Opens in a new tab
vmblog logo 2024 wht (updated)

Skyhawk Security Ties AI Red Team Cloud Attack Scenarios to Known Threat Actor Tradecraft

Share: 

David Marshall | Published: March 24, 2026

Skyhawk Security has added Threat Actor Context to its award-winning platform. The enhancement adds real-world adversary insights to cloud attack scenarios created with Skyhawk’s AI Red Team, mapping them to known threat actors, major campaigns and affiliated CVEs.

“Security teams have plenty of data, telemetry and alerts. What they’re usually lacking is the context to transform that data into security insights and pinpoint why simulated attack scenarios matter to their business based on activity seen in the wild,” said Chen Burshan, CEO of Skyhawk Security. “We’re helping them view scenarios through the lens of known attacker behavior to better assess exposure and improve prioritization.”

The new capability looks beyond TTPS. Threat Actor Context enriches Skyhawk’s platform by adding curated threat intelligence to attack scenarios, incorporating signals such as targeted industries, geographies and malicious campaign methods. It was designed as a contextual enrichment capability using Skyhawk’s attribution engine. This adds value for customers by showing them what their attack scenario resembles and why it deserves attention in their business’s specific context.

At launch, Threat Actor Context connects scenarios to threat intelligence-based adversary behaviors such as:

  • Scattered Spider – patterns tied to identity-driven intrusions and high-profile attacks like MGM Resorts and Caesars Entertainment
  • APT29 – tradecraft linked to NOBELIUM and TeamCity-related cloud intrusion activity
  • APT44 / Sandworm – patterns associated with disruptive operations and campaigns like BadPilot
  • TraderTraitor – techniques tied to the JumpCloud compromise and the Bybit theft
  • APT41 – behavior associated with operations such as Operation CuckooBees and broader public sector targeting