AML-ATLAS-2026-04 | MITRE ATLAS Mapped 2026 – Top AI Threat Detection: AI Agent Tool Credential Harvesting (AML.T0098)

Detects instances where an AI agent tool invocation contains potential credential data (API keys, tokens) followed by a suspicious sign-in or Key Vault access event from an atypical location for that specific identity within a short timeframe. This rule monitors for potential exfiltration or abuse of credentials handled or exposed by AI agents.