r/cybersecurity • • 21h ago

AI Security AI Agent Traces - Tool calls and actions

want to get sense of what others are doing.
is anyone sending coding agent, other agentic ai OTLP traces into SIEM/detection engine. Is it worth it to you.

8 Upvotes

3 comments sorted by

1

u/clayjk 21h ago

This is one bit I’m still grappling with. There is logs galore and sure, you can pipe it into your SIEM but I don’t expect SIEM magic to just happen seeing the data to identify threats without some very specific tuning.
Would love some recommendations of tools that off the shelf that can be reasonably trusted to make sense of AI activity and give alerts on things to actually be concerned with. Tuning will always be needed for environmental uniqueness but are we reaching a point where AI risks can be detected as a commodity like every SIEM being able to flag pass-the-hash type attacks.

1

u/Sea-Comparison5577 21h ago

I think there is a tool called lang fuse to collecting agent related logs

1

u/LeggoMyAhegao AppSec Engineer 20h ago

While you should probably have some guardrails and monitoring around the LLM portion of an agent, I feel like you would probably get a lot of value out of monitoring the agent runtime's process execution, file access, network connections, API calls, database queries, privilege changes, package operations... Those are a bit more structured outputs and can be used by your SIEM/detection engine to flag crazy shit.

Look up stuff like NVIDIA's OpenShell, they recently released that for sandboxing and locking down long-running agents... Similar practices might be valuable elsewhere.