MITRE ATLAS Mapped 2026 – Top AI Agentic Resource Consumption Abuse Detection (A

This rule detects anomalous behavior in AI agent tool invocations, specifically monitoring for high volumes of tool calls, high costs associated with token consumption, or suspicious tool interactions following a flagged indirect prompt injection. This behavior is indicative of potential resource exhaustion (denial of service) or abusive agent behavior as defined by the MITRE ATLAS framework for AI security.