Catch Attackers Before They Strike with AI-powered Threat Intelligence

Nadir Izreal (CTO & Co-Founder · Armis)

RSA Conference 2025 · Day 4 · West Stage · Keynote

Overview

Armis CTO and Co-founder Nadir Israel argues that defenders are losing the cybersecurity war for two compounding reasons: widespread AI adoption by attackers and a persistent failure to achieve basic asset visibility. The solution he proposes is an AI-driven early warning system — combining LLM-powered threat intelligence with agentic honeypots — capable of detecting emerging attack campaigns weeks to months before they reach production environments, flipping the industry from reactive posture to genuine prevention. ---

Watch on YouTube

Visual summary for Catch Attackers Before They Strike with AI-powered Threat Intelligence by Nadir Izreal
Visual summary for Catch Attackers Before They Strike with AI-powered Threat Intelligence by Nadir Izreal

Key moments

  1. 1:38 Good guys are losing: AI attackers outpace defenders structurally
  2. 3:29 AI-powered adaptive malware already used by APT groups today
  3. 5:11 Hospital ignored warnings, got ransomwared, used pen-and-paper two months
  4. 7:43 58% of organizations feel almost entirely reactive to threats
  5. 8:21 Typical enterprise has millions of vulnerabilities to sift through
  6. 9:54 Two months early warning possible for threats like Log4Shell
  7. 14:15 Armis monitors over 5 billion assets worldwide
  8. 16:44 Smart honeypots detect attacker weapon-testing before main strike

Catching Attackers Before They Strike: The Case for AI-Powered Threat Intelligence

Speakers: Nadir Israel, Co-founder and CTO, Armis

Conference: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco

YouTube: https://www.youtube.com/watch?v=5l2bfdoxBUU

Reading time: ~7 min

TL;DR

Armis CTO and Co-founder Nadir Israel argues that defenders are losing the cybersecurity war for two compounding reasons: widespread AI adoption by attackers and a persistent failure to achieve basic asset visibility. The solution he proposes is an AI-driven early warning system — combining LLM-powered threat intelligence with agentic honeypots — capable of detecting emerging attack campaigns weeks to months before they reach production environments, flipping the industry from reactive posture to genuine prevention.

Introduction

The premise of Nadir Israel's RSA Conference 2025 keynote was deliberately provocative: in the ongoing conflict between attackers and defenders, the good guys are losing. Not just holding ground — losing. And the reasons, Israel argued, are not exotic. They are familiar failures that have compounded at machine speed, accelerated by the same AI revolution that the security industry is only beginning to fully reckon with.

Israel, who co-founded Armis nine years ago after hearing from CISOs and CIOs that they fundamentally did not know what assets they owned, framed his talk around a shift the industry has long discussed but rarely achieved: moving from reactive security to proactive prevention. The mechanism he described has a cinematic shorthand — Minority Report, catching threats before they materialize — but the underlying technology is operational today.

Why Defenders Are Losing: The Two-Factor Problem

▶ Watch: Israel frames the defender gap (0:00)

Israel identified two structural reasons defenders lag behind attackers. The first is technology adoption asymmetry: attackers are leveraging AI aggressively and at scale, while many defenders have not yet secured the basics. The second is a problem that predates AI entirely — organizations still cannot reliably enumerate what they own.

The consequences of poor asset visibility compound quickly. A typical enterprise today has millions of vulnerabilities and security findings. Most are not relevant. Most are not being actively targeted. But teasing out the specific subset that attackers are actively weaponizing remains an unsolved problem for most organizations.

AI has worsened the attacker side of this equation dramatically. Israel listed capabilities that have migrated from science fiction to operational reality: deepfake-based social engineering (including WhatsApp and Zoom impersonations targeting finance departments), polymorphic malware that adapts mid-attack, and agentic AI platforms that take advantage of contextual information at every stage of a compromise chain. Tools like WormGPT and its variants are being used not just by sophisticated APT groups but by low-skill actors who previously lacked the expertise to mount complex attacks.

"The biggest problem with all of this isn't even how much it generates scale and speed... It's about lowering the bar for many others who in the past needed lots of experience."

(4:00)

The Hospital That Waited: A Case Study in Reactive Security

▶ Watch: The ransomware hospital story (4:00)

Israel grounded the abstract argument in a concrete incident. A hospital deployed Armis in a proof-of-concept engagement. The platform immediately surfaced a prioritized list of critical exposures: a VPN aggregator two years behind on patching, Active Directory misconfigurations enabling privilege escalation, and similar high-priority findings. While the hospital went through budget procurement — leaving Armis running but unacted upon — attackers struck.

Three months later, the hospital was ransomwared. Because Armis had been passively monitoring the entire time, the full attack chain was captured: entry through the VPN aggregator, lateral movement to Active Directory, then full compromise. The institution declined to pay the ransom, but operated on pen and paper for two months while systems were restored.

The disparity between the cost of remediation (patching a VPN aggregator, tightening Active Directory) and the cost of the breach (two months of operational paralysis) was the keynote's most visceral data point. It illustrated the core argument: organizations know what to fix, but most lack the mechanism to act before attackers do.

