Skip to main content
Mallory is a Black Hat USA 2026 Startup Spotlight finalistBooth #5803 · Startup CitySee the details
Mallory
Adversary Timelines Have Collapsed: Defenders Must Rethink Proactive Security with Agents
Back to BlogAnnouncements

Adversary Timelines Have Collapsed: Defenders Must Rethink Proactive Security with Agents

Jonathan CranAugust 4, 20264 min read

I've spent my career on one side of a simple question: what can an adversary see, and how fast can they act on it? At Intrigue, at Mandiant, at Kenna, Bugcrowd, and Rapid7 before that, the answer kept changing, but it changed at human speed. A new vulnerability dropped, researchers dug in, exploit code circulated, and defenders had a window measured in days or weeks to get ahead of it.

That window is gone. AI has collapsed the cost and time of finding exploitable flaws. What used to require a skilled researcher and a few weeks now takes a model and a few hours. When a working exploit can land the same day a weakness becomes known, the entire rhythm defenders build their programs around (scan, score, ticket, patch) stops making sense. The clock those tools were designed for no longer exists.

Intelligence was never the problem

Security teams are not short on intelligence. They are drowning in it. Threat feeds, vulnerability scanners, attack surface tools, and cloud posture products all do their jobs, and the result is a thousand-item backlog ranked by a severity score that has no idea who is attacking you.

That is the real gap in security operations today. Call it the context-action gap: the distance between everything your tools can tell you and the handful of things your team can actually act on this week. Every hour an analyst spends manually correlating a new CVE against your environment, or pivoting between a threat report and an asset inventory, is an hour the adversary's timeline no longer grants you.

Point tools can't close that gap, because it sits underneath them. Hunting threats, prioritizing exposures, and building detections all start from the same raw material: stories, TTPs, vulnerabilities, and IOCs, correlated against what you actually run. Today that correlation happens in an analyst's head, across three tools, one investigation at a time. The intelligence is shared. The work shouldn't take three products and a swivel chair.

Why now is different

Here's the part that keeps me optimistic. The same shift that armed attackers also handed defenders something genuinely new: reasoning systems that can do the analyst correlation step at machine speed, on a standing basis, across everything at once.

But speed alone isn't the answer, and neither is autonomy for its own sake. An agent that acts without context creates noise. An agent that acts without governance creates risk. For AI to actually carry the load in a security program, three things have to exist together: context that unifies attack surface, threat, and vulnerability intelligence into one picture; reasoning that determines whether a given signal reaches your environment and how much it matters given live adversary activity; and policy that keeps every action scoped, auditable, and under your rules.

Miss any one of the three, and you get what the market has plenty of already: chatbots bolted onto old queues, or automation nobody trusts enough to turn on.

How Mallory is built to close it

This is the thesis behind Mallory, and behind the architecture we're introducing this week: a unified context and intelligence layer built from the ground up to feed action.

Mallory is architected around a context graph, fusing your entire attack surface with current threat and vulnerability intelligence, so every new CVE or adversary technique is checked against your actual exposure in minutes. A reasoning layer, the agentic harness, determines what matters and why, anchored to who is actually attacking you, not a static score. A policy and governance layer lets your team decide exactly how much autonomy the agents get, from routing a prioritized case into the ticketing tool you already use to handing routine exposure remediation to agents at scale.

The layers are fully separable on purpose. Some teams want a contextual intelligence source feeding workflows they already trust. Others are ready to let agents carry routine work end to end. Both run on the same context and reasoning underneath. What changes is how far your policy layer lets it go.

Mallory platform architecture diagram showing the Context Graph and Agentic Harness sitting between a Medallion Data Lake and a Governance and Policy layer, fed by threat intelligence and attack surface collection, and powering use cases like exposure investigation, supply-chain risk, threat hunting, and vulnerability prioritization.
Context and reasoning sit in the middle, wrapped in governance, with policy controlling how far agents can act.

Adversaries got faster, and they got cheaper this year. Matching them is about closing the distance between knowing and acting, once, at the layer where the work actually happens.

Understand the threat. Eliminate exposure. It's time our architecture reflected it.

- jcran

Prioritize with context. Act with governance.

Mallory unifies your attack surface with live threat and vulnerability intelligence, then lets your team decide how far agents can act on it.

Start Free Trial