AI
I have been both watching/listening and in meetings where I have heard some ‘interesting’ statements about ‘machine speed’ hacking by with unlimited capacity and unlimited speed….
You can, if you know me, imagine my expression on my face, however I figured let’s not settle for ‘Trust me bro it doesn’t work like that’, let’s do some SCIENCE!
(I know everyone loves scientists these days after they pluck numbers out of their ass and say things like: there is a 10-70% chance AI will destroy humanity in the next 5 years’ (and have zero evidence for the math let alone evidence for the risk model other than ‘trust me, I’m super smart’).
I’m not that smart so I do actual testing of theories, and then I share things, I know, I’d make a terrible ‘scientist’. It’s hot in the lab today so this will be a quite a brief view but should contain the key details.
The LAB
Ok the theme here is… DEUS EX, It couldn’t really be any other! So in the lab I’ve deployed an Active Directory domain: Unatco.local
The attacker was armed with a network adjacent unauthenticated position, with Claude OPUS 4.8 (and CVP) (on a Workgroup Windows machine, WSL+Kali was already available so if it wasn’t that would be more time or possible detection)
The kill chain
With great unlimited speed, comes great unlimited responsibility: (/S)

The Flow

The NetDraw Diagram
I’ve added this diagram (With a Journey) to https://mr-r3b00t.github.io/net_draw/

The Proof
A flag was dropped on both domain controllers c:\flag.txt

The SOC
We observed but we did not take action (or it would have been a very boring blog/experiment)

Observations
This went quite well, the agent/LLM model was not given any special instructions of skills. The agent (computer program) was prompted with a GOAL and it completed the computing task that a human set it (me).
Summary
From a shell with no access other than internet and local admin to DA in 52 minutes, sounds fast… but I’ve done similar in <60 seconds using a batch file before… the kill chain here abused ESC 8 which requires a request to another server then a relay to an ADCS server, so the setup for the infra for that is a bit fiddly.
But what we can see here:
- Machine speed doesn’t make sense, computer, network and environment speed would.
- This was not any different to what a human can do in terms of outcome, method and execution clearly was, but the attacker packets were just the same as if I had loaded Metasploit etc.
This lab is heavily monitored, it’s a network inside a network, with physical separation (dual firewalls, IPs), there’s very good observability here, much more than say the AI ‘LABS’ had in their experiments where third party organisations were compromised. (funny that).
The lab’s configuration was similar to many orgs I’ve seen in the real world! A lot of active directories are really not very well configured/managed/secured.
Hopefully this brief blog is useful, I’ll try expand on this later and the science will continue!







