01 / 07 ⚠ Threat advisory — 2026

The attackers brought AI. Most SMBs didn't.

Agentic AI now writes its own malware, rotates its own infrastructure, and clears its own logs — at machine speed, against companies that still rely on a single MSP and a firewall. IronCastle is the AI-native SOC built for the businesses on the other side of that asymmetry.

Project Glasswing · Disclosure window
--Days
:
--Hrs
:
--Min
:
--Sec
First public wave of AI-found CVEs · expected early July 2026

No firm date has been set — it could come anytime. Now is the time to make sure you're protected. Get updates as we learn more:

Why Mythos matters →
Specimen — owner portal
FIG. 01 — sample tenant — illustrative
portal.ironcastle.io / overview
OverviewIncidentsReports
Overview
— last 7 days
Live · 0.4s
94
Security score
Active incidents 03 OPEN
Critical Suspicious sign-in from new country [email protected] SAN-FR-IP 2m
High Outdated agent on 2 endpoints auto-remediation queued DEV-LAP-04 12m
Medium MFA disabled for 1 user [email protected] M365 1h
24/7Human SOC + autonomous AI, always on
5–30 minAnalyst response SLA, by tier
AI + humanAutonomous detection, human verdict
Live threat advisory · Q2 2026

The threat model just changed. Quietly.

Throughout 2025 the criminal economy quietly adopted the same agentic AI tools as Fortune 500 R&D teams. The result: red-team frameworks like Mythic, Sliver, and Havoc are now driven by autonomous agents that rewrite payloads in seconds, pivot through cloud identities, and stay under the radar of every signature-based tool an SMB can afford. The asymmetry is no longer skill — it's tempo.

VECTOR · 01

Agentic malware that rewrites itself

LLM-driven implants regenerate their own code on every beacon — defeating SHA256 blocklists, YARA strings written even an hour earlier, and the entire premise of "known-bad" detection.

↑ 312% novel implant variants observed YoY
VECTOR · 02

Autonomous post-exploitation

Frameworks like Mythic 4.x ship with agent operators that pick their own targets, dump their own credentials, and decide their own lateral path — without a human at the keyboard.

4 min median dwell before first lateral move
VECTOR · 03

SMB-targeted spearphishing at scale

Generative voice + email clones tuned per-employee from public LinkedIn data. The "your CFO is asking" message now sounds exactly like your CFO — and follows up if you don't reply.

1 in 7 SMBs hit by AI-tailored phishing in the last 12 months

This is why we built IronCastle. Signature tools are losing to autonomous attackers. The answer is an AI defender that runs at the same speed — on your machines, in your cloud, with humans on top.

Full 2026 threat brief →
02 / CapabilitiesEight pillars

An AI defender that moves first. Humans that finish the job.

Every capability below is live in production today — built for an attacker who never sleeps and never types the same payload twice.

01

AI Guardian — autonomous triage

A frontier-model-powered analyst reads every incident in plain English, maps it to MITRE ATT&CK, and recommends the next action — within seconds. Auto-contained alerts carry an 🤖 AI Guardian attribution so your team always knows who acted.

  • Latest frontier models with cached context
  • Analyst-grade verdict + reasoning
  • MITRE technique + remediation hints
02

YARA scanning with signed rule packs

Every non-Apple-signed process gets scanned against a cryptographically signed YARA pack the moment it spawns. Catches in-memory toolkits like Mimikatz, Cobalt Strike, and Mythic implants before they finish loading.

  • Ed25519-signed rule distribution
  • libyara compile, on-device match
  • Auto-quarantine on hit
03

Tamper-resistant agent

The IronCastle agent ships with a kernel-level KeepAlive, watchdog heartbeat, and tamper telemetry. If an attacker tries to pkill it, launchctl unload it, or delete the LaunchDaemon, the agent emits a critical incident and respawns within 1-2 seconds.

  • LaunchDaemon KeepAlive (macOS)
  • 30s heartbeat watchdog
  • Tamper-attempt critical alerts
04

Auto-response cascade

Kill the process, quarantine the file, block the hash tenant-wide, isolate the host from the network — all queued automatically the instant a critical detection fires. SOC analysts pick up the cleaned-up incident, not the active fire.

  • 7-min median containment
  • AUTO-CONTAINED badges on the queue
  • Network isolation (pf, IPv6-aware)
05

Forensic snapshots on demand

One click captures the full process tree, network state, loaded kexts, and system metadata on the affected endpoint — then stores it forever next to the incident. Audit, replay, prove what happened.

