Ingest
Logs, packets, endpoint telemetry, identity events. Normalised to a common schema. Time-aligned across every source.
How artificial intelligence is reshaping both attack and defense – and what you need to know right now.
What an AI-native defense platform does between the first packet of an attack and the moment it’s contained.
Logs, packets, endpoint telemetry, identity events. Normalised to a common schema. Time-aligned across every source.
A model trained on labelled incidents assigns a confidence score to each chain of events. False-positive rates are calibrated weekly.
Above the threshold, contain. Below it, alert. The boundary is auditable, versioned, and explainable to a regulator.
Isolate the host. Revoke the token. Quarantine the inbox. The response playbook runs autonomously inside a documented blast radius.
Most vendor claims about "AI-powered security" collapse into one of two categories: statistical anomaly detection that has existed since the 2000s rebranded with a new label, or a genuine large-language-model layer that reads, summarizes, and drafts. The second category is what changed in 2024-2026, and it changed both sides of the fight at the same time, which is why the honest answer to "is AI winning for attackers or defenders" is neither, yet.
The offensive use cases that show up in real incident reports are unglamorous. Phishing emails no longer have the broken grammar that used to be a reliable tell: a model can localize a lure into fluent Spanish, French, or German in seconds. Reconnaissance that used to take an analyst a day of manual OSINT (organization charts, vendor relationships, employee LinkedIn profiles) can be scraped and summarized in minutes. Voice cloning from a 30-second sample has made "urgent call from the CEO" scams cheap to run at scale. None of this is a new attack technique: it is the same social engineering and phishing playbook that has worked for twenty years, just cheaper and more convincing to produce.
What has not materialized yet, despite the headlines, is autonomous AI malware that discovers and exploits zero-days on its own without a human operator in the loop. Every documented "AI-assisted" intrusion still has a human deciding what to do with the model's output.
On the blue-team side, the highest-value use case is not detection: it is triage. A mid-size SOC can generate thousands of alerts a day; the median analyst spends most of a shift closing false positives rather than investigating real ones. A model that reads an alert, pulls the relevant logs, and drafts a one-paragraph summary of what probably happened cuts that triage time meaningfully, even when a human still makes the final call. Detection engines that flag behavioral anomalies (a service account authenticating from a new country at 3 a.m.) are a genuine improvement over static signature matching, but they trade false negatives for a different kind of false positive, and tuning that trade-off is still a manual, ongoing job.
| Use case | Offensive value | Defensive value |
|---|---|---|
| Content generation | Fluent phishing lures, deepfake voice/video | Auto-drafted incident summaries and reports |
| Pattern recognition | Faster target reconnaissance from public data | Behavioral anomaly detection over static rules |
| Automation | Scaling personalized scams cheaply | Alert triage and first-pass log correlation |
| Current ceiling | Still needs a human to weaponize output | Still needs a human to approve containment |
For most people outside a security team, the practical takeaway is narrower than the marketing suggests: assume that any unsolicited message – email, text, or voice call – asking you to move money, click a link, or "verify" a login can no longer be screened by tone or grammar. Verify through a second channel you already trust (call the person back on a known number, not one they just gave you) rather than trusting how polished the request sounds.
Daniel A. and Óscar S. run Breachfolio, a small independent site about security and AI. This page was drafted with AI assistance and reviewed by a person before it went live. We write from documentation, vendor sources and published research rather than from original lab benchmarks, and we link a source in the sentence that relies on it. How we work · About us
We read every message – corrections, tips for a future comparison, or just feedback on this page.