AI-Speed Attacks Meet Preemptive Defense
Sevii's new module autonomously remediates AI-driven attacks at machine speed.
As organizations deploy more AI tools, attackers are using the same technology to strike faster than humans can respond. Sevii, a security firm, is countering with an AI module that not only detects threats but also acts on them instantly, without waiting for a human analyst.
Autonomous Defense and Remediation Platform Expands
Sevii has extended its Autonomous Defense & Remediation (ADR) platform with a new module designed to handle the speed and scale of AI-driven attacks. According to the company, the module receives alerts from a customer's entire security detection stack, ingests them in real-time, and analyzes them. While existing tools detect attacks and report them to security operations centers (SOCs), Sevii's new module intercepts that reporting and responds instantly and autonomously.
Seven-Day Retrospective Hunt
The module uses AI agents, which Sevii calls 'cyber warriors,' to conduct a seven-day retrospective context hunt. This hunt determines whether a detected action is normal or abnormal, helping confirm if it's a genuine AI attack. If confirmed, the agents search for similar attack patterns elsewhere in the infrastructure, assessing whether the attack is broader than initially detected and whether immediate remediation is needed.
"When we get the AIDR detection, we start the action to determine whether it is good or bad from policy, or is it acting in the fairest way," explained Sevii's CEO and co-founder, Curt Aubley. "We immediately collect all the data we need. We call it a hunt. We grab all that data and analyze it to be able reverse engineer the attack and take any necessary action."
Human-in-the-Loop: A Marketing Comforter?
Remediation can be autonomous or triggered by a human defender, but Sevii suggests the human option is often a formality. "Having a human in the loop may be required by today's governance policy. But consider the damage and speed at which OpenAI rogue agents attacked Hugging Face," commented Aubley. "Seventeen seven-minute actions. It's mathematically impossible for a human to keep up with that."
"Having a human in the loop may be required by today's governance policy. But consider the damage and speed at which OpenAI rogue agents attacked Hugging Face," commented Aubley. "Seventeen seven-minute actions. It's mathematically impossible for a human to keep up with that."
— Curt Aubley, CEO and co-founder, Sevii
Immediate Remediation in Action
Sevii's remediation can be immediate. During its context-gathering, the system may detect a high volume of data leaving a customer's network. It then performs an instant intelligence search to check if the data transfer is standard, where it's going, and whether the destination is a known command-and-control (C2) server or otherwise malicious. The company says it already knows if a destination has been flagged as bad within the last 15 minutes.
If data is being sent to a dangerous location, "We will absolutely immediately stop that activity and autonomously do an impact analysis as well to see what data left and how quickly we stopped it," said Aubley.
Example: Compromised Laptop
To illustrate the process, Aubley described a scenario where an employee's laptop is compromised. The module detects the compromise, hunts for context, and validates the detection. If confirmed, it isolates the laptop, disables the user's account, removes active sessions, and forces a password reset. It then securely connects to the laptop to remove malicious processes and registry entries, before removing isolation, performing a final validation, and releasing the system back to the customer.
"We will isolate the laptop and disable the account, remove those sessions from that account, and force the person to reset their password. So, first the identity portion is stopped, so the adversary can no longer log into these other systems. That stops the spread. We securely connect to the laptop and remove the bad processes and registries and things of that nature," he continued. "Once done, we remove the isolation. We do a final validation, and we watch that system to make sure that it is not acting strangely anymore. If satisfied, we release it back to the customer."
Speed of Response
The complete AI-driven autonomous process typically takes between two and fifteen minutes. This contrasts with AI attacks, which Sevii says typically take between 30 seconds and 30 minutes to execute. The company positions the module as a way to fight fire with fire, matching machine speed with machine speed.
- Remediation time: 2–15 minutes
- AI attack duration: 30 seconds to 30 minutes
- Hugging Face attack: 17 actions, each 7 minutes
- Context hunt: 7-day retrospective
Why It Matters for Security Teams
The emergence of AI-driven attacks that can outpace human response times is a growing concern. For organizations relying on traditional SOC workflows, the gap between detection and action could be exploited. Sevii's approach suggests that autonomous, machine-speed response may become necessary. While human oversight remains a regulatory requirement for some, the practical reality of AI attacks may force a reevaluation of what that oversight means.
Sources
- SecurityWeek Original source
Continue Reading
CrowdStrike's SafeMind pairs attack and defense AI
CrowdStrike's SafeMind pairs Red Tempest and Blue Solano models for continuous red teaming and autonomous defense.
AI Exploit Porting: Fast, Costly, Still Needs Humans
Forescout researchers used Claude to port a PLC exploit, revealing AI's potential and limits in attack development.
AI Agents Outpace Enterprise Guardrails
65% of enterprises have seen AI agents act out of scope, with weak detection and authorization gaps.