Book a demo call with us
Cross icon
Qevlar AI
Logo Qevlar
Cybersecurity

Attackers Give AI an Objective. Defenders Give It Alerts.

Attackers use AI to reason from intent to outcome. Defenders still optimize alerts. This article explains how objective-driven AI could reshape the SOC and cyber defense.

Shane Shook
Shane Shook
Venture Partner @ Forgepoint Capital, guest author
Attackers Give AI an Objective. Defenders Give It Alerts.

TL;DR

  • Attackers are using AI to reason toward objectives, not simply to automate individual stages of an attack
  • Most defensive AI is still focused on alerts, indicators, triage, and playbooks — an approach built around an increasingly outdated attack model.
  • Cyber defense should focus less on static “crown jewels” and more on key business processes whose value and exposure change over time.
  • Modeling those processes as dynamic graphs can help defenders understand which identities, systems, data, and relationships matter most at a given moment.
  • Defensive AI should evolve from a tool or assistant into an orchestrator that reasons about adversary intent, business exposure, and the controls needed to protect critical outcomes.
  • Success should ultimately be measured by whether important business processes remain intact and the attacker’s objective is denied, and not simply by how quickly alerts are closed.

Every serious intrusion I have investigated had a purpose that had nothing to do with computers. Someone wanted a competitor's formulation before it reached market, or wanted to trade ahead of an announcement, or intended to disrupt a supplier at the moment it would hurt most, redirect a payment, or hold operations hostage when the victim could least afford to refuse. The network was only the terrain on which those objectives were pursued.

‍

That distinction matters more now than at any time in my career, because attackers are using AI to reason their way to those objectives while most defenders are using AI to process signals faster.

Attackers Have Stopped Thinking in Stages

For two decades we have described attacks as a sequence of reconnaissance, initial access, exploitation, privilege escalation, lateral movement, collection and exfiltration. The model was useful because it described how human operators actually worked. Each stage required different skills, often different people, and time, and defenders found their best opportunities in the handoffs between stages.

‍

Anthropic's threat intelligence documents how quickly that is changing. In August 2025 it reported actors using agentic AI to perform attacks rather than merely advise the humans conducting them [1], and in November 2025 it described a suspected state-sponsored espionage campaign in which AI carried out most of the tactical work while humans stepped in at key decision points [2]. Its September 2026 report characterizes the trend, in Anthropic's phrase, as a move from assistant to orchestrator, with multi-agent systems executing large parts of an operation and workflows that rebuild their tooling after being detected [3]. Anthropic is careful to note that humans still retain the decisions that matter most to the operator, and that autonomy and severity are separate questions. The operating model has changed regardless.

‍

Speed is the least interesting part of this shift. When AI can reason from an objective to the actions required to achieve it, and adapt to the environment autonomously, reconnaissance, access and exploitation stop being distinct phases and become process automation in service of an outcome. The human sets the goal and reviews the results, and the AI works out and adapts the path in between. Far more of the distance between intent and outcome can now be delegated to a machine that reasons.

Defenders Remain Bound to an Obsolete Model

Most defensive AI is still organized around the old model, classifying alerts, enriching indicators, correlating events and running playbooks. Signal-specific detection and response is built around the stages attackers are abandoning. It asks what an event is and which step of the kill chain it represents. It does not ask what the activity is worth to someone trying to achieve an outcome against the business right now, or where the business is most vulnerable in its cycle at this moment, given what peer victims are experiencing and its own circumstances. The first question leads to a response, a remediation and a closed ticket. The other two produce an understanding of the adversary's intent and of the business's own exposure, and together they enable an adaptive defense.

‍

Speed is still necessary, though not sufficient. Machine-speed attackers compress the window between detection and damage, and a slow SOC will lose that race. An adversary that rebuilds its tooling after detection and changes its path as the environment changes will not be defeated by a defender running the same playbook faster, however. Accelerating an alert-centric workflow shortens each response cycle without changing what the cycle is for, and a faster SOC can remain just as predictable to the adversary as a slow one.

