Investigating AI Agent Security Incidents

All AI agent violations appear in the unified Incidents > Exfiltration Prevention view - there is no separate incident queue. This page explains how to identify, review, and respond to AI agent incidents.


Finding AI Agent Incidents

Navigate to Incidents > Exfiltration Prevention. AI agent incidents are identified by the "AI Prompt" event type label in the incident list.

Incident List Columns

Column

Content

Event Label

"AI Agent Hooks" label for Hooks and AI Agent Telemetry for OTEL

When

Relative time (e.g., "2 hours ago")

Actor

Machine name and device ID

Policy

Policy name that triggered the violation

Status

Active, Blocked, Ignored, Resolved or Acknowledged

Last updated

Was this helpful?