Back to Intelligence

AI-Agent Breach of DIVD: Defending Against Autonomous Attack Tooling — Detection and Hardening Guide

SA
Security Arsenal Team
September 29, 2026
11 min read

The Dutch Institute for Vulnerability Disclosure (DIVD) — the nonprofit that responsibly discloses vulnerabilities on behalf of defenders worldwide — has disclosed that it was breached by an automated AI agent. DIVD characterized the attack as "loud and very, very messy," a description that should immediately shape how defenders think about this incident class.

This is not a hypothetical anymore. Agentic AI tooling — autonomous systems that can enumerate, probe, exploit, and iterate without a human operator at the keyboard — has now been confirmed in the wild against a real, security-conscious target. The uncomfortable irony of an organization that exists to close vulnerabilities being compromised by autonomous tooling should land hard with every CISO reading this.

The good news embedded in DIVD's description: loud and messy means detectable. Autonomous agents, at least in their current generation, generate telemetry at machine speed and machine volume — request floods, rapid-fire enumeration, error spikes, and behavior sequences no human operator produces. If your logging pipeline is healthy and your detections are tuned for velocity anomalies rather than just signature matches, you have a fighting chance. This post walks through exactly what to look for and how to harden against it.

Technical Analysis

What We Know About the Attack

Based on DIVD's public characterization of the incident:

  • Target: DIVD's infrastructure — an organization whose holdings are uniquely sensitive. DIVD maintains data on unpatched, un-disclosed vulnerabilities and coordinates disclosure with vendors globally. A breach here isn't just an organizational incident; it's a potential intelligence goldmine for follow-on exploitation.
  • Attack vector: An autonomous AI agent — software that chains reconnaissance, vulnerability identification, and exploitation steps without human pacing.
  • Operational signature: "Loud and very, very messy" — consistent with agent behavior we've observed in red team exercises using autonomous tooling: high request rates, brute iteration through exploit paths, noisy failed attempts left in logs, and no operational security discipline because there is no human operator worrying about being caught.

Why Autonomous Agents Change the Defensive Equation

Traditional intrusion detection assumes a human adversary with human constraints: working hours, fatigue, attention limits, and a preference for stealth because getting caught costs the operator something. Agentic attacks invert several of those assumptions:

AssumptionHuman OperatorAutonomous Agent
Request pacingThrottled, often deliberately slow to evade detectionMachine-speed — hundreds of requests per minute
Failed attemptsLimited; operator pivots after a few failuresRelentless iteration through exploit permutations
StealthUsually prioritizedFrequently absent — speed over subtlety
Session behaviorHuman-like browsing patternsNon-human sequences, no mouse/scroll events, API-style interaction
Tooling fingerprintsCurated, sometimes customFramework defaults — python-requests, curl, headless browser UAs, LLM-agent orchestration libraries

The defensive takeaway: velocity and pattern anomalies become your highest-fidelity signals. An agent that fires 4,000 requests at your application in 12 minutes is not trying to hide — it's trying to finish before you respond.

Attack Chain (Defender's View)

Based on the behavioral profile described, a typical agentic intrusion chain looks like this:

  1. Automated reconnaissance — mass enumeration of endpoints, parameters, and technologies against the target's external surface.
  2. Vulnerability identification — high-volume probing: fuzzing input fields, testing injection primitives, enumerating versions, attempting known-exploit paths in rapid sequence.
  3. Exploitation — once a viable path is identified, the agent executes the exploit and establishes initial access (commonly a web shell or command execution on the web tier).
  4. Post-exploitation automation — enumeration of the compromised host, credential harvesting attempts, and lateral movement probing — again at machine speed.
  5. Data access — in DIVD's case, the concern is exposure of vulnerability disclosure data: unpatched flaws, affected organizations, and coordination communications.

Exploitation Status

This is confirmed active exploitation in the wild — not a proof-of-concept or a theoretical capability. A production organization with competent defenders was breached. Treat autonomous agent activity as a present-tense threat category in your threat model, not an emerging one.

Detection & Response

The detections below target the observable behaviors inherent to agentic attacks: machine-speed request velocity, non-human tooling fingerprints, web-tier process spawning (web shells), and rapid enumeration sequences. These are the signals DIVD's attackers almost certainly generated — the question is whether they'd fire in your environment.

