
When the Attacker Never Sleeps: How Agentic AI Is Getting Past EDR
For most of the last decade, endpoint detection and response has been a backbone of enterprise defense. The model is straightforward: put a sensor on every host, watch for suspicious behavior, detect it, and respond before the attacker can do serious damage. Built into that model, however, is an assumption we rarely had to say out loud: the attacker operates at something close to human speed.
That assumption is breaking down.
Agentic AI is changing the tempo of an intrusion. An agent can conduct reconnaissance, choose its next move, write or modify code, test it, evaluate the result, and try again without waiting for a person at a keyboard. In November 2025, Anthropic disclosed what it described as the first documented large-scale cyberattack executed largely by AI. According to Anthropic, a state-sponsored group used AI agents to perform roughly 80 to 90 percent of the work against approximately 30 organizations, with humans stepping in at only a handful of decision points.
That was an early warning. What has come since is more concerning.
In its September 2026 threat report, Anthropic described a Russian state-nexus operator using AI agents to monitor how its malware performed against security products. When tooling was detected, the agents could modify and rebuild it in an effort to evade those defenses and then put the new version back into operation. Anthropic's conclusion captures the problem: capable adversaries can now "close the loop," bypassing traditional security detections faster than defenders can develop and deploy them.
That is the challenge for EDR.
Detection has always involved a race between attacker and defender. Defenders identify malicious behavior, improve detections and controls, and force attackers to change what they are doing. That friction has traditionally worked in the defender's favor because adapting takes time. Attackers have to understand why something failed, modify their approach, test it, and try again.
Agentic AI compresses that cycle.
An agent capable of evaluating its own results and modifying its tooling can potentially accomplish in minutes what once required an attacker to stop, diagnose a problem, rewrite code, test it, and redeploy it. A detection may still work exactly as designed. The problem is that the adversary may be able to adapt to that detection almost immediately.
Speed compounds the problem. CrowdStrike's 2026 Global Threat Report puts average eCrime breakout time, the window between initial access and lateral movement, at 29 minutes. The fastest it observed was 27 seconds. In one case, data was being pulled out four minutes after the attacker got in. The same report found that operations by AI-enabled adversaries rose 89 percent year over year.
EDR can automatically stop some malicious activity, and that capability remains enormously valuable. But when an intrusion can move from initial access to lateral movement or exfiltration in seconds or minutes, any defensive model that depends on a human seeing, understanding, and responding to an alert is increasingly at a disadvantage.
There is also a quieter side to the problem.
Sophisticated attacks do not necessarily have to look malicious on an endpoint. Attackers increasingly operate through valid credentials, legitimate administrative tools, and normal cloud services. Agentic systems can make that problem more difficult by allowing an adversary to continuously evaluate an environment and adjust its behavior based on what it encounters.
EDR is very good at identifying activity that looks wrong on an endpoint. It has a much harder problem when the activity itself looks legitimate and the real issue is that the person or machine performing it should not be doing it.
And some of the most damaging activity may never occur on a managed endpoint at all. Attackers can pivot into unmanaged systems, cloud workloads, storage platforms, identity infrastructure, and backup environments where endpoint visibility may be incomplete or nonexistent. If the destructive activity occurs somewhere the endpoint sensor cannot see, EDR cannot be expected to provide the entire answer.
None of this means EDR has failed. It hasn't.
EDR remains a critical security layer and stops an enormous amount of malicious activity. But organizations need to be clear-eyed about what any detection technology can and cannot do against an adversary capable of adapting in real time. The faster attackers can observe defensive controls and modify their behavior, the less comfortable organizations should be assuming that prevention and detection will catch everything.
The safer planning assumption is that something eventually gets through.
That changes the question. Instead of asking only, "Did we catch the attacker in the act?" organizations also need to ask, "Do we know what the attacker did to our data?"
That is where the data itself becomes one of the most reliable witnesses.
An attacker can change its tools, infrastructure, credentials, techniques, and timing. It can try to make its activity resemble legitimate administration. But the consequences of destructive activity ultimately have to exist somewhere. Encryption, corruption, deletion, unauthorized modification, and other changes to data can leave measurable evidence independent of the particular malware, technique, or infrastructure that caused them.
That distinction matters because defenders do not necessarily need to recognize every version of an attack to determine that the integrity of their data has changed.
It matters even more when it comes to recovery.
Ransomware operators understand that backups are one of the defender's greatest sources of leverage. If attackers can corrupt, encrypt, delete, or otherwise undermine recovery data before the organization realizes what has happened, they can turn a security incident into a much larger operational crisis. An agentic attacker capable of operating quickly and adapting to defensive controls is particularly well suited to attacking that recovery process.
That makes continuous validation of backup and recovery data increasingly important. Organizations need to know not simply that a backup exists, but whether the data inside it is intact, whether it has been altered, and which recovery point can actually be trusted.
Because recovery is ultimately where the consequences of all of this become real.
Agentic AI is changing the economics and speed of cyberattacks. Defenders cannot assume they will always identify a new technique, build a detection, and deploy it before the attacker changes again. The answer is not to abandon EDR or stop trying to detect the attacker. It is to recognize that detection alone cannot carry the entire burden.
Watch the endpoint, yes.
But verify the data.
When the attacker never sleeps, certainty about what you can recover may be the control that matters most.
Can you prove your recovery points are clean?
Your board will ask if you can recover clean. This checklist lets you answer with evidence.
