Session

Hijacked by a Document: Catching a Rogue AI Agent in Your Logs

AI agents now read email, open files, and call cloud APIs on our behalf. One poisoned document is enough to turn that agent against you. It uses the agent's own access and valid credentials, and nothing in your stack sees malware. To the SOC, it looks like normal work.

In this session, I hijack a working AI agent in a lab using indirect prompt injection and follow the attack from start to finish through the logs. You will see what the agent did, what evidence it left behind, and which signals give it away: reading data it never touched before, calling tools in an unusual order, sending data to new destinations, and working at a speed no human could match.

From that trail, we build detections step by step using identity, cloud audit, API, and network logs that most organizations already collect. We then cover how to baseline a non-human identity, how to tell a hijacked agent from a buggy one, and how to shut it down without breaking the business process it supports.

Original lab research. No products, no hype. You leave with detection logic you can build the next day.

Learning objectives:

See how a hijacked AI agent behaves and why traditional detections miss it.
Trace an agent attack end to end through common log sources.
Build behavioral detections and baselines for non-human identities.
Contain a compromised agent with a clear response playbook.

Konstantinos Lianos

Cloud Security Specialist - Microsoft Regional Leader & Senior Microsoft Student Ambassador

Athens, Greece

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top