AI Is Rewriting The Adversary Playbook; Defense Must Adapt

Direct Source Verification: This story is aggregated from Forbes (forbes.com). Full reporting rights and copyright belong to the primary publisher.
Your environment and the behaviors any attacker must run to cross it have not changed. That is where defense must focus.

Jon Baker is VP, Threat-Informed Defense at AttackIQ.

gettyFor decades, cyber threat intelligence has understood the adversary as a person: a human operator with a particular set of knowledge, skills and abilities, who reaches for the techniques they know. That assumption underpins much of how we defend. It is why we profile threat actors, track their preferred tradecraft and build detection around the playbooks specific groups run. Humans leave predictable patterns.

AI is dissolving that predictability. As adversaries adopt AI, they grow more sophisticated than their own skills would allow, and their playbooks become more diverse than any operator’s experience could produce. A defense built on knowing who is likely to attack you, and how they tend to work, is standing on ground that is starting to move.

Verizon’s “2026 Data Breach Investigations Report“ (subscription required) found that AI’s impact is operational: It speeds up known techniques rather than creating new ones. The median actor sought help for roughly 15 distinct MITRE ATT&CK techniques, and fewer than 2.5% were rare. Anthropic, which supplied data for the analysis, published a mapping of a year of AI-enabled attacks onto ATT&CK. Every observed behavior mapped to the existing framework. These are well-trodden paths, run faster.

AI expands adversary capability in two directions. Horizontally, it widens access. Any actor can now reach the full catalog of known techniques. They are no longer bound by what one operator happens to know. Vertically, it deepens variation. Where a technique allows many different procedures, AI generates new ones cheaply, faster than procedure-based detection can track.

The predictability we lost was in the human. The set of behaviors has not grown. AI simply gives adversaries fast access to all known behaviors and the ability to rapidly create new procedures. What stays fixed is the terrain. Your environment and the behaviors any attacker must run to cross it have not changed. That is where defense must focus.

Not every technique carries equal weight. Some are chokepoints: techniques where many others converge or diverge, so a wide range of otherwise different attacks all route through them. Process injection is the classic example. Many techniques lead into it, many follow from it and defending that one technique disrupts many attack paths at once.

AI does not move the chokepoints. An attacker who reaches the full catalog and generates endless new procedures still funnels through them. They sit on your terrain, fixed by how an attack must reach your critical assets, not by the attacker’s imagination.

That is what makes them defensible. You cannot predict the path, but you can find the chokepoints every route to your crown jewels runs through and concentrate detection there. A short list of them accounts for a broad spectrum of attacks.

The vertical problem, cheap new procedures, is a detection problem. Anchor a detection on something an adversary changes easily, a file hash, a command string or one tool’s signature, and the next procedure evades it. AI makes that failure routine because producing a fresh procedure for a known technique is now trivial.

The fix is to anchor detection on what cannot change. MITRE’s Summiting the Pyramid methodology scores a detection by its robustness against evasion. Tie a detection to ephemeral values an adversary changes at will, and it scores low, allowing a new procedure to slip past. Tie the detection to the behavior at the core of the technique, and it scores high, holding across procedures. It gives detection engineers a way to grade their analytics and level up the weak ones.

A detection that survives new procedures is worth more than 10 that a single new one evades. Build for that, and you stop rebuilding coverage every time an attacker changes a detail.

Chokepoints and invariants point to three moves for defenders.

Assess your defenses against the behaviors adversaries cannot easily change, the chokepoints and the invariants, and raise your detections and controls to orient on them.

Prioritize detection coverage by your terrain, your business context and your chokepoints—the techniques where many attack paths converge—so one defense covers many routes. Orient coverage around disrupting the paths to your critical assets.

Prove your controls against many procedures for each behavior, not one canonical procedure. A control tested against a single procedure tells you nothing about the next. Broad, continuous validation is how you find where you are exposed before an adversary does and confirm your defenses continue to operate as intended.

Defenders must run the evaluate, elevate and validate cycle at the pace the adversary sets. When any actor can reach the whole catalog and readily generate a new procedure, a program that evaluates itself once a quarter is already behind.

AI has changed the economics of offense. Defenders need to use it to change the economics of defense. Generating the procedures to validate against, drafting candidate detections and scoring them for robustness can all be automated at scale, which is what lets the loop run continuously rather than periodically. Engineers stay in the decision seat: which behaviors matter, which paths.

It must be continuous for two reasons. Detections decay and need constant validation to confirm they still fire as intended. And the terrain keeps moving, surfacing new gaps and techniques faster than any point-in-time assessment can catch. Each gap becomes a new detection, elevated and validated, and the loop turns again.

AI may make the adversary less predictable. It does not make defense unknowable. The advantage will go to defenders who stop trying to predict every procedure an attacker might invent and instead build around what attackers cannot avoid: the behaviors they must execute, the chokepoints they must cross and the terrain they must traverse. The path is clear. Whether defenders can turn that loop fast enough to keep pace is the open question.​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Original Source
https://www.forbes.com/councils/forbestechcouncil/2026/09/11/ai-is-rewriting-the-adversary-playbook-defense-must-adapt/
Visit Forbes ↗
SHARE STORY:
𝕏 f in

Related Coverage in Defense