Countering AI with AI: Detect and Respond with ThreatTrace
2026-09-08T14:00
home > Resources > Articles/Blogs > Countering AI with AI: Detect and Respond with ThreatTrace

Recently, a shocking attack incident shook the cybersecurity community: Chinese operators used jailbroken AI coding agents (Claude Code / Codex) to autonomously compromise over 12,000 WordPress sites and steal cryptocurrency wallet keys on a massive scale. At nearly the same time, the U.S. federal government issued a warning that attackers are leveraging AIgenerated exploit scripts to target Siemens S7 PLCs, putting water, energy, and manufacturing critical infrastructure at severe risk. These evolving AIpowered threats demand a new generation of detection and response capabilities – and ThreatTrace, the NDR platform from AIStorm under AsiaInfo Inc., is built precisely to meet that challenge.

 

 

In response to this situation, ThreatTrace offers a “Fighting AI with AI” approach. As a nextgeneration Network Detection and Response (NDR) platform designed for advanced persistent threats, ThreatTrace no longer relies on signatures. Instead, it leverages deep packet inspection, local sandbox dynamic analysis, and threat intelligence correlation to accurately identify AIgenerated stealthy attacks and unknown malicious payloads in northsouth traffic, providing full visibility into advanced threats on the network side. At the same time, ThreatTrace deeply fuses security alerts with asset intelligence, using a risk assessment model to automatically highlight compromised hosts, drastically reducing alert noise and helping security teams quickly pinpoint real threats among thousands of alerts.

 

On the automated response front, ThreatTrace seamlessly integrates with other AsiaInfo security products such as ThreatShield and NGFW. Once a threat is confirmed, the platform can trigger automatic blocking via firewalls or EDR, effectively stopping lateral movement and significantly shortening MTTR – freeing defenders from the reactive dilemma.

 

Notably, ThreatTrace includes an onpremises sandbox that protects data privacy while supporting custom images and dynamic behavioral analysis – particularly suitable for industries with strict data localization requirements. Backed by AIStorm’s global threat intelligence network, ThreatTrace has proven its effectiveness in realworld scenarios, including major national event security护航 and ransomware emergency response in the manufacturing sector.

 

The era of AIpowered attacks has arrived. Only by empowering defense with AI can we gain the upper hand in this asymmetric battle. ThreatTrace is delivering solid NDR capabilities to help enterprises build a visible, defensible, and rapidly responsive cybersecurity perimeter.

 

At AIStorm, cyber resilience is not built through isolated security products. It is achieved through a continuous security cycle of visibility, protection, detection and improvement. 

 

1.Find

The first step is knowing what is exposed.

Using External Attack Surface Management (EASM), organisations can continuously discover internet-facing assets, identify shadow IT, uncover forgotten services, and understand where external risks exist before attackers exploit them.

 

2.Block

Once exposure is identified, risks should be reduced as quickly as possible.

Virtual patching provides immediate protection for vulnerable and legacy systems without waiting for maintenance windows, software upgrades or application changes—helping organisations minimise risk while maintaining business continuity.

 

3.Monitor

Cyber threats evolve continuously.

Network Detection & Response (NDR), combined with Threat Intelligence, enables organisations to monitor network activity, detect suspicious behaviour, identify emerging threats, and uncover attacker activity before incidents escalate.

 

4.Remediate

Security does not end after detection.

The final step is closing the loop—prioritising remediation, reducing measurable risk, and continuously strengthening operational resilience as the threat landscape evolves.

This is an Exposure-to-Response approach: transforming cybersecurity from periodic assessments into a continuous security lifecycle.