13 million tool calls: auditing every AI coding agent action with Elastic Agent
AI summary · glm-5.3
Elastic Security Labs shows how Cursor hooks plus Elastic Agent turn AI coding agent activity into 13 million huntable security events.
Elastic Security Labs demonstrates auditing AI coding agent behavior by pairing Cursor hooks with Elastic Agent, capturing every tool call, shell command, file read, and MCP request as structured events. The dataset of 13 million captured events can be hunted with ES|QL, giving defenders visibility into agent actions.
- Cursor hooks and Elastic Agent capture all agent tool calls
- Covers shell commands, file reads, and MCP requests
- 13 million structured events analyzed
- Events are huntable with ES|QL queries
Full article
Cursor hooks and Elastic Agent capture every tool call, shell command, file read and MCP request as structured events you can hunt with ES|QL.
This source does not provide full text. Read it at elastic.co.