AI SecurityDetection & ResponseNews

Detecting Rogue AI Agent Activity: Agent Telemetry and Egress Alerts

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Rogue or manipulated AI agents reveal themselves through activity outside their expected scope. These detections focus on egress, unexpected data access and file creation by agent identities.

Signals worth watching

  • Outbound connections from agent environments to government, healthcare or other sensitive external domains not on the allowlist.
  • Agent identities accessing data stores or APIs outside their assigned scope.
  • File creation or modification by agents in locations they shouldn't write to.
  • Repeated denied requests (an agent "probing" for a way through).
  • Sudden increases in agent tool calls or runtime.

Where the data lives

  • Firewall and DNS logs for agent network segments.
  • Cloud audit logs for agent identities (Entra sign-in and audit logs, CloudTrail).
  • Storage and database access logs.
  • Agent platform logs (tool calls, actions, transcripts).

A starting query

Repeated denied egress from agent subnets (Azure Firewall):

AZFWApplicationRule
| where SourceIp startswith "10.60."
| where Action == "Deny"
| summarize Denied = count(), Destinations = make_set(Fqdn, 25) by SourceIp, bin(TimeGenerated, 10m)
| where Denied > 20

Agent identity data access beyond baseline (AWS):

AWSCloudTrail
| where UserIdentityArn has "agent-"
| summarize APIs = make_set(EventName, 50), Resources = dcount(tostring(Resources)) by UserIdentityArn, bin(TimeGenerated, 1h)

Response

  1. Stop the agent and revoke its identity.
  2. Preserve transcripts and logs.
  3. Identify external systems contacted and notify their owners promptly through verified channels.
  4. Document the timeline for regulatory reporting.

Sources

  1. Source
detect rogue ai agent activityOpenAI agent Medicare breach2026

More on this story