MITRE ATLAS 2026 Top AI Detection: Unauthorized AI Agent Tool Invocation Chain [
This rule monitors the behavior of AI agent orchestrators to detect potentially malicious activities, specifically focusing on unauthorized tool usage, deep tool invocation chains, and potential data exfiltration. It triggers when an agent invokes a tool outside of its authorized scope, performs an excessively deep sequence of tool calls, or accesses sensitive data followed by an outbound connection to an external endpoint, which is consistent with the MITRE ATLAS AML.T0053 technique.
Sigma

