ZeroHour
Elastic Security Labspublished ()ingested Wieger van der Meulen1

13 million tool calls: auditing every AI coding agent action with Elastic Agent

infoAI safety & securityimportance 45
AI summary · glm-5.3

Elastic Security Labs shows how Cursor hooks plus Elastic Agent turn AI coding agent activity into 13 million huntable security events.

Elastic Security Labs demonstrates auditing AI coding agent behavior by pairing Cursor hooks with Elastic Agent, capturing every tool call, shell command, file read, and MCP request as structured events. The dataset of 13 million captured events can be hunted with ES|QL, giving defenders visibility into agent actions.

  • Cursor hooks and Elastic Agent capture all agent tool calls
  • Covers shell commands, file reads, and MCP requests
  • 13 million structured events analyzed
  • Events are huntable with ES|QL queries
Full article

Cursor hooks and Elastic Agent capture every tool call, shell command, file read and MCP request as structured events you can hunt with ES|QL.

This source does not provide full text. Read it at elastic.co.