Sophos Red Team reported that its OpenClaw agentic AI system successfully conducted a controlled, noisy penetration test against a legacy on-premises production network under strict safety controls. The team said it limited prompt injection, data exfiltration, and destructive behavior through tightly managed ingress and egress controls, custom in-house skills, and a lightweight human approval process rather than exposing the agent to public external skills. During the exercise, OpenClaw remained within its configured boundaries and produced a detailed audit trail that simplified reporting.
The test significantly accelerated offensive security work, cutting Active Directory reconnaissance from roughly three days to three hours and generating 23 actionable findings on the internal network. Sophos said the agent also demonstrated autonomy by proposing an alternate attack path that used an authorized EC2 GPU instance to crack a captured hash, showing how AI systems can extend operator capabilities while still requiring oversight. The company concluded that agentic AI already presents meaningful security implications and is likely to become an important tool for defenders that can deploy it safely.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
As part of the test, the agent autonomously suggested an alternative attack path involving use of an EC2 GPU instance to crack a captured hash after receiving authorization, demonstrating higher operational autonomy within the approved guardrails.
During the exercise, OpenClaw stayed within configured boundaries, reduced Active Directory reconnaissance time from roughly three days to three hours, and generated 23 actionable findings with a detailed audit trail for reporting.
Sophos Red Team conducted a controlled experiment using the OpenClaw agentic AI system against a legacy on-premises production network, with strict ingress/egress controls, custom in-house skills, and human approval checkpoints to limit risk.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.