Is OpenClaw an Entry Point for Attackers? - Hunting AI Infostealers and Malicious Skills
Red Canary via YouTube
Power BI Fundamentals - Create visualizations and dashboards from scratch
35% Off Finance Skills That Get You Hired - Code CFI35
Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore the emerging cybersecurity threats posed by OpenClaw, an agentic AI tool that attackers are exploiting through malicious "skills" to create powerful infostealers in this 32-minute episode of SecOps Weekly. Learn from Red Canary's staff threat hunters Tyler Winchester and Brittany Sattler as they demonstrate their systematic approach to hunting for OpenClaw-related threats across enterprise environments. Discover what OpenClaw is and understand the specific dangers associated with AI "skills" and ClawHub, including why this technology matters to enterprise security. Follow the complete threat hunting methodology from the initial planning phase through modeling malicious behavior, examining three key hypotheses for hunting AI infostealers, and executing data queries to identify threats. Gain practical insights into actionable outcomes from threat hunting activities and understand how AI tools are being integrated into modern threat hunting workflows. The presentation covers the entire hunt process with detailed timestamps, providing cybersecurity professionals with concrete strategies for identifying and mitigating risks associated with agentic AI tools that could be weaponized by malicious actors.
Syllabus
- The hunt process
- What is OpenClaw?
- The danger of AI "skills" & ClawHub
- Why OpenClaw matters to the enterprise
- The planning phase: Modeling malicious behavior
- 3 hypotheses for hunting AI infostealers
- Executing the hunt: Querying for data
- Actionable outcomes
- AI in the threat hunting workflow
Taught by
Red Canary