
The 2-Minute Dwell Time: Why Agentic AI is Redefining Threat Hunting
Source: YouTube · Cloud Security Podcast · published Apr 15, 2026 · 44:12
Adversaries are leveraging AI agents to accelerate attacks, collapsing lateral movement times to under three minutes and forcing defenders to adopt agentic threat hunting to maintain visibility.
Key Takeaways:
• Adversary lateral movement speed has collapsed from days to as low as 2.5 minutes, rendering traditional detection timelines obsolete 0:11-0:16
• Attackers are using AI tools like Anthropic and OpenAI to orchestrate attacks at machine speed, evidenced by an actor exfiltrating 150GB from the Mexican government 0:00-0:08
• The "cardinal sin" of threat hunting is failing to operationalize findings—leaving work on SharePoint drives allows adversaries to reuse TTPs weeks later 0:20-0:31
• AI agents excel at fast detection but struggle with fully credentialed malicious insiders, low-and-slow attacks, and cloud hunting due to telemetry limitations 0:26-0:36
• Security teams must blend detection engineering and threat hunting, treating identity as the new perimeter and focusing on system-wide correlation 0:16-0:20
To remain effective, security teams must treat detection logic as dynamic and operational, ensuring insights are integrated into active defense rather than archived in static locations.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
By design, we have accepted that we're not covered. It's just more hoping a single threat actor using Inthrope with a sprinkling of Open AI to exfiltrate 150 GB of data in February. Lateral movement start date is days, moved down to 12 hours, has now dropped down to 2 2 and 1/2 minutes. >> I don't know how many people actually think about life cycle of detection rules as well. Oh my gosh. Should we even water this plant or should we let it alone? The cardinal sin of hunting. We did all this great work and then it lives on a SharePoint drive. And the adversary can come back and use those exact same TTPs a week later. People have the creativity and skills. They just haven't had the time to do it in the Yeah. And now we're in a world that is If you haven't using AI agents for threat hunting, …