All Posts
Announcements

Introducing the AegisAI Red Team Agent: Test Your Own People Before an Attacker Does

We built an AI agent that runs spear-phishing the way attackers now run it, against your own people, scoped and approved by your security team, so you see who clicks before a real attacker finds out.
Written by
Badr Salmi
Published on
June 30, 2026

For years, the thing that made a spear-phishing campaign dangerous was effort. Researching a target, writing a convincing lure in their context, impersonating a vendor or person they trust, and timing the send all took a skilled human. That effort was the moat. It is gone.

The capability that used to take a nation-state now works for anyone leveraging readily available AI tools. An attacker can point an AI agent at your company, have it read public signals about your people, write a personalized lure for each one, and send from infrastructure that looks legitimate, for about the cost of a cup of coffee. The result is not a clumsy mass email. It is a targeted message that references a real project, a real vendor, and a real person your employees know.

So the test that matters is no longer "can your employees spot a generic phishing email." It is "what happens when an agent as capable as the attacker targets your people on purpose." That is the question the Aegis Red Team Agent answers.

The problem: phishing tests train people for last year's email

Most phishing awareness tools send templates. They reuse a handful of lures, rotate the subject lines, and report a click rate. Employees learn to recognize the template, the click rate drops, and everyone feels safer.

The attacker is not using the template. The attacker is using an agent that writes a fresh, personalized lure for each target, drawn from live public information. A test built on recognition measures whether your people can spot something they have seen before. It does not measure what happens when they see something they have not.

To know your real exposure, the test has to be as capable as the threat.

A new approach: attacker-grade tradecraft, run on your terms

The Aegis Red Team Agent is built the way attackers build them, and run the way a partner should. It does four things, and your security team controls every one of them.

  1. Target. You provide the scope: a domain, departments, roles, or named employees. Nothing runs until your team approves it.
  2. OSINT. The agent gathers public signals autonomously across the web, LinkedIn, news, and code, mapping each target's role, projects, and relationships.
  3. Craft. It generates two to three personalized lures per target, using vendor, tooling, or peer impersonation, with real call-to-action links.
  4. Deliver and measure. It sends from approved infrastructure and captures per-target click, reply, and credential-submit events, with timestamps.

The difference from a template tool is not a feature. That is the whole point. You are measuring your exposure to the attack that is actually coming, not to a pattern your people already memorized.

What your security team gets back

Per-target engagement metrics. Click-through, reply, and credential-submit rates, broken down by employee, team, and lure type. You see who clicked, not just how many.

The lure inventory, with its OSINT trace. Every email the agent generated, paired with the public sources it pulled to write it. This is the part awareness training usually lacks: a concrete example of how a specific person was targeted, and why it worked.

Controls and training recommendations. Concrete next steps, from gateway controls and vendor-impersonation policy to role-targeted training for the people and lure types that performed worst.

Run safely, on your terms

An offensive capability earns trust by how it is run, not just by what it can do.

  • Consent first. Every engagement is scoped and approved with your security team before anything sends.
  • Your people, your terms. You define targets, timing, and tone, and you can pause or stop a run at any time.
  • An auditable trail. Every lure, every source, and every event is logged and handed back as evidence.

The goal is never to catch employees out. It is to find the gaps an attacker would have found first, and to close them with training and controls.

What it looks like in practice

In one scoped run against a Fortune 500 company, targets, sender infrastructure, and lure tone were tuned with the CISO's team before any send. The agent then ran autonomously and delivered a full report. One in four employees clicked and the security team saw exactly who, which lures worked, and the public information that made each one convincing, before a real attacker had the chance to learn the same thing.

Why AegisAI

AegisAI comes from the team that built Gmail's defenses and scaled Google Safe Browsing. The same agents that read your email to stop phishing and business email compromise understand how these attacks are constructed. Pointing that understanding at your own organization, with your team in the loop, turns it into a measurement of your real exposure.

Spear-phishing got cheaper and more capable for the attacker. The way to stay ahead of it is to run the same capability against yourself first.

See who clicks before an attacker does. Request a sample report, or book a demo with your security team.

Don’t Miss the Next Big Threat
Subscribe today to receive updates on the newest cyberattacks, product innovations, and best practices for protecting your organization.

Subscribe

Success! We’ll be in touch soon.
Something went wrong while submitting.
Related topic articles
Read All Articles
Threat Research
Email Security
Red Tide: A Calendar-Invite Worm That Spreads Mailbox to Mailbox
A phishing campaign that spreads itself: in one confirmed case, a personal Gmail account picked up the lure, and nineteen minutes later a different mailbox at the same company was sending it onward.
September 23, 2026
Red Tide: A Calendar-Invite Worm That Spreads Mailbox to Mailbox
One message forks into what a browser draws and a concealed span written for an inbox assistant, which repeats the attacker's ask back to the reader in the product's voice
Threat Research
The Inbox Has a Second Reader: Prompt Injection in Gemini and Copilot
Attackers hide instructions in email that Gemini and Copilot read and that people cannot see. How email prompt injection works, and how Aegis catches it.
September 18, 2026
The Inbox Has a Second Reader: Prompt Injection in Gemini and Copilot
A mail flow diagram: inbound mail passes through the SEG inline to the mailbox, while AegisAI reads the same mail by API with no MX change, producing a second verdict
Technical Guides
How to Replace a Secure Email Gateway Without Breaking Mail Flow
Replace your secure email gateway with no MX change. A parallel-run migration plan: pilot design, stakeholder buy-in, and the metrics that prove it worked.
September 18, 2026
How to Replace a Secure Email Gateway Without Breaking Mail Flow