A survey underpinning Armis's Cyber Warfare Report found that 58% of organizations feel they are almost entirely reactive to threats — doing virtually nothing they would characterize as proactive.

The Early Warning Concept: Months Ahead of CISA KEV

▶ Watch: Early warning system explained (8:00)

The heart of Israel's keynote was a description of what proactive defense actually looks like in practice. The concept: an early warning system capable of surfacing specific exploited vulnerabilities weeks to months before they appear on authoritative lists like CISA's Known Exploited Vulnerabilities catalog.

He pointed to Log4Shell as an illustrative benchmark. An effective early warning system, he argued, could have provided two months of lead time on an attack of that magnitude — enough time to remediate the exposure before it was weaponized at scale. This is not theoretical; Israel stated the rate of detection ahead of CISA KEV is measurable and consistent.

The mechanism works because attackers have their own operational timelines. Before a nation-state or criminal group hits a major target, there is a chain of events: reconnaissance, weapon development, and — critically — weapon testing against softer targets. Attackers targeting a U.S. Fortune 500 bank will first test their tools against banks in Brazil, Africa, or other regions where detection capability is lower.

"If you position those smart honeypots in the right places and take advantage of that, you get forewarning of credible attacks."

(14:00)

Two Technologies Making Early Warning Possible

▶ Watch: LLMs and honeypots in practice (12:00)

Israel described two AI-driven mechanisms that together constitute the early warning infrastructure Armis has built.

LLM-powered threat intelligence. Traditional threat intelligence relies on keyword matching and domain monitoring — approaches that produce high volumes of low-context signals requiring manual analysis. LLMs trained on threat data can understand relevance, intent, and context simultaneously. They can assess whether a piece of chatter in dark web forums is actually meaningful to a specific organization type, not just whether it mentions a relevant keyword. This dramatically reduces analyst burden and improves actionability.

Agentic AI honeypots. The more novel capability Israel described is smart honeypots powered by agentic AI. Armis monitors more than five billion assets globally, providing a massive data set of real-world attack surfaces — retail environments, hospitals, manufacturing plants, data centers, airports. That telemetry can be used to construct convincing synthetic environments that mimic real targets.

When attackers conduct weapon tests against these honeypots — as they routinely do before major campaigns — the system captures not just the fact of an attack, but the specific CVEs being exploited, the tactics and techniques employed, and attribution signals pointing to the threat actor. Those findings are then mapped against an organization's actual environment to identify which specific vulnerabilities are on an attacker's active list.

▶ Watch: The five billion asset advantage (14:00)

The result is a system that does not rely on external feeds or retrospective analysis. It generates its own signals from active attacker behavior and translates them directly into prioritized remediation guidance — specific CVEs, specific attack paths, specific mitigations.

Notable Quotes

"The good guys are losing. We all kind of feel that, uh, to a degree, but there's two main reasons why that is. One is technology adoption, especially on the AI side, by the attackers."

— Nadir Israel (0:00)

"Fifty-eight percent of organizations feel that they are almost entirely reactive to threats that manifest. They do virtually nothing that they would perceive as proactive."

— Nadir Israel (8:00)

"This isn't just another needle in a needle stack. This is very specific which CVE, which exploit, which security finding, which misconfiguration is being taken advantage of, and what exactly is the attack path that is used after that."

— Nadir Israel (14:00)

Key Takeaways

  • Defenders are structurally disadvantaged by two compounding failures: AI-accelerated attacks and persistent inability to achieve complete asset visibility, a problem Armis has heard from CISOs since the company's founding in 2016.
  • Attackers have their own operational timelines — reconnaissance, weapon testing, deployment — and signals from each phase can be collected and acted upon before a production attack occurs.
  • LLMs trained on threat data can evaluate relevance, intent, and context in ways that keyword-based threat intelligence cannot, dramatically reducing analyst workload and improving prioritization accuracy.
  • Agentic AI honeypots, built from real attack surface telemetry across more than five billion monitored assets, create decoys that attract and expose attacker weapon tests in advance of major campaigns.
  • The measurable outcome is weeks-to-months of advance warning on major vulnerability exploitation campaigns, with specificity at the CVE and attack-path level — enabling proactive remediation rather than reactive response.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

Armis's CTO delivers a technically coherent argument dressed in a vendor keynote that is never quite honest about the gap between 'here is a concept' and 'here is reproducible evidence.' The honeypot-based early warning system is genuinely interesting; the 'weeks ahead of CISA KEV' claim needs a lot more substantiation before Zero treats it as real. This is a vendor pitch with a good idea buried inside it.

Heather Calloway (CISO) — SOLID

Armis presents an AI-driven threat intelligence system that identified Log4Shell exploitation two months before CISA added it to KEV, using agentic honeypots and LLM analysis across 5 billion monitored assets. The hospital ransomware case study is the clearest statement of why reactive security fails.

→ Top-rated talks at RSA Conference 2025

All talks from RSA Conference 2025