Presented at DEF CON 34
Attackers Don't Need Shells, They Need Prompts: This Is How We Hunt Them
Abstract
Threat hunting was built around network traffic, process execution, authentication events, and endpoint activity, but in AI systems the most important signals are embedded in language: for example, prompts, tool calls, retrieval data, and model responses. Traditional techniques such as exact match rules, signatures, behavioral filters, and one off LLM analysis either miss semantically equivalent attacks or become too costly to apply at scale. We present Intent based Threat Hunting, a practical method for overcoming the language barrier and effectively hunting threats against AI agents.