isc.sans.edu 9 Oct 2026, 07:52 UTC

AI Agent Logs Expose Attacker Chats and Help Trace Cyber Intrusions

AI Agent Logs Expose Attacker Chats and Help Trace Cyber Intrusions
CyberSIXT Evidence Panel Source marked as original reporting

ON 9 October 2026, the SANS Internet Storm Center’s Friday Stormcast notes continued concerns about how AI agents are used in cyberattacks and how defenders can trace those activities. The episode highlights two scripts by Jim Clausing that convert AI-agent activity logs into searchable JSON, assisting forensics when attackers use AI on their own hosts or when the victim’s logs reveal AI involvement.

A notable case mentioned involved CrowdStrike discovering an attacker’s CLAUDE[.]md file on a compromised system in a South Korean financial institution, which allegedly exposed the attacker’s chat history with the Claude AI. The segment emphasises that not only attacker-side logs but also victim-side logs can be valuable for understanding how AI agents were used, potentially aiding both breach analysis and red-team emulation. The discussion frames this as a shift from “script kiddies” to “prompt kiddies,” underscoring the evolving mindset behind modern AI-assisted intrusions.

The episode also covers international domain name typosquatting and evolving defences against lookalike domains. It explains how attackers historically exploited mixed character sets to impersonate brands, and how browsers like Google Chrome have tightened detection by flagging confusables. Nevertheless, fresh variants using non-official confusable characters can bypass some checks, with differences in how Safari and Chrome render such domains.

In security advisories, Cisco released a high-severity advisory for Finesse with server-side request forgery that restricts access to sensitive information and lacks a patch, with Cisco indicating a fix may not arrive until early next year. The episode concludes noting the importance of monitoring both attacker and victim AI activity forensics and defending against evolving domain-based impersonation threats.

View full article

Article by CyberSIXT