AI agents put offensive cyber within reach of novices

Comparing the performance of AI agents to humans in offensive cyber operations

Benjamin Sperisen, Jair Aguirre, Henri van Soest, Zylex Lopez

ResearchPublished Jun 25, 2026

Our research finds that artificial intelligence (AI) capabilities as of April 2026 make offensive cyber capabilities much more broadly available compared to the large language models (LLMs) of 2025, even without special expertise. RAND previously conducted a study of human uplift from AI for offensive cyber tasks. We discovered that participants generally struggled even with AI assistance, finding statistically insignificant uplift, and also found that users almost never succeeded in our more difficult challenges despite having access to AI tools.

Following this study we re-tested the same challenges with Claude Code using Sonnet and Opus 4.6. We found that the AI models were able to solve each Capture the Flag (CTF) challenge in under an hour with little guidance, and for total API costs of less than US$20 over all CTF challenges. Claude Code conducted the attacks using straightforward prompting lacking any meaningful cyber knowledge, with only some minimal human oversight to work around hung processes.

Attention has recently focused on the strong offensive capabilities of the restricted-access Mythos Preview model. However, our findings show that even today’s publicly available models have made complex offensive cyber tasks, including some that were empirically out of reach of both novices and fairly technically advanced users using 2025 chatbots, broadly accessible to anyone who can install Claude Code. At the same time AI may also be boosting cyber defenders, and offense-only evaluations like CTFs omit this counterbalancing uplift. Accordingly, the evaluation of cyber capabilities and defensive measures will have to become much more sophisticated to be relevant.

Key Takeaways

Offensive cyber capabilities that were out of reach for non-experts in 2025 are now broadly accessible

  • Our research with human participants showed that the harder CTFs were very difficult both for novices and technical users (including those with some cybersecurity background), even with the aid of August 2025 frontier models as chatbots and eight hours to work on them. Today, these CTF challenges can all be solved by users without any cyber expertise in less than an hour, if the users can install Claude Code.

It is reasonable to assume many unpatched systems can be exploited by unskilled novices very soon, if not now

  • Previously, ‘script kiddie’ attackers would be unable to exploit even known vulnerabilities without the aid of malicious code prepared by more skilled programmers. Now, Claude Code can generate and run such scripts on demand. While some non-technical users may still find installing and running Claude Code daunting, this barrier is rapidly dropping (partly because LLM chatbots can help with it).

AI agents appear able to carry out piggy-back attacks, building upon previously exploited target systems

  • We observed one AI model taking advantage of the progress a previous and different AI model had made, saving time and money. If vulnerable systems are only partially patched or if cybersecurity incidents are not fully resolved, AI agents may be able to exploit such systems at rate faster and cheaper than benchmarks and further complicate attribution.

Offensive cyber evaluations must go beyond CTFs and passive vulnerable systems, and should include environments featuring active defenders

  • Our results suggest CTFs may be approaching saturation. This is in line with the UK AISI’s report on Claude Mythos Preview, which suggests that the cyber ranges of passive, vulnerable systems may soon be saturated as well. Relevant assessments likely need to include active defenders of systems who can detect and counter an attack. Such active adversarial assessments are significantly more complex and expensive to construct and depend on the skill of the defenders. But this level of realism is needed given that capabilities now exceed the simpler settings used before.

Topics

Document Details

Citation

Chicago Manual of Style

Sperisen, Benjamin, Jair Aguirre, Henri van Soest, and Zylex Lopez, AI agents put offensive cyber within reach of novices: Comparing the performance of AI agents to humans in offensive cyber operations. Santa Monica, CA: RAND Corporation, 2026. https://www.rand.org/pubs/research_reports/RRA3892-2.html.
BibTeX RIS

Research conducted by

This publication is part of the RAND research report series. Research reports present research findings and objective analysis that address the challenges facing the public and private sectors. All RAND research reports undergo rigorous peer review to ensure high standards for research quality and objectivity.

This document and trademark(s) contained herein are protected by law. This representation of RAND intellectual property is provided for noncommercial use only. Unauthorized posting of this publication online is prohibited; linking directly to this product page is encouraged. Permission is required from RAND to reproduce, or reuse in another form, any of its research documents for commercial purposes. For information on reprint and reuse permissions, please visit www.rand.org/pubs/permissions.

RAND is a nonprofit institution that helps improve policy and decisionmaking through research and analysis. RAND's publications do not necessarily reflect the opinions of its research clients and sponsors.