MITRE ATLAS Mapped 2026 – Top AI Agent Tool Supply Chain Compromise Detection (A
Detects suspicious modifications or registrations of AI agent tools within the registry. The rule identifies three core indicators of compromise: usage of an unverified or external registry source, unauthorized tool definition modifications (hash mismatch against baseline), and a suspicious 'update chain' where a non-standard maintainer pushes a tool update that simultaneously increases requested operational scopes.
Microsoft Sentinel (KQL)

