Detecting Claude Code activity using OpenTelemetry
How telemetry can reveal agent sessions, tool calls, commands and potentially dangerous workflows.
Practical research, detections and security controls for AI agents, coding assistants and autonomous systems.
Understand how agents interact with tools, credentials, source code and enterprise systems—and how to observe, control and investigate their actions.
AI agents can execute commands, access files, call external services, modify source code and use enterprise credentials. Traditional logs may record the action without clearly showing whether it was initiated by a human, an AI assistant or an autonomous workflow.
They can execute commands, modify resources and trigger complex enterprise workflows autonomously.
They may reach source code, secrets, internal APIs, cloud systems and highly sensitive data.
Human and agent actions often look identical in existing audit logs, hindering investigations.
Telemetry, attribution, session identity and behavioural baselines.
MCP servers, tools, plugins, prompt injection and permissions.
Practical detections using OpenTelemetry, SIEM, endpoint, identity, cloud and source-control logs.
Least privilege, approval workflows, isolation, policy enforcement and secure deployment patterns.
How telemetry can reveal agent sessions, tool calls, commands and potentially dangerous workflows.
A practical analysis of trust boundaries, tool permissions, prompt injection and server compromise in Model Context Protocol environments.
Why audit logs struggle to distinguish human actions from autonomous activity, and how to fix the attribution gap.
Our methodology relies on practical experimentation, active data collection, and validated engineering.
Agent behaviour
Logs & telemetry
Attack paths
Detection controls
Workflows
Findings
A practical checklist for evaluating coding assistants, MCP servers and autonomous agents before enterprise deployment.
Watch hands-on implementation and architecture reviews on YouTube.
Building robust detections using OpenTelemetry logs from popular dev tools.
Watch video →Understanding the Model Context Protocol, trust boundaries, and authorization models.
Watch video →Practical examples of SIEM queries for detecting excessive agent permissions.
Watch video →Agent Security Lab is an independent technical research project focused on securing AI agents and AI-assisted development environments.
The lab studies how autonomous systems interact with enterprise identities, tools, source code, cloud environments and sensitive data. We focus on evidence-based research rather than marketing, operating as a dedicated engineering publication for security practitioners.
The objective is to turn emerging AI security risks into practical controls, telemetry strategies and deployable detections.
Receive new detection ideas, technical experiments and implementation guidance for securing AI agents.