For security and AI platform teamsTechnical preview

See what the AI agent
did at runtime.

Investigate suspicious commands, credential access, and outbound activity in supported AI workloads. Connect the observed behavior to the process and workload behind it.

01

Investigate the action that followed.

An agent can invoke tools that interact with the operating system. Primod's runtime detections examine supported behaviors such as suspicious command execution, credential access, and cloud-metadata connections.

app.primod.io / runtime / alerts / support-agent
Runtime alert HighIllustrative AI workload scenario · Product UI preview

AI agent tool process read multiple credential stores

Workload
support-agent · Deployment
Namespace
ai-platform
Process chain
agent runner → tool runner → /bin/sh
Observed activity
Reads of several credential files followed by a connection attempt to the cloud-metadata endpoint
Interpretation
Consistent with credential access and a cloud-metadata access attempt
Response
Observe — no action blocked
+0 msTool runner spawns /bin/sh Succeeded
+12 msReads ~/.aws/credentials, then a kubeconfigFile contents are not displayed Succeeded
+37 msConnection to 169.254.169.254:80 Failed

Relative times are documentation data, not a measurement. The timeline supports investigating credential access; it does not establish successful exfiltration.

Where it ran

Podsupport-agent-5c8b9-q7m2z
Nodenode-pool-gpu-01
Containeragent
Image digestsha256:41bd…77c2

Request context

No linked request available

Detection details

Rules: ai-agent-secret-read · ai-agent-ssrf-imds

Technique mapping: ATT&CK and ATLAS references as provided by the rules

Evidence quality

Limited · No linked request available: this workload is not request-instrumented

Complete · Process ancestry complete for this alert

Illustrative AI workload scenario · Product UI preview

02

Keep the workload context.

Review the process lineage and supporting evidence behind a finding so security and AI platform teams can investigate together. Technique mappings add a reference point where the detection provides them.

03

Review response separately from detection.

Use observe mode to inspect supported response policies before considering enforcement on compatible nodes. Confirm the rule, operation, and deployment requirements during evaluation.

app.primod.io / runtime / response-policy
Response policy Technical previewProduct UI preview

Outcome states · select to compare

Observe mode does not block. The policy records what it would have denied.

Rules · policy state · outcome in this state

rce-shell-web-ancestorProgram launch · /bin/shObserve Would deny
cred-read-sa-tokenFile open · service-account tokenObserve Would deny
ai-agent-ssrf-imdsConnect · 169.254.169.254:80Observe Would deny

Observe mode does not block. Enabling enforcement is a separate operator decision and depends on node capabilities. Enforcement can be unavailable on a node; the policy state then reads unavailable with the reason.

Response preview · observe by default · Product UI preview

Questions teams ask.

Does this detect every prompt injection?
No. Runtime behavior can reveal suspicious consequences; it does not establish the intent of every prompt or cover every prompt-injection outcome.
Does a framework mapping prove full coverage?
No. A mapping describes a detection's relationship to a technique. Supported capture and validated scenarios determine what has actually been demonstrated.

Explore runtime evidence for your AI workloads.

Request a demo