Autopsy Series
Would Ethosure have caught this? Sysdig’s LLM-driven post-exploitation in four pivots
An attacker exploited a Marimo notebook, then handed the reins to an LLM agent that pivoted four times — from notebook to cloud credentials to AWS Secrets Manager to an internal PostgreSQL database — in under one hour. The bastion phase alone ran in under two minutes. Signature-based detection tuned for scripted attackers is the wrong instrument for an agentic adversary.