YAML
---
title: High-Velocity Web Requests From Single Source - Autonomous Agent Behavior
id: 3f8a1c92-6b4d-4e7a-9c15-2d8f4a6b1e30
status: experimental
description: Detects abnormally high request rates from a single source IP against web infrastructure, consistent with autonomous AI agent enumeration and exploitation tooling. Machine-speed request bursts are a primary indicator of non-human attack automation.
references:
  - https://www.bleepingcomputer.com/news/security/automated-ai-agent-used-to-breach-cybersecurity-nonprofit-divd/
  - https://attack.mitre.org/techniques/T1595/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.reconnaissance
  - attack.t1595.002
logsource:
  category: webserver
detection:
  selection:
    cs-method:
      - 'GET'
      - 'POST'
      - 'PUT'
  condition: selection | count(cs-uri) by c-ip > 500
  timeframe: 5m
falsepositives:
  - Legitimate load testing or QA automation (allowlist known test sources)
  - Search engine crawlers with valid verified bot identity
  - Internal vulnerability scanners (allowlist scanner IPs)
level: high
---
title: Automated Tooling User-Agent on Web Infrastructure
id: 9c2e7b14-3a5f-4d86-b821-7f3c9e0d5a62
status: experimental
description: Detects HTTP requests carrying user-agent strings associated with scripting libraries, headless automation frameworks, and default HTTP clients commonly used by autonomous attack agents rather than human browsers.
references:
  - https://www.bleepingcomputer.com/news/security/automated-ai-agent-used-to-breach-cybersecurity-nonprofit-divd/
  - https://attack.mitre.org/techniques/T1071.001/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.command_and_control
  - attack.t1071.001
logsource:
  category: webserver
detection:
  selection_ua:
    User-Agent|contains:
      - 'python-requests'
      - 'aiohttp'
      - 'httpx'
      - 'Go-http-client'
      - 'curl/'
      - 'wget/'
      - 'node-fetch'
      - 'axios/'
      - 'HeadlessChrome'
      - 'Playwright'
      - 'Puppeteer'
  filter_healthchecks:
    cs-uri|contains:
      - '/health'
      - '/status'
      - '/ping'
  condition: selection_ua and not filter_healthchecks
falsepositives:
  - Legitimate API integrations and partner automation (tune per-application baseline)
  - Internal monitoring tooling
level: medium
---
title: Web Server Process Spawning Shell or Command Interpreter
id: 5d1f8e36-7c2a-4b94-a638-1e9b4d7c2f08
status: experimental
description: Detects web server worker processes spawning command shells or scripting interpreters, a hallmark of successful web exploitation and web shell deployment as seen in automated intrusion chains.
references:
  - https://www.bleepingcomputer.com/news/security/automated-ai-agent-used-to-breach-cybersecurity-nonprofit-divd/
  - https://attack.mitre.org/techniques/T1505.003/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.persistence
  - attack.t1505.003
  - attack.execution
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\w3wp.exe'
      - '\httpd.exe'
      - '\nginx.exe'
      - '\tomcat9.exe'
      - '\java.exe'
  selection_child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\certutil.exe'
      - '\bitsadmin.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Rare — legitimate web applications invoking system commands (inventory and allowlist by application)
level: critical
KQL — Microsoft Sentinel / Defender
// Hunt: Machine-speed request bursts and automated tooling fingerprints against web assets
// Covers both velocity anomalies (agent enumeration) and non-human client fingerprints
// Tables: CommonSecurityLog (WAF/proxy CEF) and Syslog (Linux web tiers)

let threshold = 300;
let window = 5m;
CommonSecurityLog
| where DeviceProduct has_any ("WAF", "Proxy", "Web", "IIS", "nginx", "apache") or isnotempty(RequestURL)
| where isnotempty(SourceIP) and isnotempty(RequestURL)
| summarize RequestCount = count(),
            DistinctURIs = dcount(RequestURL),
            Methods = make_set(RequestMethod),
            UserAgents = make_set(RequestClientApplication, 10)
    by SourceIP, bin(TimeGenerated, window)
| where RequestCount > threshold
| extend AutomationFingerprint = iff(
    UserAgents has_any ("python-requests", "curl", "aiohttp", "httpx", "Go-http-client", "node-fetch", "axios", "HeadlessChrome", "Playwright", "Puppeteer"),
    "HIGH-CONFIDENCE AUTOMATION",
    "Velocity anomaly - investigate")
| project TimeGenerated, SourceIP, RequestCount, DistinctURIs, Methods, UserAgents, AutomationFingerprint
| order by RequestCount desc;
VQL — Velociraptor
-- Hunt: Web server processes spawning unexpected child processes (web shell / post-exploitation)
-- Run against web tier endpoints following any suspected agentic intrusion
SELECT Pid,
       Ppid,
       Name,
       Exe,
       CommandLine,
       Username,
       CreateTime
FROM pslist()
WHERE Ppid IN (
        SELECT Pid
        FROM pslist()
        WHERE Name =~ '(w3wp|httpd|nginx|tomcat|java|node|php-fpm)'
      )
  AND Name =~ '(cmd|powershell|pwsh|sh|bash|dash|wscript|cscript|mshta|certutil|curl|wget|nc|ncat|python|perl)'
Bash / Shell
#!/bin/bash
# Agentic Intrusion Triage & Web Tier Hardening Script
# Run on Linux web/application servers after suspected autonomous-agent activity
set -euo pipefail

echo "=== [1] Top source IPs by request volume (last 24h of access logs) ==="
for log in /var/log/nginx/access.log /var/log/apache2/access.log /var/log/httpd/access_log; do
  if [ -f "$log" ]; then
    echo "--- $log ---"
    awk -vDate="$(date -d '24 hours ago' '+%d/%b/%Y:%H' 2>/dev/null || date '+%d/%b/%Y')" \
        '{print $1}' "$log" | sort | uniq -c | sort -rn | head -15
  fi
done

