< Back to all clusters
[TECHNOLOGY] · 2 sources

AI-generated PowerShell script powers aggressive Active Directory enumeration attack

Security researchers identified a PowerShell script, described as “vibe‑coded,” that was generated with assistance from a large‑language model and used to enumerate Active Directory (AD) environments. The code contained hallmark AI artifacts such as a verbose debugging title, colorful console output and a placeholder hostname “Server1.HR.local.”

The attacker accessed a domain‑joined Windows server via Remote Desktop Protocol using stolen credentials, staged the script in the C:\ProgramData\ folder, and executed an aggressive, noisy reconnaissance cascade that located the domain controller, harvested users, computers, groups, OUs and trusts, and saved the results in CSV files and an HTML inventory report. Legitimate tools s5cmd and SharpShares were then used to locate and exfiltrate data from network shares. The incident, reported from early June 2026, illustrates how AI can act as a force multiplier, lowering the technical barrier for less‑skilled actors while keeping core attack tactics unchanged.