  • Process tree + parents
  • Live socket map + listeners
  • Loaded kext & dylib inventory
06

Quarantine vault + hash blocklist

Quarantined files move to a tamper-evident vault with sidecar metadata. The SHA256 is added to a per-tenant blocklist so the same payload is auto-killed on every other endpoint, before it runs.

  • Tenant-wide SHA256 blocklist
  • Auto-block on re-execution
  • VirusTotal & MalwareBazaar enrichment
07

Multi-tenant & white-label MSSP

Partners run their own SOC under their own brand on our platform. Super admin → partner → tenant hierarchy, with isolation enforced at the database row level. Built for MSPs, IT consultancies, and regional SOCs.

  • Partner portal + analyst seats
  • Per-tenant data isolation (RLS)
  • White-label domain + logo
08

Owner transparency, by default

A "What we did for you" panel logs every analyst and AI action against your incidents. A 0-100 security score with 7-day trend lives on the home page. Plain-English answers — no jargon, no dashboards-only-an-MSP-can-read.

  • Live incident audit log
  • Daily security score snapshot
  • Weekly board-ready digest
03 / ServicesBeyond detection

Detection is the start. We cover the whole resilience stack.

Catching the attack is half the job. Getting you back to work — and hardening everything around the endpoint — is the other half. These services wrap the platform so a breach never becomes a shutdown.

01

Backup & disaster recovery

Immutable, ransomware-proof backups that an attacker can't encrypt or delete — paired with rapid restore so a bad day stays a bad day, not a closed business. Cloud or on-prem retention, your choice.

  • Immutable, air-gapped backups
  • Rapid bare-metal & file restore
  • Cloud or on-prem retention
02

Business continuity planning

A tested plan to keep operating through an incident — not a binder that sits on a shelf. We design the failover, write the runbooks, and rehearse the recovery before you ever need it.

  • RTO / RPO design
  • Failover & DR runbooks
  • Tested recovery drills
03

Managed IT & 24/7 support

The day-to-day IT layer under the security layer — proactive monitoring, patching, and certified engineers on call. Annual maintenance contracts with on-site support across the GCC.

  • Annual maintenance contracts (AMC)
  • 24/7 on-site engineers
  • Proactive monitoring & patching
04

Network & perimeter hardening

Most SMB breaches walk in through a flat network and an unmanaged firewall. We deploy next-gen firewalls, enforce who gets on the network, and segment it so one compromise doesn't become all of them.

  • Next-gen firewall deployment
  • Network access control (NAC)
  • Segmentation & zero-trust design
05

Security assessments & pen-testing

Find the gaps before an attacker does. Vulnerability assessments, hands-on penetration testing, and a policy review that maps cleanly to the compliance frameworks your customers and regulators ask about.

  • Vulnerability assessment (VMDR)
  • Penetration testing
  • Policy & compliance review
06

Data protection & encryption

Keep the data itself safe even when a device is lost or stolen. Full-disk and endpoint encryption, data-loss controls, and secure cloud storage — so a missing laptop is an inconvenience, not a notifiable breach.

  • Endpoint & disk encryption
  • Data-loss prevention controls
  • Secure cloud storage
IndustriesWho we defend

From the oil field to the operating room.

Attackers count on certain businesses being under-defended — the ones with valuable data, thin IT teams, and no room for downtime. Those are exactly the businesses we're built for.

ENERGY
Oil, gas & energy
OT-adjacent networks and high-value targets where downtime is measured in barrels, not minutes.
HEALTH
Healthcare & clinics
Patient data, HIPAA alignment, and ransomware crews that specifically target medical practices.
INDUSTRY
Manufacturing & industrial
Production lines that can't stop and legacy systems that were never built to be online.
HOSPITALITY
Hospitality & retail
Card data, distributed sites, and seasonal staff — a wide attack surface on a thin IT budget.
FINANCE
Financial & professional services
Firms holding client money and sensitive records under real regulatory scrutiny.
SMB
SMBs & growing teams
Companies too big to ignore and too small to staff a 24/7 SOC of their own. Our core.
04 / MethodSix days to coverage

From signed contract to fully monitored — in two weeks.

01 — Connect

Hook it up

Deploy the agent and link your cloud, identity, and SaaS accounts. No re-architecture, no agents-on-agents.

02 — Tune

Learn the place

Our AI learns your environment for 7 days, suppressing known-good signals so the noise floor drops.

03 — Watch

Round the clock

24/7 detection, AI triage, and analyst response. You see only what actually matters — by SMS, email, or Slack.

