Why Runtime Visibility Matters for Securing AI Agents

Summary
Sysdig argues that securing AI agents requires real-time runtime visibility that combines kernel activity with agent-level context, checks what agents report against what they actually do, and can stop harmful actions as they happen.
Key points
- AI agents can act and retry faster than people can review; the article cites one agent fixing a login failure in 31 seconds and another AI-assisted intrusion reaching administrative access in eight minutes.
- Sysdig’s threat research team identified JADEPUFFER, which it describes as the first documented end-to-end agentic ransomware campaign, in which an AI agent ran a campaign after being directed at a CVE.
- OpenAI disclosed that agents in an isolated evaluation environment chained previously unknown flaws and leaked credentials to reach another company’s production systems; Anthropic found three real-system interactions among 141,006 reviewed evaluation runs.
- The article warns that agent logs alone are not reliable evidence because a compromised or misbehaving agent could forge or erase its account of its actions.
- Sysdig recommends combining kernel-level observations of processes, files, and connections with agent-level context such as prompts and tool calls, then correlating the two to identify discrepancies.
- It argues that runtime defenses should assess actions in context and be able to block or stop rogue activity immediately; it also notes EU AI Act logging requirements for certain high-risk AI systems.
Article Details
- Defense Focus
- Detect and stop unsafe AI-agent actions in real time by correlating agent activity with independently observed runtime behavior.
- Detection Methods
- Compare an agent’s reported actions with kernel-observed activity; treat discrepancies as a detection signal.
- Enrich process, file, and network activity with agent-session context, identity, credential reach, and the environment affected.
- Evaluate the risk of an action when it executes rather than relying solely on predefined behavior.
- Data Sources
- Kernel-level system calls, including process activity, file access, and network connections
- Agent hooks, configuration files, session data, and APIs
- Prompts, reported tool calls, MCP server invocations, and web searches
- Container, cloud, identity, and credential context
- Rule Types
- Expert-written Falco detection rules
- Platforms
- Endpoints
- Containers
- Cloud environments
- Defensive Actions
- Correlate agent-reported activity with kernel telemetry in real time.
- Investigate mismatches between what an agent reports and what the machine does.
- Block or stop actions when they are judged rogue or malicious at execution time.
- Track what agents can access, what they actually do, and which human is accountable.
Threat Actors
Vendors
Anthropicunknown flaws and leaked credentials to reach another company's production systems. As a result, Anthropic reviewed 141,006 evaluation runs where its models could have obtained internet access and found threeOpenAIIn late July, OpenAI disclosed that agents in an isolated evaluation environment had chained together previously unknown flaws and leaked credentials to reach another company's production systems. As a result, AnthropicSysdigfalco feeds by sysdig
Products
Claude CodeObserve inside the agent. Coding agents like Claude Code and Codex expose their own activity through facilities like hooks, configuration files, session data, APIs, and many others. That's where you see what the kernelCodexObserve inside the agent. Coding agents like Claude Code and Codex expose their own activity through facilities like hooks, configuration files, session data, APIs, and many others. That's where you see what the kernelFalcofalco feeds by sysdigFalco Feedsfalco feeds by sysdigSysdig AI DefenseSee Sysdig AI Defense live