‍

For this reason, SOC metrics that are disconnected from business metrics are insufficient on their own. Mean time to detect, mean time to respond, case throughput and alert closure rates describe how efficiently the machinery runs, and they say nothing about whether the organization saw or stopped the activity that threatened its most material outcomes. They also start the clock in the wrong place. Detection latency begins when the business first becomes exposed and the adversary's activity first becomes observable, long before an analyst receives a case. Much of that interval passes unobserved, so a SOC can improve every one of its metrics while an adversary quietly achieves what it came for.

‍

A deeper blind spot sits in one of the most familiar concepts in our field.

Crown Jewels Shift With the Attacker's Intent

The idea of crown jewels came out of incident response. It originally described two things. The first was the points of compromise that gave an attacker control over the environment, such as domain controllers, identity stores and privileged credentials. The second was the key stores of value an attacker ultimately wanted, such as intellectual property, customer data and financial systems. As the concept was abstracted into security programs, crown jewels came to represent the single points of failure for defense, and most programs now begin by listing them and giving them the strongest protection.

‍

The underlying insight still holds, since single points of failure are where an attacker gains control or value. The weakness lies in how the list is built and maintained, because it assumes that value is fixed, and in practice it rarely is.

‍

Value is set by the attacker's intent, which is specific to time and place. Merger documents are extraordinarily valuable in the weeks before an announcement and worth far less afterward. A treasury approval workflow matters most at quarter close, a logistics scheduling system becomes critical during peak season or a shortage, and a research repository matters most before a patent filing or product launch. The same asset can be irrelevant on Monday and decisive on Friday.

‍

Attackers understand this because their objectives are economic. A defender protecting a static list of crown jewels is answering a question the adversary asked some time ago and has since moved past.

‍

The key business process is a better unit of defense. By that I mean the chain of people, identities, systems, data and suppliers that produces an outcome the business depends on. Because processes carry the dimension of time, they let defenders ask when a given process is most valuable to an adversary and what the adversary would need to control in order to exploit it.

Key Processes as Graphs

John Lambert of Microsoft made the point in 2015 that defenders think in lists while attackers think in graphs, and that attackers win as long as that remains true [4]. A key process can be modeled as a graph. Each identity, system, data store, integration and third party is a node, and each trust relationship, dependency or flow of data between them is an edge, with a strength set by what it carries.

‍

Certain core technologies hold the strongest edges in almost any environment. Directory services connect every identity to every resource it can reach, and data services connect every application to the information it depends on. These are the classic points of control, and they deserve the protection they receive. Viewing the graph only through node value, however, repeats the limitation of the crown jewels list, because it ranks the permanently strong nodes and overlooks how edge values evolve.

‍

Edge strength changes with the business cycle, and as it does, it connects associated nodes into paths that did not matter the week before. At quarter close, the edges linking a treasury approver's identity, the payment platform and a banking integration strengthen, and together they form the route to a fraudulent transfer. During a transaction, the edges between a deal team, a document repository and outside counsel strengthen in the same way. None of those nodes necessarily ranks highly on its own. Their significance comes from the edges that connect them at that moment, and an objective-driven attacker will reason along exactly those paths because they lead to the outcome.

‍

Mission dependency modeling has long weighted the edges between assets and business processes [5, 6]. What it has lacked is edge weights that move with the business cycle and with the intent of the adversary. A node's value at any moment is the sum of the values of its edges, and each edge's value depends on the business activity it carries at that point in the cycle, how easily an attacker can traverse it, and how far it advances a particular objective. The same node can therefore rank very differently for a fraudster, an extortionist or an espionage operator.

