Most Popular 2026 AI-Based Attack Detection — AI Agent Framework RCE via Plugin Invocation Path Traversal
Detects potential exploitation of AI agent frameworks, such as Semantic Kernel, where plugin or tool invocation primitives are abused to execute arbitrary commands or manipulate files via path traversal. The rule monitors for AI-hosting processes (e.g., python.exe, node.exe) spawning shell child processes or file-related commands containing path traversal sequences (e.g., '..\..\') paired with file operation keywords.
Sigma

