Use Cases

Real-World Security Protection

From development security to data leak prevention to supply chain governance, AIDR covers core enterprise Agent security scenarios.

Development Security

Dev Agent Behavior Governance

When developers use IDE Agents and CLI Agents, they may inadvertently trigger sensitive file access, unauthorized outbound connections, or model switches. AIDR tracks all tool call chains in real-time, detecting anomalies without interrupting the development flow.

Typical Detection Scenarios

  • IDE Agent accessing .env / .ssh / credentials file alerts
  • CLI Agent executing curl to unknown domain detection
  • New tool / new model first appearance instant notification
  • Dev environment vs production environment baseline comparison

Data Leak Prevention

Insider Threats & Data Exfiltration

Agents can be exploited for data theft, such as via BashExec → curl to exfiltrate code, or cross-domain transfer of sensitive data through MCP. AIDR monitors all egress traffic and tool combination patterns.

Typical Detection Scenarios

  • High-risk tool + new endpoint combination detection
  • Permission decision deny→allow oscillation pattern identification
  • Single-session tool call frequency anomaly spike alert
  • Sensitive path bulk access drift detection

Supply Chain MCP

MCP Ecosystem Security

MCP extends Agent capabilities but also introduces supply chain risks. AIDR tracks all MCP server/tool calls, discovering non-whitelisted combinations and unauthorized cross-domain access.

Typical Detection Scenarios

  • New MCP endpoint auto-discovery & asset registration
  • Non-whitelisted MCP server/tool combination alerts
  • MCP authentication status change detection
  • MCP call chain Trace traceability

Your scenario not listed?

AIDR's event contract is universal. Let's discuss your specific needs together.