‍

Seeing the graph this way changes how defenses are organized. Graph controls can draw defensive perimeters around the edges that matter most to a process at a given moment, and around the nodes those edges connect, instead of around network segments drawn years ago. Adaptive controls then have somewhere precise to act. Moving target defense changes the configuration and addressing of those nodes so the attacker's reasoning rests on terrain that has shifted. Deception places convincing decoys along the strengthened paths, turning each interaction into high-fidelity evidence of intent. Conditional access governs the edges themselves, tightening the requirements to traverse a strong edge as the risk to its process rises, without shutting the process down. None of these controls is new. What AI adds is the ability to apply them through reasoning instead of static policy, so that a system which understands which process is in play, and which edges an adversary would need, can recommend or apply the right control at the right place and time.

‍

That reasoning should draw on more than one organization's view. Attackers pursue objectives across peer and competitor victims, and indicators seen in one environment reveal the pattern of an objective being pursued in another. Few enterprises can see that pattern on their own. Sector information-sharing groups provide part of the picture, and managed security providers that operate across many customers provide more, because activity that looks like noise in one environment becomes recognizable across a portfolio. Orange Cyberdefense, running SOC operations for many organizations, has a vantage point no single defender has, and its own account of its Qevlar partnership makes the point, noting that each qualified alert improves detection for all of its managed customers [7]. With that focus and that reasoning, signals become inputs to a defense that adapts, raising the attacker's cost at every step and denying the outcome before damage is done.

Give Defensive AI an Objective

Attackers have moved AI from assistant to orchestrator, and the SOC needs an equivalent progression. AI as a tool automates discrete tasks such as enrichment and triage. AI as an assistant investigates cases and recommends responses. AI as an orchestrator of defense reasons continuously about the adversary's likely intent and the business's current exposure, and organizes adaptive controls around the processes that matter. Most SOCs today sit between the first and second stages, while their adversaries already operate in the third.

‍

Vulnerabilities offer a practical test. The industry habitually treats a vulnerability as a patching problem, where discovery creates a remediation ticket and success means closing it. The association of vulnerability with patch is a non sequitur. It turns every finding into a demand on IT's change calendar and is a persistent source of tension between CISOs and CIOs, who have to weigh remediation against uptime, operational risk and business timing. Many vulnerabilities cannot be remediated quickly, and some never will be, particularly in legacy systems, operational technology, and critical dependencies that have to be defended as they are.

‍

Knowing about a vulnerability is valuable because it informs the graph. A newly identified weakness changes how easily an attacker can traverse the edges around a node, and therefore the exposure of every process those edges serve. Defenders then need to know which processes the asset serves, what an adversary would gain by exploiting it at this point in the business cycle, whether there is evidence of exploitation here or at peer victims, and how deception, conditional access, and configuration changes should be reorganized around it for as long as the exposure exists. Remediation remains the ideal end state where it is feasible, and a decision the business makes on its own terms. Defense proceeds regardless of when or whether it happens.

‍

Qevlar's Watchers capability shows part of this shift in practice [10]. For supported endpoint vulnerabilities affecting servers, workstations, and laptops that are awaiting remediation, the capability researches the vulnerability, assesses relevant exposure, and hunts for evidence of past exploitation. 

‍

It then deploys a Watcher with a monitoring mission that states what to watch, why, and until when, linked to the accepted risk, the affected assets, and an accountable owner. The Watcher runs on the telemetry the customer already collects, and it builds and maintains its own detection logic, schedule, and updates over time, so an analyst does not have to. It also reports its own health, so a quiet Watcher never hides lost coverage. When a Watcher finds something, Qevlar investigates with the customer’s context, and every investigation feeds better detection and new Watchers. Qevlar's detection is itself built on graphs, which suits the model described here.

‍

In effect, the defensive AI holds a standing objective, which is to know whether this weakness is being used against the business for as long as it awaits remediation. That continuous awareness is what the graph needs to reorganize adaptive defenses around the exposed node, so the exposure becomes a condition to be actively defended rather than the least-watched period between discovery and patch.

