ctipilot.ch

Agentic Vulnerability Discovery Harness (AVDH)

tool · tool:avdh-agentic-vulnerability-discovery-harness single-source

Mandiant/Google Threat Intelligence Group's multi-agent, AI-orchestrated source-code vulnerability discovery pipeline (built on Google's Agent Development Kit); found 100+ true-positive critical vulnerabilities in a stolen corporate repository within two days during an incident-response engagement, and has produced 12+ assigned CVEs over ten months of deployment (Mandiant, 2026-08-18).

Coverage timeline
1
first 2026-08-28 → last 2026-08-28
Peak priority
notable
1 notable
Sources cited
1
1 hosts
Sections touched
1
research
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Resource Development TA0042

T1588.006Obtain Capabilities: Vulnerabilities×1

Adversaries may acquire information about vulnerabilities that can be used during targeting. A vulnerability is a weakness in computer hardware or software that can, potentially, be exploited by an adversary to cause unintended or unanticipated behavior to occur. Adversaries may find vulnerability information by searching open databases or gaining access to closed vulnerability databases.

Evidence: 2026-08-28/gtig-avdh-agentic-vulnerability-discovery-stolen-source · ATT&CK page ↗

Story timeline

  1. 2026-08-28GTIG Agentic Vulnerability Discovery Harness (AVDH): Mandiant's multi-agent pipeline found 100+ true-positive critical vulnerabilities in a stolen corporate source-code repository within two days
    researchOnce source code leaks, the exploit-development clock now runs at machine speed, not at a defender's patch-cycle speed

Where this entity is cited

  • research1

Source distribution

  • cloud.google.com1 (100%)

explore in graph

Entries about Agentic Vulnerability Discovery Harness (AVDH) (1)

2026-08-28 · view entry permalink →

NOTABLENATOB2

GTIG Agentic Vulnerability Discovery Harness (AVDH): Mandiant's multi-agent pipeline found 100+ true-positive critical vulnerabilities in a stolen corporate source-code repository within two days

Mandiant describes the Agentic Vulnerability Discovery Harness (AVDH), an AI-orchestrated, multi-agent pipeline built on Google's Agent Development Kit that performs threat modelling, entry-point discovery, context enrichment, hypothesis generation and validation in a deterministic, sequential pipeline architecture rather than an unstructured single-prompt scan. During a real incident-response engagement involving stolen corporate repositories, the harness "discovered over 100 true-positive critical vulnerabilities in just two days — achieving results in a fraction of the time required for manual review" (Mandiant / Google Threat Intelligence Group, 2026-08-18). Over ten months of deployment it has produced 12 assigned CVEs, with a further dozen currently in active disclosure. Mandiant attributes the low false-positive rate to structuring the analysis process, enforcing sceptical multi-agent validation steps, and injecting domain-specific human expertise directly into the pipeline rather than relying on an LLM's unstructured judgement: "by structuring the analysis process, enforcing skeptical validation steps, and injecting domain-specific human expertise directly into the pipeline, we've achieved a leap in efficacy" (Mandiant / Google Threat Intelligence Group, 2026-08-18).

The defender-relevant inference is squarely about exposure, not about the tool itself: once proprietary source code is exposed — through a breach, a leaked repository, or a supply-chain compromise — an adversary with comparable agentic tooling can be assumed to enumerate its exploitable flaws at machine speed, inside a window measured in days rather than the weeks or months a defender's own patch cycle assumes: "adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code is exposed, defenders must scramble to identify and patch vulnerabilities while attackers deploy machine-speed AI tools against them" (Mandiant / Google Threat Intelligence Group, 2026-08-18).

This is a distinct primary publisher and a distinct technical finding from this run's other agentic-AI entries — Wiz's Red Agent (a single CI/CD flaw discovery) and the Taiwan intrusion (a live, confirmed campaign) — kept separate per the item-granularity rule: defensive vulnerability-discovery tooling, an offensive red-team tool finding one flaw, and an offensive intrusion are three distinct claims from three distinct publishers. actions[] is empty: the defender-relevant response is a standing incident-response planning assumption (treat any leaked-source-code incident as an accelerated exploit-development clock, not a days-to-weeks one) rather than a discrete do-now task this specific report changes.

During a recent incident response investigation involving stolen corporate repositories, the harness discovered over 100 true-positive critical vulnerabilities in just two days — achieving results in a fraction of the time required for manual review.

Adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code is exposed, defenders must scramble to identify and patch vulnerabilities while attackers deploy machine-speed AI tools against them.

By structuring the analysis process, enforcing skeptical validation steps, and injecting domain-specific human expertise directly into the pipeline, we've achieved a leap in efficacy.

Mandiant / Google Threat Intelligence Group 2026-08-18
research28 Aug 06:36Zsingle-sourceOpen finding ↗