echo ""
echo "=== [2] Automation-tool user agents observed ==="
for log in /var/log/nginx/access.log /var/log/apache2/access.log; do
  if [ -f "$log" ]; then
    grep -Eio 'python-requests|aiohttp|httpx|Go-http-client|node-fetch|axios/[0-9.]+|curl/[0-9.]+|HeadlessChrome|Playwright|Puppeteer' "$log" \
      | sort | uniq -c | sort -rn || true
  fi
done

echo ""
echo "=== [3] 4xx/5xx error spikes per source (enumeration fingerprint) ==="
for log in /var/log/nginx/access.log /var/log/apache2/access.log; do
  if [ -f "$log" ]; then
    awk '$9 ~ /^[45]/ {print $1, $9}' "$log" | sort | uniq -c | sort -rn | head -15 || true
  fi
done

echo ""
echo "=== [4] Recently modified files in web roots (web shell check) ==="
for root in /var/www /srv/www /usr/share/nginx/html; do
  if [ -d "$root" ]; then
    find "$root" -type f \( -name '*.php' -o -name '*.jsp' -o -name '*.aspx' -o -name '*.py' -o -name '*.sh' \) \
      -mtime -3 -ls 2>/dev/null || true
  fi
done

echo ""
echo "=== [5] Web server child processes (live web shell indicator) ==="
for svc in nginx apache2 httpd php-fpm; do
  pidof "$svc" >/dev/null 2>&1 && \
    ps --ppid "$(pidof $svc | awk '{print $1}')" -o pid,ppid,user,cmd 2>/dev/null || true
done
ps aux | grep -E '(nginx|apache|httpd|php-fpm)' | grep -v grep | head -5 || true

echo ""
echo "=== [6] Rate-limit / fail2ban posture ==="
if command -v fail2ban-client >/dev/null 2>&1; then
  fail2ban-client status || true
else
  echo "[!] fail2ban NOT installed — install and enable per-IP rate limiting"
fi
grep -r "limit_req_zone" /etc/nginx/ 2>/dev/null || echo "[!] No nginx rate limiting zones detected"

echo ""
echo "=== Triage complete. Review sections 1-5 for anomalous sources, then block at WAF/edge. ==="

Remediation

If you suspect autonomous agent activity against your environment — or you simply want to be ready for it — prioritize the following:

Immediate (0–24 hours):

  1. Deploy velocity-based alerting. If your SIEM cannot alert on per-source request rate thresholds today, fix that first. Agentic attacks are velocity attacks; rate anomaly detection is the single highest-value control.
  2. Enforce rate limiting at the edge. Configure nginx limit_req_zone, Apache mod_ratelimit/mod_evasive, cloud WAF rate rules (Cloudflare, AWS WAF, Azure Front Door), or API gateway throttling. A hard cap of a few hundred requests per source IP per minute disrupts most autonomous tooling without impacting real users.
  3. Verify web-tier process monitoring. Ensure EDR coverage on all web/application servers and confirm alerts exist for web server processes spawning shells (see Sigma rule above).

Short term (1–2 weeks): 4. Audit your external attack surface the way an agent would: run your own automated enumeration against yourself. If your ASM tooling can find it in minutes, so can theirs. Close exposed admin panels, forgotten staging environments, and unauthenticated API endpoints. 5. Baseline user-agent and client behavior per application. Alert on deviations — scripting-library UAs hitting human-facing applications are a cheap, high-signal detection. 6. Review credential hygiene on internet-facing services. Autonomous agents excel at credential stuffing and password spraying at scale. Enforce phishing-resistant MFA everywhere, and alert on authentication velocity anomalies, not just lockouts. 7. Validate your IR playbooks against machine-speed timelines. An agent can move from recon to exploitation in minutes. If your containment workflow requires a change ticket and a meeting, you will lose. Pre-authorize automated containment: WAF blocks, edge rate limiting, and EDR host isolation triggered by high-confidence detections.

Strategic (this quarter): 8. Threat-model agentic adversaries explicitly. Update tabletop scenarios: your adversary no longer sleeps, doesn't get tired, and doesn't care about being loud. Dwell time assumptions built on human adversaries are now invalid. 9. Protect coordination and disclosure data. If your organization handles vulnerability data, pentest findings, or pre-disclosure coordination, treat that repository as crown-jewel data — segmented, encrypted, access-logged, and monitored. DIVD's incident demonstrates that this data class is an active target. 10. Engage in information sharing. Monitor disclosures from DIVD and peer organizations for technical indicators from this incident as they are published, and feed them into your detection stack promptly.

The deeper lesson from this breach is one we should all sit with: an organization whose entire mission is closing vulnerabilities was breached by automation. Nobody's external surface is too small or too security-aware to skip the fundamentals — rate limiting, velocity alerting, EDR on the web tier, and an IR process that can act at machine speed.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.