04 — Improve

Score climbs

Score climbs every week as we close gaps in MFA, patching, and identity hygiene — all without you logging in.

05 / OutcomesThe numbers

Measured by what we resolve, not what we alert.

24/7
Human SOC coverage, every day
5–30min
Analyst response SLA, by tier
2
SOC regions — Dubai & Sydney
AI+human
Autonomous detection, human verdict
06 / PricingWatchtower → Keep → Citadel

Premium by design. Per device. Price-locked.

Three tiers, named for what they defend. Every tier includes the AI Guardian. Sparring and Edge Triage start on Keep. The full red-team programme lives on Citadel. Full breakdown on pricing.html.

Watchtower
The outer wall · up to 50 devices
$40/device / mo
$480 / device / year · billed annually
  • AI Guardian — autonomous triage
  • Endpoint + identity + 1 cloud account
  • 30-min response SLA
  • Weekly digest · monthly review
  • SOC 2 evidence pack (read-only)
See full tier →
Citadel
The summit · 100+ devices, regulated industries
$200/device / mo
$2,400 / device / year · billed annually
  • Everything in Keep
  • AI-vs-AI Sparring — AI-generated novel attacks
  • Dedicated analyst pod · 5-min response SLA
  • Quarterly internal pen-test report
  • Apple Endpoint Security custom rules
  • HIPAA · ADGM · PCI · custom frameworks
Talk to sales →
07 / TrustCertifications & alignment

Built to a higher bar than the things it protects.

We're audited, attested, and obsessed with showing our work. Customers can pull every control on demand from the portal.

ISO 9001
Quality management
Certified — process discipline across delivery and support.
ISO 27001
Information security
Certified — ISMS in place, audited annually.
ISO 42001
AI management system
Certification in progress — responsible-AI controls for our detection engine.
SOC 2
SOC 2
Type II attestation expected Q4 2026; trust-services criteria mapped today.
HIPAA
HIPAA aligned
BAA available for healthcare customers on Keep and Citadel.
CIS v8
CIS Controls v8
Benchmarks tracked and enforced across customer environments.
08 / FAQHonest answers

Questions, answered.

What does "AI-powered attacker" actually mean for an SMB?

It means the people targeting you are no longer hand-crafting payloads — they're driving frameworks like Mythic, Sliver, and Havoc with autonomous agents that regenerate malware on every connect, pick lateral targets without a human, and clone voices to social-engineer your finance team. Signature-based antivirus loses to this. You need a defender that runs on the same architecture: continuous behavioural detection, on-device AI, and humans on top for judgment. That's what IronCastle is.

How is this different from CrowdStrike or SentinelOne?

Three things. One: enterprise EDRs cost $80-200/endpoint/month and ship without a SOC. You still need to hire analysts. Two: they're tuned for 5,000-seat enterprises, not 50-seat SMBs — false positives bury small teams. Three: we built IronCastle around an AI-first SOC from day one. The AI Guardian (latest frontier models) reads every incident before a human does — so a 30-person team behind the scenes can defend 2,400 customers without missing anything.

What does the agent actually do on my endpoint?

A signed, tamper-resistant Rust binary that runs as root with full-disk access. It streams process, file, and network telemetry to our collector, runs on-device YARA scans against a signed rule pack, kills processes that match the per-tenant blocklist, isolates the host on instruction (pf-based), and respawns itself within 1-2 seconds if anyone tries to kill it. Zero kernel extensions on macOS, zero performance drag on Windows. Two-minute install.

What happens during an incident?

The AI Guardian triages in seconds, writes the verdict in plain English with MITRE technique IDs, and auto-queues containment — kill the process, quarantine the file, blocklist the hash, isolate the host. A named analyst reviews. If we need you, we contact you on the channel you set (Slack, SMS, phone) with one suggested action. You'll never get paged at 2am for a routine alert. Every action is logged in the "What we did for you" panel on your portal.

Can my IT team see what your analysts see?

Yes. The portal exposes a SOC-grade analyst view with full event timeline, MITRE mapping, AI Guardian reasoning, forensic snapshot, and the live incident audit log. Owners see the simple view by default; admins can flip. MSPs get the partner portal — same view across every tenant they manage.

Where is my data hosted?

Customer data lives in the region you choose — UAE, AU, or EU — and never leaves it. Our parent, Permus Software House, operates from Dubai and Sydney, with regional data planes in each. We hold ISO 9001, 27001, and 42001 certification.