Agent Behavior Analytics / ABA

Agent Behavior Analytics (ABA)

Guance ABA continuously analyzes AI Agent model calls, tool executions, command parameters, production changes, and token consumption. It identifies high-risk operations, sensitive-data exfiltration, call loops, and cost anomalies on real execution traces, so enterprises can see, investigate, and audit Agent behavior.

Agent Behavior Analytics (ABA)

What problem does ABA solve?

See what an Agent actually does before governing it continuously

Agent risk does not always come from malicious intent. It can also result from variable expansion, permission boundaries, or unsafe tool combinations. ABA analyzes actual model calls and tool executions—not only generated output—and reconnects intent, action, result, and risk evidence in one session context.

A third category of security detection

Complement SIEM and CSPM with coverage for Agent runtime behavior

SIEM focuses on security logs and events, while CSPM focuses on cloud configuration and exposure. ABA examines the Agent execution path to determine which tools were called, what actions occurred, and whether results crossed permission or risk boundaries.

Guance ABA Agent behavior security rules in the official detection library
ABA shares the security detection workflow with SIEM and CSPM and adds an official rule library for Agents.

官方检测规则

六类典型 Agent 风险,在真实执行链路上持续检测

选择规则查看检测条件、证据字段和建议处置。规则基于实际模型与工具 Span,而不是脱离运行结果的静态文本判断。

01

AI_AGENT_001

High-risk shell command execution

tool:exec
AI_AGENT_001 high-risk shell command execution rule
Identify high-risk shell commands on real execution traces while preserving command parameters and match evidence.
风险场景

Identify high-risk commands such as rm -rf, chmod 777, crontab writes, and firewall changes, including cases where variable expansion or path construction mistakenly targets a production environment.

检测逻辑

Match commands and parameters on executed tool Spans instead of inspecting only static text before model execution.

告警证据

Session ID, Span ID, complete command parameters, execution time, and return status.

建议处置

Pause the session, verify scope and approval records, and roll back or restore as appropriate for the impact.

Investigation path

Drill down from a risky Session to the Agent's actual actions

Detection is only the first half. ABA places risk level, session history, and individual call chains on one investigation path, so teams do not have to reconstruct the incident from massive log volumes.

Find sessions that need priority handling by risk level

查看证据Risk level, number of risk events, session status, and duration

得到结论Isolate high-risk investigation targets from large volumes of normal sessions

数据接入路径

Agent SDK / OpenTelemetry → Session, Trace, Span → model calls, tool executions, tokens, and risk signals

适用场景

Designed for security, platform, engineering, and SRE teams running Codex, Claude Code, Qoder, WorkBuddy, or Guance AI Agents.

使用边界

ABA provides continuous detection, investigation, and auditing. Approval, blocking, or automatic termination of high-risk actions should be configured through the organization's permission and runtime policies.

查看接入文档

Supported integrations

Observe the Agents you already use

Whether it is a coding Agent, operations Agent, or an in-house enterprise Agent, standard trace data lets teams analyze sessions, models, tools, cost, and risk in one view.

Explore AI Agent Observability
  • Codex
  • Claude Code
  • Qoder
  • WorkBuddy
  • Guance AI Agent

Frequently asked questions

ABA is a security detection capability for AI Agent runtime behavior. It analyzes model calls, tool executions, command parameters, file access, network exfiltration, production changes, and token consumption to continuously detect, investigate, and audit high-risk Agent behavior.

Related resources

See how Agent Behavior Analytics fits your business systems