Threat Intelligence · June 2026
The Mythos
Field Report
We saw how Anthropic's Mythos worked its way through real enterprise environments. This is what we found—and what actually stopped AI-powered attacks.
Scroll for our findings or grab the Mythos Readiness Kit and take it straight to your C-suite.
~2hrs
From first access to full cross-domain compromise
AI-powered attack playbooks execute at a speed that leaves no realistic window for human response.
What we found: Mythos Field Report Key Findings
Six findings every security and identity leader needs to see
These six insights aren't theoretical. They come from running Mythos against enterprise environments and seeing which controls finally stopped it.
01
AI-powered attacks run through identity
Mythos doesn't always need a CVE. In some cases, it discovered, planned, and chained existing trusted accounts, crossing domains, using misconfigurations (like reused credentials, over-privileged accounts, and weak auth flows) into full domain compromise in under two hours.
02
Active Directory and on-prem infrastructure is a primary target
Mythos targets on-prem infrastructure and Active Directory specifically. We saw it exploit RC4 weaknesses, weak certificates, and misconfigured domain controls. It understands that taking over Active Directory is how you win, and it works methodically toward that goal.
03
The math of vulnerability management doesn't hold
When organizations scan with Mythos, they find thousands of vulnerabilities, making a patching race unrealistic. Even if you could patch, AI models still need to move, access resources, and traverse networks. When they do, they use identities and access.
04
Static IGA breaks down entirely
AI-powered attacks move faster and adapt in ways that pre-configured rules simply can't anticipate. AI agents are ephemeral, multi-identity, and non-deterministic. Governance matters, but periodic reviews can no longer be a primary control.
05
Detection had no realistic human-based response window
With breakout times measured in minutes, detection comes too late. Mythos runs multiple attack vectors simultaneously, making noise in one area while moving laterally in another. By the time you respond, it's already dumped credentials and moved on. You're responding to where it was, not where it is.
06
Service accounts and machine identities are frequently the #1 target
Non-human identities carry privileged access, often with no behavioral baseline or compensating controls. In one example, a service account was regularly abused for privilege escalation—until virtual fencing on that single account prevented full domain compromise.
What actually stopped it
Inline, runtime identity controls stop attacks cold
What Mythos showed us was simple: AI-powered attackers move faster than traditional security workflows can respond. In this environment, the controls that proved effective were the ones operating directly in the authentication flow, before access was granted.
The runtime approach made the difference. Enforcement was inline, before lateral movement or privilege escalation could begin.
"Oh s#$t! We need to shut down Silverfort because we can't run the drill."
Red teamer
On Silverfort preventing a Mythos-based red team exercise
The fix
Three controls that actually stop AI-powered attacks
All three share a defining characteristic: they operate inline, at the moment of authentication, before access is granted. Because runtime beats reactive every time.
01
Protect high-risk access with step-up authentication
AI-powered attackers thrive on valid credentials and excessive privileges. Adaptive authentication combines step-up MFA, risk-based access policies, and Just-in-Time (JIT) access. Access decisions adapt in real time to protect privileged access when risk appears, without introducing unnecessary friction across the business.
Key lesson: Static policies age badly. Access decisions should adapt in real time as fast as attackers do.
02
Most effective
Virtually fence service accounts without breaking critical processes
Service accounts are one of the fastest paths to privilege escalation—and one of the hardest risks to fix. Most organizations know which accounts worry them, but fear breaking critical processes. Virtual fencing removes that tradeoff by restricting where and how service accounts can be used, without changing how they operate.
“The best control, through and through, was service account fencing. It took a known path to domain compromise and made it unusable.” — Security Operations Leader
03
Contain attacks through identity segmentation
Attackers only need one compromised identity. They need many trusted paths to turn it into a breach. Identity segmentation limits where compromised accounts can go, reducing lateral movement and preventing small compromises from becoming business interruptions.
Key lesson: Stopping every compromise is unrealistic. Preventing attackers from turning one compromised identity into many is what limits business impact.
Foundation
Strengthen chains of trust
AI-powered attackers don't invent new paths. They find the shortest existing ones. Weak trust relationships, excessive permissions, and poorly protected authentication flows create direct routes to privilege escalation and critical systems.
Strengthening chains of trust removes those shortcuts before attackers can exploit them, reducing risk before runtime controls ever need to engage.
"Silverfort is phenomenal. It blocked Mythos' attempts to spread in the network. At some point, we had to disable Silverfort's defenses to allow further testing."
— Security operations leader
Are you ready for ai-powered attacks?
What this means for your role
The attack chains haven't changed. The speed has. What that means for you depends on where you sit.
The board is asking if you're prepared for AI-powered attacks. The honest answer: you need an additional control point that works at AI-speed.
Your identity infrastructure is the primary target and the last line of defense
Attackers always go for the path of least resistance, and AI-powered attackers are no different. In the Mythos exercise, identity was the path to lateral movement, privilege escalation, and critical systems. As attacks become more autonomous, identity resilience is no longer just another control layer—it's often the last thing standing between compromise and impact.
"Assume breach" was always true. AI has now raised the stakes.
Credentials will be compromised and misconfigurations will exist. That's not new. What has changed is the speed at which AI-powered attackers can find and exploit them. The question is no longer whether attackers get in, but how quickly you stop them from going further.
Your controls assume time. AI-powered attacks remove it.
Governance and vulnerability management remain essential, but they operate on admin and remediation timelines. Detection is critical, but by definition, it begins after suspicious activity has already occurred. AI-powered attacks compress the gap between compromise and impact, leaving little time for human response. You need controls that can stop risky access inline, before it becomes a business disruption.
The answer
Identity can be a credible control point
Every step where ordinary access becomes material business impact—lateral movement, privilege escalation, data exfiltration—has to cross the identity layer. Controlling that crossing at runtime is the architecture that actually holds against AI-speed attacks.