‍

This kind of delegation is already being tested in real operating environments. Orange Cyberdefense has been integrating Qevlar into its SOC operations since October 2025 to automate alert processing and qualification so that its experts can focus on higher-value work [7], and in September it hosted a discussion in Paris with Anthropic and Qevlar on how frontier models are changing both offense and defense [8,9]. Freeing human judgment from the mechanics of triage is the necessary first step, and directing that judgment toward objectives comes next.

‍

Human on the Loop

Human judgment remains central in this model, although its position changes. When AI is a tool, a human has to be in the loop, initiating and approving every intermediate step, and that does not scale against an adversary whose AI never waits. When AI is a resource partner, the human is on the loop. People define the objectives, the processes that matter, the constraints and permissions under which adaptive controls may act, and the escalation points where judgment, risk and accountability require a person. The AI carries out the continuous work between those decisions. Attackers have adopted the same division of labor, with humans choosing targets and reviewing results while AI reasons through the work in between.

What Should Defensive AI Be Accountable For?

If the answer is processing more alerts faster, defenders will optimize a SOC built for an attack model that is already fading while their adversaries work in an entirely different way.

‍

Defensive AI should instead be accountable for outcomes, which is also how attackers judge their own AI. The adversary's AI succeeds when its objective is achieved, and ours should succeed when that objective is denied.

‍

Measuring that requires different metrics. Instead of how quickly signals were processed, we should ask whether key processes stayed intact through their periods of peak value and exposure, how much cost, rework and delay we imposed on the adversary, and whether it achieved what it came for. These are business metrics, and a SOC that cannot express its performance in terms the business recognizes is measuring its own activity rather than its defense.

‍

Attackers have given AI an objective, and defenders need to do the same. With defensive AI used properly, the SOC should support an understanding of the adversary's intent and of the business's own exposure, and enable an adaptive defense.

References

1. Anthropic. "Detecting and countering misuse of AI: August 2025." August 27, 2025. https://www.anthropic.com/news/detecting-countering-misuse-aug-2025

2. Anthropic. "Disrupting the first reported AI-orchestrated cyber espionage campaign." November 13, 2025. https://www.anthropic.com/news/disrupting-AI-espionage

3. Anthropic. "Detecting and countering misuse of AI: September 2026." September 10, 2026. https://www.anthropic.com/threat-intelligence-report-september-2026

4. Lambert, J. "Defender Mindset." Microsoft Threat Intelligence Center blog, April 26, 2015. https://learn.microsoft.com/en-us/archive/blogs/johnla

5. Heinbockel, W., Noel, S. and Curbo, J. "Mission Dependency Modeling for Cyber Situational Awareness." NATO STO-MP-IST-148, The MITRE Corporation, 2016. https://www.sto.nato.int/publications/STO%20Meeting%20Proceedings/STO-MP-IST-148/MP-IST-148-05.pdf

6. Holsopple, J. and Yang, S. J. "Handling Temporal and Functional Changes for Mission Impact Assessment." IEEE CogSIMA, 2013, pp. 212–219. 

7. Orange. "Orange Cyberdefense Enhances Its Detection Capabilities with Qevlar AI's Artificial Intelligence Solution." Press release, October 6, 2025. https://www.orange.com/en/press-release/ocd-qevlar-334578-334578

8. Orange Cyberdefense. Frontier AI discussion with Anthropic and Qevlar AI, Paris, September 17, 2026. [URL to be supplied by Qevlar] 

9. Qevlar AI. "Orange Cyberdefense Enhances Its Detection Capabilities with Qevlar AI's Solution." October 6, 2025. https://www.qevlar.com/post/orange-cyberdefense-enhances-its-detection-capabilities-with-qevlar-ais-solution

‍

Published on
October 7, 2026
Updated on
October 7, 2026
Table of content
H2 toc

See how much of your manual workload can be automated