Two separate research efforts describe using AI to accelerate and operationalize offensive security workflows for defenders. Pacific Northwest National Laboratory presented ALOHA (Agentic LLMs for Offensive Heuristic Automation), an AI-based system intended to reconstruct real-world attacks from threat reports and generate variants for testing an organization’s defenses, with the stated goal of reducing attack recreation and validation cycles from weeks to hours. The work is positioned as enabling faster threat emulation so security teams can more quickly verify whether detections and controls catch newly disclosed techniques.
A different academic/industry team (Alias Robotics and Johannes Kepler University Linz) proposed Generative Cut-the-Rope (G-CTR), which combines AI-driven penetration testing with game theory to turn high-volume AI security testing logs into structured attack graphs and compute optimal attacker/defender strategies (e.g., via Nash equilibria). The authors claim the approach can convert unstructured outputs into actionable guidance in seconds, addressing the common operational problem that automated testing tools generate more data than teams can interpret strategically.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Pacific Northwest National Laboratory described ALOHA (Agentic LLMs for Offensive Heuristic Automation), an AI system that ingests threat reports, reconstructs likely attack chains, and executes emulations in test environments to validate detections. PNNL said the system can cut attack reconstruction and validation time from weeks to hours and help generate mitigations and tune defensive tools through iterative purple-team testing.
Researchers from Alias Robotics and Johannes Kepler University Linz presented Generative Cut-the-Rope (G-CTR), an automated penetration-testing framework that turns AI security logs into attack graphs, computes Nash equilibria, and feeds optimized attacker and defender guidance back into agent execution. In reported cyber-range and real-world exercises, the system improved success probability, reduced cost and variance, and produced attack graphs that closely matched expert annotations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.