Introduction to AI Cybersecurity Harness
As AI-enabled hacking becomes a bigger threat for cybersecurity and national security, public attention has focused on leading frontier AI companies developing more powerful large language models. However, enterprises are now building their own technology platforms that take these general-purpose LLMs and turn them into bespoke cybersecurity tools, referred to as a "harness."
What is a Harness?
A harness controls the model's behavior, limits its risks, and connects it to internal IT systems and networks so it can work reliably at scale. New research from Cato Networks shows how much power can come from a harness. It paired OpenAI's ChatGPT 5.5 and GPT 5.5-Cyber models with its own tool and tested the abilities of the agent to hack into a victim network with as little human direction as possible.
Across six different scenarios, the pairing achieved complete end-to-end attack chains, including domain administrator privileges and Active Directory access, sometimes in as little as 40 minutes. Guy Weisel, a tech evangelist at Cato Networks, said, "What was most surprising is that first we saw that it was capable of doing accelerated reasoning and attack, and interacting and doing all this by itself, like doing all of the stages of the attacks."
Importance of a Harness
Critically, the most successful scenarios happened when the model was given appropriate operational context from the technical harness developed by Cato Networks. Weisel said, "It does support that it's not just about the frontier model... We found that [our harness] really helps the reasoning" of the LLM. The agent was given some resources to complete its tasks, including an external Kali Linux attack host, the simulated target's public IP address, and a set of low-level domain credentials acquired through phishing.
The Cato Networks research uses OpenAI models, but only as an example. Weisel said he believes other models would likely achieve similar results. In any event, if current trends hold, the kind of capabilities provided by LLMs like GPT 5.5 are likely to be open-source within a year.
Industry Adoption
Cato Networks is far from alone. Most enterprises have their own AI harnesses, and executives tell CyberScoop they are playing an increasing role in more effectively steering the frontier model workflows. While AI tools can struggle to duplicate human workflows in other areas, LLMs have long shown potential in cybersecurity and coding, improving greatly over the past few years.
Eric Doerr, chief product officer at Tenable, said a harness used in the company called "Hexa" offers a defensive advantage: it can work with different commercial LLMs while delivering consistent results. Doerr said, "One of the first things we do when we get a [new] model is say 'Well, let's run it through Hexa and see what we learn.'" Hexa is meant to ensure that whichever model or models become dominant, Tenable will be able to integrate it into their tech stack and protect their most sensitive assets from unintended behaviors.
Conclusion
Dan Rapp, chief AI and data officer at Proofpoint, said their harness, "Satori," has become a critical tool for keeping their agentic AI on track while giving humans the ability to step in when things go awry. Rapp said, "I think what you're seeing in the foundation of frontier models is you have raw intelligence, raw reasoning power, but to get these systems to perform the way you want to, both context engineering – the content provided ensuring that its accurate and relevant – and the harness engineering are essential to actually get the systems to perform well." This suggests that while policymakers and cybersecurity experts have focused on the spread of newer and more powerful frontier models, industry – and likely soon the cybercriminal underground – has quickly developed the kind of technical infrastructure that is becoming far more important to AI cyber defensive and offensive tasks.
Source: CyberScoop