AI Agent Activity Outside Established Operational Baseline
Detects anomalous behavior by an AI agent identity by monitoring for off-hours activity, significant statistical spikes in task invocation volumes compared to a 30-day baseline, or the execution of task categories not previously associated with that specific agent. Such behaviors may indicate account hijacking or unauthorized command injection.
YARA-L

