Product
Platform
AWS
AWS
Azure
Azure
CI/CD
CI/CD
Google Cloud
Google Cloud
Identity
Identity
Kubernetes
Kubernetes
Workstations
Workstations
Credentials & artifacts
Credentials & artifacts
Use cases
AI Agent Detection
Cloud & Kubernetes Breach
Insider Threat Detection
Supply Chain & CI/CD Attack
Workstation Compromise
PricingCustomers
Resources
  • ResearchAbout
  • Careers
  • Contact
Community Edition
Book a demoCommunity Edition
Logo

AI Agents vs. Canaries: Detecting Attacks That Move at AI Speed

We sent 10 frontier AI models to attack a live AWS cyber range. See what 951 attack runs revealed about catching agentic attacks with canaries.

Live webinar

·

June 18, 8am PT / 11am ET / 4pm GMT+1

·

Zoom

Register for webinar
Nick Reva

Director of Security Engineering at DoorDash

Alessandro Brucato

Security Researcher

Sam Cox

Co-founder, CTO

AI agents can now compromise a cloud environment in minutes - and they're only getting faster. Tracebit benchmarked ten frontier AI models inside a controlled AWS cyber range to measure how quickly they can escalate to admin, and whether deception technology catches them in time. Across 951 attack runs, AI reached admin privilege escalation in an average of 14 minutes - but canaries warned the defender before the attack landed in 95.9% of those runs, a median 8 minutes ahead of the attacker's first critical action.

In this technical session, the researchers behind the study share what they found. They'll walk through the benchmark design, a synchronized replay of AI agents attacking the same account with and without canaries, and what it means for defending against offensive AI agents.

Join Tracebit's Alessandro Brucato (Security Researcher) and Sam Cox (Co-founder & CTO), alongside Nick Reva, Director of Security Engineering at DoorDash, for a hands-on look at detection in the age of AI attackers.

The team will also dig into a challenge they faced: using AI to research AI. They'll cover how to get reliable signal out of models that tend to agree with whatever you put in front of them, and how to keep your testing objective so the results aren't skewed by a model telling you what you want to hear.

What you'll take away:

  • How fast frontier AI models really move, escalating from low-privilege access to admin
  • Why canaries give defenders a head start
  • Why simply warning a model that deception may be present can cut full compromise
  • How to use AI to research AI, and why models that agree too readily can skew your results
  • What an assume-breach detection strategy looks like when attackers operate at AI speed

Who Should Attend:

  • Security leaders preparing their detection strategy for offensive AI agents
  • Security engineers and architects building detection and deception programs
  • Detection and response teams focused on high-fidelity signal and early warning
  • Cloud security teams responsible for AWS, GCP, and Azure environments
Register for webinar
Soc 2 Type 2 imageCheckmark imageAWS Qualified software illustration
PLATFORM
AWS
Azure
CI/CD
Google Cloud
Identity
Kubernetes
Workstations
Credentials & artifacts
USE CASES
AI Agent Detection
Cloud & Kubernetes Breach
Insider Threat Detection
Supply Chain & CI/CD Attack
Workstation Compromise
COMPANY
CustomersResearchAboutCareersContactStatusCommunity Edition
SOCIAL
© 2026 Tracebit
Privacy PolicyTerms of ServiceCookie Settings