Research · curated 12 Sep 2026
When AI agents look like attackers: what behavioral telemetry tells us
First reported sophos.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
AI coding agents are generating adversary-like behavioral telemetry — running low-reputation executables, automating browser tasks, and triggering credential-access rules — creating detection-engineering challenges and alert noise that defenders must learn to distinguish from real attacks.
A joint analysis from The Hacker News and Sophos X-Ops examines telemetry showing that enterprise AI coding agents (Claude Code, Cursor, Codex, and others) increasingly trigger SOC alerts and endpoint behavioral detection rules originally designed for adversaries. AI-related alerts remained only 0.43% of all SOC alerts but grew 685% between February and June 2026, with agent activity frequently mapping to MITRE ATT&CK tactics like Credential Access and Execution.