Agent

Detection Agent

Continuously analyzes AI agent behavior, identities, permissions, and interactions to identify suspicious activity and emerging threats.

See the platform
Detection Agent product view
Capabilities

What the Detection Agent does inside Wing.

CAP.01
Behavioral Threat Detection

Continuously analyze AI agent behavior to identify suspicious activity: abnormal behavior, unexpected tool usage, unusual access patterns, and behavioral anomalies.

CAP.02
Identity Threat Detection

Identify threats targeting AI agent identities: compromised credentials, privilege abuse, and unauthorized authentication attempts.

CAP.03
Attack Path Analysis

Reveal how attackers could move through your agent ecosystem: chained attack paths, lateral movement, and privilege escalation opportunities.

CAP.04
Context-Aware Correlation

Correlate signals across your agent ecosystem to surface multi-stage attacks and high-confidence threat indicators.

Integration map

Where the Detection Agent reads and writes.

agent
Detection Agent
SIEM
EDR
CloudTrail
GitHub
Okta
read write read/write
Security & governance
guardrails
  • Detection rules are tenant-scoped, versioned, and continuously updated.
  • High-confidence detections enriched with context to minimize alert fatigue.
  • Privacy-preserving signal analysis.
  • Enables the Enforcement Agent to take immediate action against confirmed threats.
audit.log
00:39:05  detect.anomaly ok severity=medium agent=glean
00:39:12  detect.access_pattern WARN path=hr-db user=bot.ops
00:39:28  detect.correlate ok confidence=0.94 signal_count=3
00:39:44  detect.threat_intel match=T1538 source=ti-feed

Deploy the Detection Agent with Wing.

All agents