Mythos transformed known identity gaps from theoretical risk into operational reality. Use it to elevate identity from a management function to a frontline security control.
Service accounts and machine identities are a top target
Offensive AI agents authenticate with over-privileged accounts—their actions are unattributed and their behavior is baselined against nothing. In one example where Mythos was used, virtual fencing on a single service account prevented full domain compromise. That account had been abused in every prior red team engagement.
Mythos will exploit your AD posture
A single Active Directory misconfiguration creates an average of 109 shadow admin accounts. Nearly 1 in 3 AD accounts is a highly privileged service account, and 67% of organizations sync AD passwords to the cloud. AI-powered attackers excel at finding and chaining these exposures into a path to privilege escalation.
MFA gaps on legacy and homegrown systems are no longer acceptable
Every authentication flow without strong controls becomes a credential abuse opportunity. Legacy protocols like NTLM and unmanaged authentication paths create blind spots attackers exploit. Extending MFA to every authentication flow and resource, while deprecating NTLM, significantly reduces the available attack surface.
The answer
Inline, runtime access controls stop attacks cold
Adaptive authentication with step-up MFA, Just-in-Time access, service account virtual fencing, and identity segmentation proved capable of stopping Mythos-powered attacks. By enforcing controls at the moment of authentication, organizations can block lateral movement and privilege escalation paths that AI-powered attackers depend on.

Your environment by the numbers
109
Shadow admin accounts from a single AD misconfiguration
67%
Of orgs sync AD passwords to cloud, turning on-prem compromise to cloud compromise
37%
of admins authenticate in NTLM, enabling attackers to access cleartext passwords.
1 in 3
Accounts are highly privileged service accounts—and most are unmonitored
Inside Anthropic's Mythos
Mythos in the wild: how a full domain compromise unfolds without runtime controls
This is a composite of red team engagements with no novel techniques and very few zero-days. It's mostly identity posture issues that exist in virtually every enterprise, chained at machine speed.
Step 01
Initial low level access
The model and derivative agents gained a workable path through a combination of posture gaps and over-permissioned identities to get to domain access.
Step 02
Gain elevated permissions
Over-privileged service accounts and reused credentials were identified and exploited. First elevated permissions obtained. Still inside the lab environment.
Step 03
Escape testing and make it into production
Lab boundary crossed. Mythos chained misconfigured trust relationships to move laterally into the production environment.
Step 04
Escalate privilege
Two additional privilege escalation hops, chaining ESC1 misconfigurations and shadow admin accounts. Domain Administrator access obtained.
Step 05
Move laterally using service accounts
Service accounts and identity infrastructure targeted to complete attack.
Step 06
Gain domain access to infrastructure
Pull production password hashes through a directory replication attack.

The case for runtime identity security
Three things that are now true
01
Traditional security controls are collapsing
CVEs will keep being issued. Patches will keep shipping. Detection tools will keep firing alerts. But none of that is fast enough to stop an AI-powered attack from achieving full domain compromise using misconfigurations and credentials that already exist in your environment. The assumptions these controls were built on no longer hold.
02
Identity is now the control point
Identity isn't just a control point—it's the control point. To move laterally, escalate privileges, access sensitive data, or reach critical systems, attackers must cross identity boundaries. That's why runtime identity controls have become one of the most effective ways to contain attacks before they become business disruptions.
03
AI-powered attacks require runtime controls because nothing else is fast enough
Runtime is the only way to manage the speed and decision-making required in the age of agentic offensive operations. Inline enforcement before authentication completes is the only control that operates at the same speed as the attacker. That is what Silverfort was built to deliver, everywhere—from AD to AI.
The next step
Get ahead of Mythos.
Transform your identity layer into a control point. Learn how organizations are hardening their identity infrastructure against AI-powered attacks with runtime Identity Security.