Agent
Detection Agent
Continuously analyzes AI agent behavior, identities, permissions, and interactions to identify suspicious activity and emerging threats.

Capabilities
What the Detection Agent does inside Wing.
CAP.01
Behavioral Threat Detection
Continuously analyze AI agent behavior to identify suspicious activity: abnormal behavior, unexpected tool usage, unusual access patterns, and behavioral anomalies.
CAP.02
Identity Threat Detection
Identify threats targeting AI agent identities: compromised credentials, privilege abuse, and unauthorized authentication attempts.
CAP.03
Attack Path Analysis
Reveal how attackers could move through your agent ecosystem: chained attack paths, lateral movement, and privilege escalation opportunities.
CAP.04
Context-Aware Correlation
Correlate signals across your agent ecosystem to surface multi-stage attacks and high-confidence threat indicators.
Integration map
Where the Detection Agent reads and writes.
agent
Detection Agent
←SIEM
←EDR
←CloudTrail
←GitHub
←Okta
← read→ write↔ read/write
Security & governance
guardrails
- Detection rules are tenant-scoped, versioned, and continuously updated.
- High-confidence detections enriched with context to minimize alert fatigue.
- Privacy-preserving signal analysis.
- Enables the Enforcement Agent to take immediate action against confirmed threats.
audit.log
00:39:05 detect.anomaly ok severity=medium agent=glean 00:39:12 detect.access_pattern WARN path=hr-db user=bot.ops 00:39:28 detect.correlate ok confidence=0.94 signal_count=3 00:39:44 detect.threat_intel match=T1538 source=ti-feed