ReliaQuest GreyMatter Attack https://www.pexels.com/photo/night-traffic-light-trails-in-ankara-turkiye-37690286/

ReliaQuest Wants to Beat Attackers at Their Own AI Speed Game

ReliaQuest’s 2026 Annual Threat Report found that attackers moved from initial access to lateral movement in as little as four minutes last year, the fastest breakout time the company has recorded and 85% quicker than the previous year’s mark. The average across the incidents ReliaQuest analyzed was 34 minutes, down from 48 the year before, and the fastest data exfiltration the company tracked took six minutes, compared to more than four hours in 2024.

Those numbers are the backdrop for GreyMatter Attack, a new capability ReliaQuest recently introduced. ReliaQuest says AI has handed attackers three advantages: speed, scale, and a lower skill bar to pull off a sophisticated attack. GreyMatter Attack is built to hand those same three advantages to the people defending the network.

The New Math of Breakout Time

I’ve written about breakout time and dwell time for years, and the trend line has only moved in one direction. The idea of an attacker moving fast once they’re inside a network isn’t new, but four minutes doesn’t leave room for a human analyst to notice an alert, open a ticket, and start digging. By the time someone looks up, the attacker may already be somewhere else.

Fewer things need to go right for an attack to work now, and more attacks can be attempted at once, largely because AI handles the grunt work that used to require a skilled operator. That’s the problem ReliaQuest built GreyMatter Attack to address.

What GreyMatter Attack Actually Does

A defender types a plain-language prompt into GreyMatter, starting from a user identity, an entry point, or a known attacker technique. GreyMatter Attack returns a visual map of the attack paths that could plausibly follow, along with the gaps involved and recommendations for closing them, ranked by priority instead of dumped in a flat list.

That covers the mapping side. The validation side works differently. Teams can take the attack path GreyMatter generated and run it against their own environment, at the push of a button, to see whether the theoretical path holds up in practice. Whatever the test finds gets routed back into ReliaQuest’s Agentic Teammates, which can write new detections, take response actions, or adjust security controls on their own.

Brian Murphy, ReliaQuest’s founder and CEO, said the point is to use the knowledge only a defender has about their own organization to “test attack paths against their real environments” and close the gaps before an attacker gets there first.

How This Compares to Other Tools

Attack path mapping and automated red teaming aren’t new categories. Security teams have been buying breach-and-attack-simulation tools for a while now, and plenty of vendors already promise some version of continuous exposure validation. What ReliaQuest is arguing is that its version runs on the frontier models already embedded in GreyMatter, so it doesn’t require a separate tool, a separate data pipeline, or specialized red-team expertise to operate.

Whether GreyMatter Attack actually finds more real gaps, or just generates more output for a team to sort through, is something individual security teams will only know once they’ve run it against their own environment for a while. ReliaQuest is positioning it as a natural extension of GreyMatter rather than a bolt-on tool, which lines up with the company’s broader pitch around brokering across frontier models instead of relying on one.

Where This Fits

GreyMatter Attack slots into ReliaQuest’s existing pitch for GreyMatter as an “Agentic Defense” platform, alongside pieces like the Universal Translator for normalizing telemetry across vendors and the AI Model Broker that picks which model handles which task.

The four-minute breakout time comes from ReliaQuest’s own customer incident data, not a hypothetical scenario built to sell software, and it’s the kind of figure that should make any security leader uncomfortable with how their team currently finds gaps. GreyMatter Attack is ReliaQuest’s answer to that discomfort. Whether it actually closes gaps faster than attackers can find them is a question security teams will have to test for themselves, on their own networks.

Scroll to Top