All Posts
Announcements

Introducing the AegisAI Red Team Agent: Test Your Own People Before an Attacker Does

We built an AI agent that runs spear-phishing the way attackers now run it, against your own people, scoped and approved by your security team, so you see who clicks before a real attacker finds out.
Written by
Badr Salmi
Published on
July 4, 2026

For years, the thing that made a spear-phishing campaign dangerous was effort. Researching a target, writing a convincing lure in their context, impersonating a vendor or person they trust, and timing the send all took a skilled human. That effort was the moat. It is gone.

The capability that used to take a nation-state now works for anyone leveraging readily available AI tools. An attacker can point an AI agent at your company, have it read public signals about your people, write a personalized lure for each one, and send from infrastructure that looks legitimate, for about the cost of a cup of coffee. The result is not a clumsy mass email. It is a targeted message that references a real project, a real vendor, and a real person your employees know.

So the test that matters is no longer "can your employees spot a generic phishing email." It is "what happens when an agent as capable as the attacker targets your people on purpose." That is the question the Aegis Red Team Agent answers.

The problem: phishing tests train people for last year's email

Most phishing awareness tools send templates. They reuse a handful of lures, rotate the subject lines, and report a click rate. Employees learn to recognize the template, the click rate drops, and everyone feels safer.

The attacker is not using the template. The attacker is using an agent that writes a fresh, personalized lure for each target, drawn from live public information. A test built on recognition measures whether your people can spot something they have seen before. It does not measure what happens when they see something they have not.

To know your real exposure, the test has to be as capable as the threat.

A new approach: attacker-grade tradecraft, run on your terms

The Aegis Red Team Agent is built the way attackers build them, and run the way a partner should. It does four things, and your security team controls every one of them.

  1. Target. You provide the scope: a domain, departments, roles, or named employees. Nothing runs until your team approves it.
  2. OSINT. The agent gathers public signals autonomously across the web, LinkedIn, news, and code, mapping each target's role, projects, and relationships.
  3. Craft. It generates two to three personalized lures per target, using vendor, tooling, or peer impersonation, with real call-to-action links.
  4. Deliver and measure. It sends from approved infrastructure and captures per-target click, reply, and credential-submit events, with timestamps.

The difference from a template tool is not a feature. That is the whole point. You are measuring your exposure to the attack that is actually coming, not to a pattern your people already memorized.

What your security team gets back

Per-target engagement metrics. Click-through, reply, and credential-submit rates, broken down by employee, team, and lure type. You see who clicked, not just how many.

The lure inventory, with its OSINT trace. Every email the agent generated, paired with the public sources it pulled to write it. This is the part awareness training usually lacks: a concrete example of how a specific person was targeted, and why it worked.

Controls and training recommendations. Concrete next steps, from gateway controls and vendor-impersonation policy to role-targeted training for the people and lure types that performed worst.

Run safely, on your terms

An offensive capability earns trust by how it is run, not just by what it can do.

  • Consent first. Every engagement is scoped and approved with your security team before anything sends.
  • Your people, your terms. You define targets, timing, and tone, and you can pause or stop a run at any time.
  • An auditable trail. Every lure, every source, and every event is logged and handed back as evidence.

The goal is never to catch employees out. It is to find the gaps an attacker would have found first, and to close them with training and controls.

What it looks like in practice

In one scoped run against a Fortune 500 company, targets, sender infrastructure, and lure tone were tuned with the CISO's team before any send. The agent then ran autonomously and delivered a full report. One in four employees clicked and the security team saw exactly who, which lures worked, and the public information that made each one convincing, before a real attacker had the chance to learn the same thing.

Why AegisAI

AegisAI comes from the team that built Gmail's defenses and scaled Google Safe Browsing. The same agents that read your email to stop phishing and business email compromise understand how these attacks are constructed. Pointing that understanding at your own organization, with your team in the loop, turns it into a measurement of your real exposure.

Spear-phishing got cheaper and more capable for the attacker. The way to stay ahead of it is to run the same capability against yourself first.

See who clicks before an attacker does. Request a sample report, or book a demo with your security team.

Don’t Miss the Next Big Threat
Subscribe today to receive updates on the newest cyberattacks, product innovations, and best practices for protecting your organization.

Subscribe

Success! We’ll be in touch soon.
Something went wrong while submitting.
Related topic articles
Read All Articles
Threat Research
Email Security
Kali365: How a Device-Code Phishing Kit Defeated MFA Without Breaking It
A $250-a-month phishing kit turned a legitimate Microsoft sign-in feature into a way to steal Microsoft 365 access without a password, a credential form, or a single attacker-owned domain, then staged its own shutdown and kept running under a new name.
AegisAI AI-native email security for Microsoft 365 or Google Workspace
Email Security
AI
Cloud Email Security: Microsoft 365 & Google Workspace
AegisAI is API-native cloud email security for Microsoft 365 and Google Workspace. Stop the phishing, BEC, and account takeover that native filters miss.
TIDALGUEST self-replicating phishing worm: a stolen inbox becomes the next trusted sender, spreading through contact lists. AegisAI threat intelligence.
Threat Research
TIDALGUEST: A Self-Replicating Invitation Phishing Cluster
TIDALGUEST is a self-replicating invitation phishing cluster that turns each stolen inbox into a new sender and layers five evasion techniques past URL scanning.