Agentic Threat Prevention turns attack evidence into targeted blocks

Suspicious activity can change what a system is allowed to do next. Agentic Threat Prevention connects the assessment of an ongoing attack with targeted controls enforced directly in network traffic. This gives the security team visibility into both the reasoning behind a decision and the resulting intervention.

In our latest article on agentic attacks, we looked at an adversary that adapts its approach to the controls it encounters. In a controlled test, an agent progressed from external access to domain administrator privileges in 40 minutes.

That figure is a test result, not a universal deadline for defenders. It shows how quickly familiar attack stages can be carried out in sequence.

Agentic Threat Prevention tracks that progression from the defence side. When activity indicates an attack, the assessment can lead to new restrictions on the affected system. Those restrictions apply when the attacker attempts to move forward.

The server’s activity changes the conditions

A server that contacts known command-and-control infrastructure can be blocked from downloading executable files from cloud services. That contact becomes part of the basis for restricting a subsequent action.

Another example is internal network discovery combined with suspicious external communications. Here, the defence can automatically activate controls against connections the attacker uses for lateral movement.

Both examples show how context is used. A system’s recent activity influences the controls applied to it. Protection can therefore change as the attack develops, targeting specific actions further along the attack chain.

From observations to a reasoned decision

The mechanism consists of an agentic decision layer and conditional controls enforced inline.

The decision layer continuously gathers telemetry and examines the relationships between activities on individual systems. It assesses whether the observations, taken together, indicate an attack in progress and whether a system should be subject to stricter controls.

The process includes normalising signals, evaluating independent observations and checking for false positives. The sequence and context of the actions inform the assessment. The decision is justified by reference to the observations that support it.

When the evidence supports intervention, the agentic layer selects a prevention policy and activates the relevant controls. The security engine then enforces the restriction when the system attempts the action covered by that policy.

Security researchers define and maintain the policies. The agentic layer determines when to apply them based on the system’s current behaviour. The security controls carry out the actual blocking.

This creates a clear division of responsibilities between defining the protection, continuously assessing activity and enforcing restrictions in network traffic.

The demonstration showed an attack being restricted as it progressed

In a controlled vendor demonstration, an agentic attacker was tested against Agentic Threat Prevention.

The scenario began with the exploitation of a vulnerability on a publicly accessible server. The attack chain then included internal discovery, privilege escalation and lateral movement towards full domain compromise.

The defence detected the activity and activated controls as the attack progressed. The attacker did not achieve its objective.

The management interface brought together findings, supporting observations, activated controls and the status of the restrictions. These included controls targeting Active Directory queries and SMB-based lateral movement.

This allowed the security team to follow both the attack’s progression and the technical interventions. The interface showed which controls had been activated and what effect had been recorded.

The demonstration documents a scenario in which the protection prevented full domain compromise. The result applies to the environment shown and does not guarantee the same outcome in every attack.

Prevention becomes visible as the attack unfolds

The Hugging Face incident showed an autonomous agent framework gaining code execution, retrieving credentials and moving into internal clusters through thousands of actions. It illustrates the attack pattern the defence needs to be able to track. The incident does not demonstrate the effectiveness of Agentic Threat Prevention.

The solution described relies on a unified SASE architecture with traffic visibility and shared context across controls. The decision layer uses that information to assess activity and activate targeted protection as the attack progresses.

For CISOs, the value is a concrete understanding of how prevention is carried out. Observations support a reasoned assessment, which triggers a specific policy. That policy is enforced in network traffic, and the intervention is recorded.

This makes it possible to trace why a system was placed under a restriction and what that restriction actually prevented. In the demonstration, that connection could be followed through to the outcome: the attacker did not achieve full domain compromise.

‍