August 10, 2026 5m read

Defeating the Agentic Attacker: Agentic Threat Prevention in ActionΒ 

Dr. Guy Waizel
Matan Mittelman
Dr. Guy Waizel , Matan Mittelman

Table of Contents

Wondering where to begin your SASE journey?

We've got you covered!
Listen to post:
πŸ”Š This audio player requires that "Preferences" cookies be accepted

Executive summary 

Agentic attacks are changing the speed and scale of the defensive challenge. This post explains the challenge, Cato’s new purpose-built capability for addressing it, and what we observed in an end-to-end demonstration:

  • Frontier AI compresses the attack timeline.  
    Agentic attackers can identify weaknesses at machine speed, adapt in seconds, and generate AI-scale event volume. 
  • Cato’s Agentic Threat Prevention stops agentic attacks at machine speed.  
    It leverages shared context to customize attack predictions, applies inline protections to stop attack progression, and scales elastically as attack traffic surges. 
  • We put it to the test against an Agentic Attacker.  
    In the end-to-end demonstration, Cato detects the attack as it unfolds, applies controls, records mitigations in the timeline, and ultimately prevents the agent from reaching full domain compromise. 

Frontier AI raises the bar for prevention 

In our previous discussion about Frontier AI Models, we shared a vision for agentic defense built on customer-specific predictions, autonomous adaptability, and cloud-native scale. We explained why an architecture with full traffic visibility, shared context across controls, and the ability to enforce policy inline is essential for turning AI insight into prevention. This post brings that vision to life. 

Our Agentic Attacker research showed why this matters: in a controlled environment, an agentic attack chain progressed from external access to Domain Administrator privileges in as little as 40 minutes from a single high-level prompt. Cato’s cloud-native, converged SASE architecture and Single Pass Cloud Engine (SPACE) provide the customized predictions, agentic adaptability, and elastic scale needed to recognize that progression and act before the attacker reaches the objective. 

Can Your Security Architecture Prevent Attacks at AI Speed? | Download the eBook

The Moment the Agentic Attack Met Its Defense 

In this post, we put the Agentic Attacker to the test against Cato’s Agentic Threat Prevention. The scenario follows an external attacker exploiting a vulnerability in a public-facing server, then conducting internal discovery and enumeration, escalating privileges, and moving laterally toward full domain compromise. The following video demonstration summarizes this end-to-end attack chain, the defensive actions taken as it unfolded, and the final result: the attack agent did not achieve its objective. We then look behind the scenes at the prevention approach and the Agentic Feed that helps turn suspicious behavior into contextual action.

While the video shows the attack and defense progressing in real time, the following view (Figure 1) shows how Agentic Threat Prevention presents the finding, supporting evidence, activated controls, and mitigation status in the Cato Management Application. 

Figure 1: Agentic Threat Prevention in the Cato Management Application

Figure 1: Agentic Threat Prevention in the Cato Management Application

From the lab to real-world attack patterns 

Controlled demonstrations make the attacker and defender timelines visible, but the underlying pattern is not theoretical. Reported JADEPUFFER activity followed a similar progression: exploitation of an internet-facing server, internal network enumeration, and persistent communication with external infrastructure. Viewed individually, these events may appear disconnected. Viewed together, they describe a post-compromise attack chain with predictable next steps. 

The Hugging Face incident provides another real-world example. Its disclosure describes an autonomous agent framework that gained code execution, escalated to node-level access, harvested credentials, and moved laterally into internal clusters while executing thousands of actions at machine speed. These examples show why prevention must correlate related behavior as an attack develops, then apply focused controls autonomously, before the attacker advances to the next stage. 

From Security Research to Inline Prevention 

Cato Agentic Threat Prevention is based on two tightly coupled engines: inline conditional enforcement and an agentic decision-making layer. Conditional enforcement introduces prediction logic that is decided by the context of each host, not by a static rulebook alone. Hosts are tagged based on their recent activity and can be denied of certain activities that reflect the MITRE ATT&CK tactics an attacker activity may exhibit. For example, a host that is found to contact known C2 servers, can be denied downloading executable files from cloud services.

The agentic decision-making layer introduces a continuous workflow that aggregates telemetry, reasons about it, and automatically instruments prevention. Hosts in the account are evaluated for the signals they emit, and rather than treating every security data point as an isolated event, it looks for a developing attack sequence and relations between activities. If any hosts warrant stricter handling, it utilizes conditional enforcement to orchestrate prevention of further attacker activity. For example, a host found to conduct internal network discovery as well as suspicious external communications may automatically be denied lateral movement vectors used by attackers.

As Figure 2 shows, when the evidence supports action, the agentic layer selects the appropriate prevention policy and arms the relevant controls in real-time. Cato’s inline security engine then enforces that posture when the attacker attempts the next restricted behavior. This is the division of labor: researchers define and refine prevention policies, the agentic layer reasons about and evaluates host patterns and applies the policies based on evolving host activity, so inline controls act where it matters most, before the attacker’s next move.

Figure 2: From security telemetry to an evidence-bound prevention decision 

Prevention for the speed and scale of frontier AI

The practical lesson from agentic attack research is not that every attack will look the same, or that AI alone will solve the problem. It is that an agent can compress familiar stages of an intrusion, including reconnaissance, exploitation, command and control, and lateral movement, into a much shorter and more adaptive sequence. Defenders need to recognize that sequence while it is happening, not reconstruct it only after the fact.

That requires broad visibility, context that connects related activity, and controls that can be applied quickly and precisely. Cato Agentic Threat Prevention is one approach to that problem: it uses the evidence available across the platform to evaluate suspicious behavior and apply focused prevention when the context supports it. The demonstration we present here is a controlled example, but it illustrates a broader frontier-AI imperative: turn the signals already available to defenders into predictive, adaptive action.

Related Topics

Wondering where to begin your SASE journey?

We've got you covered!
Dr. Guy Waizel

Dr. Guy Waizel

Tech Evangelist

Dr. Guy Waizel is a Tech Evangelist at Cato Networks and a member of Cato CTRL. As part of his role, Guy collaborates closely with Cato's researchers, developers, and tech teams to bridge and evangelize tech by researching, writing, presenting, and sharing key insights, innovations, and solutions with the broader tech and cybersecurity community. Prior to joining Cato in 2025, Guy led and evangelized security efforts at Commvault, advising CISOs and CIOs on the company’s entire security portfolio. Guy also worked at TrapX Security (acquired by Commvault) in various hands-on and leadership roles, including support, incident response, forensic investigations, and product development. Guy has more than 25 years of experience spanning across cybersecurity, IT, and AI, and has held key roles at tech startups acquired by Philips, Stanley Healthcare, and Verint. Guy holds a PhD with magna cum laude honors from Alexandru Ioan Cuza University, his research thesis focused on the intersection of marketing strategies, cloud adoption, cybersecurity, and AI; an MBA from Netanya Academic College; a B.Sc. in technology management from Holon Institute of Technology; and multiple cybersecurity certifications.

Read More
Matan Mittelman

Matan Mittelman

Matan Mittelman is a Threat Prevention Team Leader at Cato Networks and member of Cato CTRL. He's responsible for analyzing, researching, and developing protections against emerging threats and CVEs. Matan brings nearly 10 years of experience leading cybersecurity teams. Matan holds a Master's degree in Clinical Neuropsychology from The Hebrew University of Jerusalem and a Bachelor's degree in Psychology from Ben-Gurion University of the Negev.

Read More