AegisAgent — SOC Console

Integrity-anchored Agent SOC: detect, contain, and prove every agent action.

Alerts

Severity Rule Agent Summary Created ID
Loading…

Incidents

Severity Kind Agent Summary Opened ID
Loading…

Overview (last 24 h) static demo

Protected actions
128
Blocked (deny)
7
Pending approvals
3
Open incidents
1
Detections / alerts
12
Receipt chain
✓ verified
Mean time to contain
8 s

Incident detail — provable timeline demo content

inc_01J — Prompt injection → high-risk GitHub action
agent coding-agent-prod · run run_991 · severity critical · status: contained (frozen)
ATLAS AML.T0051 OWASP LLM01
✓ timeline verified (receipt chain)
10:02:31
Allowed github.read_issue — public issue #391
rcpt …a1b2
10:02:31
context labelled untrusted_external (deterministic)
rcpt …a1b2
10:03:04
Detection AEG-1002 confused-deputy-mutation (level 12)
AML.T0051
10:05:10
Blocked github.merge_pull_requestmain · policy forbid-untrusted-mutation
rcpt …c3d4
10:05:11
approve-then-swap attempt → SDK fail-closed (action_hash mismatch · T-A1)
rcpt …c3d4
10:05:12
Active Response — agent frozen; Slack alert → #agent-security
contained
10:06:00
RCA drafted (sandboxed narrator) — root cause: untrusted issue carried hijack instructions
RCA
Evidence: receipt chain …a1b2 → …c3d4 (one-click verify) · approver: rejected · executed: nothing

Live decision feed demo content

12:04:11
Blocked github.merge_pull_request after untrusted issue context · trust: untrusted_external
action …9af1
12:03:58
Approval created github.merge_pull_requestmain · bound to action_hash
group: platform-leads
12:03:40
Allowed github.read_issue from public repository
risk: low
12:03:22
Drift MCP github-mcp-demo manifest hash ≠ pinned (AEG-4002)
AML.T0010
12:03:01
MCP discovered github-mcp-demo.create_issue
status: pending