1 min read
The Convergence of Malware-Free Attacks and AI-Enhanced Social Engineering
Learning from the 2024 CrowdStrike Global Threat Report As the digital landscape evolves, so too does the nature of cyber threats. A significant...



Uncover industry news and insights across End User Computing, Network, Storage and Cloud.
REPORTS, WHITEPAPERS & CASE STUDIES
Practical insights and outcomes through reports, whitepapers and case studies.

Learn about our certifications, confirming our commitment to ensuring that our customer data is protected.
Experienced technology leaders driving innovation, cybersecurity, cloud, and digital transformation outcomes across Australia.
We protect your privacy and handle your personal information with care and security in mind.
We protect your privacy and handle your personal information with care and security in mind.

4 min read
Secure Agility September 28, 2026
AI agents can access data, call tools and take action across your environment. Learn what AI Detection and Response (AIDR) adds to EDR and MDR, and where to start securing the agents your organisation already uses.
Most organisations now have some form of detection and response in place. Endpoint tools record what happens on devices, and a managed service or internal team acts on what those tools see. That model works well for the threats it was built for.
AI agents introduce a different kind of activity. They run inside the same environment, with the same permissions as the people who deploy them, and they take actions without a person approving each step. AI Detection and Response (AIDR) is the capability that makes this activity visible and controllable. This article explains what it is, how it relates to MDR and EDR, and what it changes for your security operations.
The term covers three separate problems, and separating them makes the rest of this topic clearer.
AI for security uses AI to help defenders work faster, for example triaging alerts or summarising an investigation.
Security against AI-enabled attackers deals with adversaries using AI to compress the time from reconnaissance to impact.
Securing the AI you have deployed protects the agents, models and data your own organisation is now running.
AIDR addresses the third problem. Your existing controls were largely designed for the first two.
A chatbot produces text. An agent executes. It reads files, calls APIs, runs commands, sends messages and chains those actions together to complete a task. It usually does this using a human user's session or a service account, so at the operating system level its activity looks like a legitimate user doing legitimate work.
Two properties make this hard to secure with conventional approaches.
The first is non-determinism. The same instruction, tools and permissions can produce a different sequence of actions each time an agent runs. Most security assurance assumes the same input produces the same output. That assumption underpins testing, change control and audit. When behaviour can only be sampled rather than certified, assurance has to move to runtime, where the actions actually occur.
The second is the absence of a baseline. Detection has traditionally worked by identifying deviation from normal. A new agent has no history, and its legitimate behaviour is fast, high-volume and wide-ranging. An agent that reads a thousand documents may be doing its job or moving your intellectual property. Volume alone will not tell you which. Intent and scope will: was this agent meant to touch this data, in this context, for this task.
Endpoint Detection and Response (EDR) records process activity, file changes, network connections and user behaviour on each device. When an agent runs, EDR sees the processes it spawns and the files it touches. That visibility is valuable and remains the foundation.
What EDR cannot do on its own is connect those actions back to their cause. It does not see the prompt that triggered them, whether that prompt contained injected instructions from a document the agent read, which tools the agent invoked, or whether the sequence of actions matched what the agent was authorised to do. Each individual action can look routine. The problem only shows up when the chain is read together, from prompt to identity to tool call to system action.
AIDR adds that layer. It discovers which AI tools and agents are running, records the interactions between agents, tools and data, connects them to the endpoint telemetry EDR already collects, and enforces policy at the moment an action is about to happen.
MDR is not a tool. It is the people and process operating on top of your security tooling, around the clock. That distinction still holds with AI.
AIDR is a capability that generates a new class of telemetry and a new class of detection. Someone still needs to investigate what it finds, determine what an agent has already done by the time a detection fires, contain it, and decide what changes to prevent a repeat. Agents can complete many actions across several systems in the time it takes a person to open an alert, so working out the scope of an incident matters as much as detecting it.
In practice, AIDR extends the scope of an MDR service rather than replacing it. The same analysts, the same escalation paths and the same reporting apply. What changes is that agent activity becomes part of what the service covers, and analysts gain the context to reconstruct what an agent did rather than only the processes it left behind.
For organisations already running CrowdStrike Falcon, which is the platform at the core of Secure Agility's MDR service, AIDR is delivered through the same sensor and console, with agent activity flowing into the same investigation workflows. There is no additional deployment, and no separate console for analysts to monitor.
The practical starting point is discovery. Very few organisations can list the agents running in their environment, because they are often stood up inside a Microsoft 365 licence, a developer's tools, or a SaaS product that quietly shipped an assistant. Establishing that inventory is non-threatening, quick, and almost always informative. From there, governance, data protection and runtime controls can be applied in order of risk.
If you would like to understand where AI agents are already operating in your environment and what your current detection coverage would show you about them, talk to Secure Agility's MDR team.
AIDR is the security capability for discovering, monitoring and responding to AI agents and AI tools as they operate inside an organisation. It focuses on runtime: what agents actually do, which tools they call, what data they access, and whether that matches what they were authorised to do.
No. AIDR is a capability that produces new telemetry and detections. MDR is the managed service that investigates and responds to them. AIDR extends what an MDR service covers.
EDR sees the processes and files an agent touches, but not the prompt that caused them, the tools it invoked, or whether the action chain was within scope. AIDR connects those pieces to the endpoint telemetry EDR already collects.
On the CrowdStrike Falcon platform, no. AIDR runs through the existing sensor and console.
With discovery. Build an inventory of the AI tools and agents already running, then apply governance and runtime controls based on the risk each one carries.
Secure Agility can help you identify the AI agents operating in your environment, assess where your current security coverage has gaps, and decide which controls to prioritise. Talk to Secure Agility →
1 min read
Learning from the 2024 CrowdStrike Global Threat Report As the digital landscape evolves, so too does the nature of cyber threats. A significant...
1 min read
From road construction projects to major infrastructure developments, construction sites are busy, high-risk environments. Delays, defects, safety...
1 min read
If you need to better understand the scope and breakdown of cloud risks and how to deploy security in a frictionless manner to prevent data breaches...