Session

Detection Engineering for AI Agents: Building SOC Visibility into Autonomous Systems

Abstract:
As AI agents become embedded across enterprise environments—interacting with internal systems, executing actions, and making autonomous decisions—they introduce a new and largely unmonitored attack surface. While much of the current focus in AI security is on preventing prompt injection and model manipulation, far less attention has been given to a critical question: how do we detect when an AI agent is being abused?

This talk presents a practical approach to detection engineering for AI agents, focusing on how security operations teams can gain visibility into autonomous systems and identify malicious or unintended behavior. Drawing from real-world architectures, we explore how AI agents interact with tools, APIs, and cloud services, and how these interactions can be instrumented, logged, and analyzed using existing security monitoring frameworks.

Through a series of realistic scenarios, we demonstrate how compromised or manipulated agents exhibit observable patterns—such as anomalous tool usage, unusual data access, and unexpected outbound communication—that can be detected using telemetry pipelines and SIEM-based analysis. Attendees will see how to translate agent activity into actionable security signals and build detection logic aligned with modern SOC practices.

The session also highlights the limitations of current logging and monitoring approaches, showing why traditional application telemetry is insufficient for agentic systems. We introduce a structured model for capturing agent behavior, including input/output tracing, tool invocation auditing, and context-aware event correlation.

Finally, we present practical strategies for implementing detection and response capabilities for AI agents, including alerting on high-risk behaviors, integrating agent telemetry into existing security workflows, and designing agents with observability in mind.

This talk bridges the gap between AI security research and operational security, equipping defenders with the tools and frameworks needed to monitor, detect, and respond to threats in autonomous AI systems.

Key Takeaways:

Why AI agents create a new blind spot for security operations
How to instrument and log AI agent behavior effectively
Detecting anomalous tool usage, data access, and agent-driven actions
Building SIEM detections and telemetry pipelines for agent activity
Practical approaches to integrating AI agents into existing SOC workflows

Session Format:
Technical deep dive with real-world scenarios and detection-focused demonstrations.

Niladri Sekhar Hore

F50 - Lead Engineer - Threat Detection & Applied Intelligence (AI / ML)

Bengaluru, India

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top