Book an Appointment
ADR — Agentic AI Detection & Response

Detection & Response for your AI agents

AI agents write code, invoke tools, and make decisions – classic security monitoring only sees peripheral events. We make agent activity visible, detect attacks on your agents, and build the response capability your SOC needs for it.

Why EDR and SIEM don't see your agents

Classic EDR monitors processes, file access, and network traffic – but the decisive telemetry of AI agents lies in prompts, decision paths, tool calls, and memory operations. Uber puts it succinctly in the paper on its ADR framework: EDR sees the file write, but not the prompt that triggered it. Agents also act through legitimate API calls and MCP connections with valid credentials, passing right through the very control points where security tooling checks for human behavior. In the SIEM, an attack chain of prompt injection, retrieval, and tool abuse falls apart into inconspicuous individual events that no correlation ruleset ties together. According to a 2026 CSA study, 68 percent of organizations cannot distinguish agent activity from human activity. The OWASP Top 10 for Agentic Applications 2026 therefore declares observability a non-negotiable core requirement – and this is exactly where Agentic AI Detection & Response comes in.

Unser ADR-Portfolio

01

Agent telemetry & observability build-out

We inventory your agent landscape – coding assistants, internal automations, customer-facing agents – and unlock their telemetry: prompts, tool calls, execution paths, and memory operations in a unified event schema. We anchor audit trails write-protected outside the agent, so session logs cannot be overwritten by the agent itself.

02

Detection use cases for ASI threats

We develop detection logic along the OWASP Top 10 for Agentic Applications 2026 – from Agent Goal Hijack through Memory & Context Poisoning to Rogue Agents. We combine deterministic policy checks, behavioral baselines, and LLM-assisted evaluation into multi-stage detections with a manageable false-positive rate.

03

MCP & tool-call monitoring

We monitor your agents' MCP traffic: tool definitions, calls including arguments and results, server connections, and data flows. We align detection patterns for tool poisoning, rug pulls, tool shadowing, and indirect prompt injection with the NSA's MCP guidance and the OWASP guide "A Practical Guide for Secure MCP Server Development".

04

Response playbooks & kill switch

We define graduated responses – from blocking individual tool calls through revoking tokens and permissions to terminating entire agent sessions. We anchor kill switches and guardrails at the infrastructure level, where the agent cannot rewrite them, with human-in-the-loop approvals for irreversible actions.

05

SOC & SIEM integration

We bring agent telemetry and detections into your existing security operations landscape: normalization into the SIEM, alert routing, triage processes, and runbooks for analysts who have never handled agent incidents before. This makes agentic AI part of your SOC instead of yet another isolated solution.

06

Continuous operations & tuning

Agents, models, and tool landscapes change on a weekly basis – your detections have to keep up. We maintain use cases and baselines, assess new MCP servers and agent rollouts, test detection against current attack techniques, and report regularly on coverage and incidents.

Open source as a building block: Uber's ADR framework

With ADR (Agentic AI Detection and Response), Uber released an open-source framework under the Apache 2.0 license at the end of July 2026 that secures AI agents through observability, benchmarking, and threat detection – according to the accompanying paper, in production at Uber for over ten months on more than 7,200 hosts. The paper, accepted at MLSys 2026, describes a taxonomy of 17 attack techniques across five tactics and a two-tier detection architecture that produced no false alarms on Uber's own benchmark. Frameworks like this are valuable building blocks, but not a finished solution: Uber did not release the prevention layer, and sensors as well as detections must be tailored to your environment, your compliance requirements, and your SOC. This is exactly where we come in – vendor-neutral, whether with Uber's ADR, commercial runtime security platforms, or your existing SIEM foundation.

Sensor: telemetry from agent tools

The ADR Sensor parses local log and state files of coding agents such as Claude Code, Cursor, or Codex CLI and normalizes them into a unified event schema – as input for a detection pipeline or SIEM.

Two-tier detection

A fast, high-recall triage pre-filters the mass of events; suspicious cases are analyzed by a second stage using agentic reasoning with enterprise context such as source code and threat intelligence.

ADR-Bench: measuring detection quality

Over 300 realistic tasks and 133 MCP servers cover all 17 attack techniques of the associated taxonomy – making the detection performance of different approaches objectively comparable.

Our approach

  1. 1

    Discovery & telemetry inventory

    We map which agents are running in your organization – coding assistants, internal automations, customer-facing agents – and what telemetry they deliver today. The result is a visibility map highlighting the biggest blind spots.

  2. 2

    Threat model & use-case prioritization

    Along the OWASP Top 10 for Agentic Applications 2026 and the 17 attack techniques from Uber's ADR taxonomy, we prioritize which scenarios are realistic and business-critical for your agents. The result is a prioritized detection roadmap.

  3. 3

    Building the detection pipeline

    We implement sensors, normalization, and detection logic – optionally based on open-source building blocks such as Uber's ADR, commercial platforms, or your existing SIEM infrastructure. Every detection is tested against simulated attacks before going into production.

  4. 4

    Response capability & playbooks

    We define graduated response actions, anchor kill switches at the infrastructure level, and rehearse the procedures with your SOC – including escalation paths and human-in-the-loop approvals for irreversible actions.

  5. 5

    Operations, tuning & evolution

    After go-live, we maintain use cases, adapt baselines to new agents and tools, and assess new attack techniques. On request, we take over continuous operations as a managed service.

Let's talk about the visibility of your AI agents

Schedule a no-obligation initial consultation. We assess your agent landscape and show you the next sensible step – from telemetry build-out to continuous operations.