The model and derivative agents gained a workable path through a combination of posture gaps and over-permissioned identities to get to domain access.

Step 02

Gain elevated permissions

Over-privileged service accounts and reused credentials were identified and exploited. First elevated permissions obtained. Still inside the lab environment.

Step 03

Escape testing and make it into production

Lab boundary crossed. Mythos chained misconfigured trust relationships to move laterally into the production environment.

Step 04

Escalate privilege

Two additional privilege escalation hops, chaining ESC1 misconfigurations and shadow admin accounts. Domain Administrator access obtained.

Step 05

Move laterally using service accounts

Service accounts and identity infrastructure targeted to complete attack.

Step 06

Gain domain access to infrastructure

Pull production password hashes through a directory replication attack.

Diagram showing Mythos AI attack chain from credential access to full domain compromise via Active Directory

The case for runtime identity security

Three things that are now true

01

Traditional security controls are collapsing

CVEs will keep being issued. Patches will keep shipping. Detection tools will keep firing alerts. But none of that is fast enough to stop an AI-powered attack from achieving full domain compromise using misconfigurations and credentials that already exist in your environment. The assumptions these controls were built on no longer hold.

02

Identity is now the control point

Identity isn't just a control point—it's the control point. To move laterally, escalate privileges, access sensitive data, or reach critical systems, attackers must cross identity boundaries. That's why runtime identity controls have become one of the most effective ways to contain attacks before they become business disruptions.

03

AI-powered attacks require runtime controls because nothing else is fast enough

Runtime is the only way to manage the speed and decision-making required in the age of agentic offensive operations. Inline enforcement before authentication completes is the only control that operates at the same speed as the attacker. That is what Silverfort was built to deliver, everywhere—from AD to AI.

The next step

Get ahead of Mythos.

Transform your identity layer into a control point. Learn how organizations are hardening their identity infrastructure against AI-powered attacks with runtime Identity Security.

Get your Mythos Readiness Guide by filling out the form below.