AI-Generated PowerShell Scripts Accelerate AD Enumeration
Abstract
Threat actors are now using generative AI to write bespoke, single-use PowerShell scripts for Active Directory enumeration. Huntress documented a June 2026 intrusion where an attacker used pre‑compromised credentials and RDP to deploy an AI‑generated script that mapped users, computers, groups, and trusts before exfiltrating data via legitimate tools like s5cmd. The script’s AI origin was evident from leftover prompt artifacts, unedited placeholder text, redundant fallback logic, and decorative console output. A parallel case from Sygnia showed an AI‑assisted attacker compromising a large AWS environment in ~72 hours using known techniques at unprecedented speed. The core risk is accelerated, harder‑to‑fingerprint execution of familiar tradecraft, since each AI‑generated script is functionally unique and evades traditional hash/signature detection.