// 2 ZERO-DAY · 5 CVE · 2 EXPLOIT · 1 ADVISORY IN THE LAST 24H→
An autonomous AI investigator correlated signals across three platforms in minutes to reconstruct a cross-platform data exfiltration campaign that began with a compromised GitHub token.

On September 29, 2026, Wiz published a case study in which its autonomous SOC investigator, Blue Agent, reconstructed a cross-platform data exfiltration campaign starting from a single alert on a compromised CI/CD service account. The attack chain spanned 18 private GitHub repositories, two distinct AWS accounts, and a production domain controller, with the investigation completed in minutes rather than the hours estimated for a human analyst. The case raises concrete questions about the speed of autonomous AI agents and the limits of cross-verification when all evidence comes from a single vendor.

Key Takeaways
  • A compromised GitHub token enabled the cloning of 18 private repositories containing hardcoded AWS credentials, which opened the pivot to the cloud.
  • The actor operated from a Zenlayer Inc IP (ExpressVPN) with a Kali Linux user agent, anomalous against the 30-day historical baseline of the svc_automation service account.
  • Blue Agent automatically correlated AWS management plane (CloudTrail), data plane (S3), and GitHub audit logs to reconstruct the full chain.
  • The investigation identified remote code execution on a production domain controller via SSM SendCommand and three custom Python scripts for SQL, PostgreSQL, and billing exfiltration.

How the Investigation Started: Three Simultaneous Alerts on a CI/CD Service Account

The investigation began when three detection rules fired simultaneously against a single actor in an AWS account. Blue Agent, Wiz's autonomous SOC investigator launched in GA for Wiz Defend customers, analyzed the signals in parallel. The actor was svc_automation, an IAM service account created in 2018 for CI/CD pipelines, not a human user. The user agent contained "kali-amd64", indicating Kali Linux. The source IP belonged to Zenlayer Inc, a hosting provider associated with VPN exit nodes, geolocated to Taiwan with ASO Zenlayer Inc (ExpressVPN).

The 30-day baseline showed svc_automation operating exclusively from three Amazon-owned IPs with user agents TeamCity Server and aws-sdk-go, performing routine CI/CD operations. In the detection window, the actor used aws-cli on Kali Linux from a Zenlayer IP, with anomalous operations: AssumeRole with administrative privileges and SSM SendCommand. "Any one of these signals could have a legitimate explanation. Together, they warranted deeper investigation," states the Wiz blog.

The Cross-Account Pivot: Same Actor, Same Pattern, Second Access Key

Blue Agent extended the Zenlayer ASO query across the entire tenant. It found only two actors with this profile: both were svc_automation, in two different AWS accounts. In the second account, the attacker used a different permanent access key but the same Kali Linux user agent and same Zenlayer IP range. The timeline in the second account shows: at 09:55 UTC, AssumeRole to the same CI role from a different Zenlayer IP; at 10:06 UTC, SSM SendCommand targeting an EC2 instance with naming convention PROD-*******-DC1, indicating a production domain controller.

The attacker achieved remote code execution on the domain controller. In parallel, the data plane revealed three Python scripts uploaded to an S3 bucket from a Zenlayer IP: mssql_table_export.py, pg_table_export.py, billing_export2.py. The names indicated custom tools for extracting data from Microsoft SQL Server, PostgreSQL, and billing systems. The scripts were uploaded from Kali Linux, then the compromised EC2 instances retrieved and executed them via curl from Amazon-owned IPs.

"This was the moment the investigation escalated from compromised credentials in multiple accounts to active data exfiltration operation with custom tooling."

The GitHub Correlation: From Source Theft to Cloud Compromise

Cross-account IP analysis revealed a third actor from the same attacker IP: a GitHub user. GitHub audit logs showed that hours before the AWS activity, a compromised token was used to clone 18 private repositories from the same Zenlayer IP. The GitHub compromise was identified as the initial access phase, not a separate incident. The private repositories frequently contained hardcoded AWS credentials, database connection strings, and service account configurations. The attacker likely extracted svc_automation's AKIA access key directly from the cloned repository contents.

The complete attack chain reconstructed by Blue Agent comprises five phases: Initial Access (GitHub source theft), AWS Pivot & Authentication, Lateral Movement & Execution (SSM on domain controller), Tool Staging (script upload to S3), Data Exfiltration. The automatic correlation spanned three platforms: AWS CloudTrail for the management plane, S3 data events for the data plane, GitHub audit logs for the SaaS layer. The historical baseline comparison was multi-dimensional: IP, user agent, ASO, operations, and timing.

Speed and Limits: Minutes Versus Hours, But With Single-Source Dependency

The full investigation, from initial alert to final classification, was completed in minutes by Blue Agent. According to the Wiz case study, a human analyst would have taken hours for the same context switching between CloudTrail, S3 data events, and GitHub audit logs, with manual queries and sequential correlations. Blue Agent executed in parallel, without interruption to the investigative flow.

However, the case presents documented limits. The source does not specify the exact date of the incident beyond the 09:55 and 10:06 UTC timestamps. The attacker's identity does not emerge: nation-state, cybercriminals, or other operators are not identifiable from the published evidence. The actual volume of exfiltrated data in GB or records is not quantified. It is not declared whether the data was subsequently sold, published, or used for extortion. The GitHub token compromise vector — phishing, credential stuffing, or other — is not specified. It is unclear whether the victim is a real Wiz customer or a composite/anonymized case study. The case study does not document whether the fix or remediation was automated by Blue Agent or required human intervention.

Why This Matters

The case study demonstrates that compromise of a GitHub token can propagate to remote code execution on an AWS domain controller within a timeframe measured in hours, through hardcoded credentials in private repositories. For cloud-native enterprises, this confirms that the security perimeter is no longer the network boundary but the single secret in a versioned configuration file. For SecOps teams, it shows the potential of autonomous AI agents to reduce MTTR from hours to minutes, but with a trade-off: the speed of cross-platform correlation depends entirely on the quality and coverage of the data from the vendor providing the platform.

The reliance on a single source for all incident facts — no cross-confirmation from CERTs, other vendors, or external researchers — constitutes a structural limit. The dossier does not specify specific corrective measures. The case raises questions about preventive secret scanning as an upstream control, but the source does not document it as an operational requirement. The takeaway is that the speed of the autonomous AI agent is real and measurable, but its investigative effectiveness remains anchored to the completeness of the dataset the organization has integrated into the platform.

Sources

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. wiz.io