Research on Emerging
Endpoint and Identity Threats.
Research and analysis on emerging endpoint, mobile, identity and autonomous threats.
What the research is about.
Autonomir research follows a single question: how does an attacker turn a foothold into trusted access, and what would it take for a system to recognise and reverse that without waiting for a person?
That puts the work at the intersection of four things that are usually studied separately — what happens on the endpoint, what happens to an identity, what happens inside a session, and what the enterprise context makes of both. Most consequential intrusions now live in the seams between them.
Where the work is focused.
How attackers compromise, persist on and operate through enterprise endpoints — and which of those stages a system can act on without human interpretation.
Threats against the device increasingly responsible for enterprise identity and access: application risk, network manipulation, phishing delivery and OS-integrity attacks.
Phishing, token theft, session hijacking and abuse of trusted authentication — the techniques that inherit trust rather than defeating it.
Attacks designed to make a compromised user, device or session continue to look legitimate to the controls evaluating it.
How a security system can safely understand, contain and recover from a condition with reduced human latency — including where autonomy should stop.
Research principles.
The work is oriented around conditions rather than samples, because the thing being defended is trust rather than a file.
What an endpoint, identity or session is doing, rather than what a payload matched.
The failures that appear between endpoint, identity, session and enterprise context.
Whether a condition can be safely undone, and what evidence proves it was.
Where automated action is appropriate, and where a decision belongs to a person.
Autonomir has not yet published formal research papers. Rather than display placeholder articles, this page sets out the subject matter and method the team is working against. Published analysis will appear here when it exists — and it will be dated, attributed and specific about what was and was not observed.
See Autonomous Endpoint Defense in Operation.
Protect every endpoint. Continuously establish trust. Respond at machine speed.
