The RT Protect EDR solution detects the presence of such software, as well as its activity: running commands, working with files, and other actions on the device.
RT-Information Security Company (RT-IB, part of Rostec State Corporation) has developed expertise packages to identify "shadow AI" — AI agents that are used on work computers without the control of the information security service. RT Protect EDR detects not only the presence of such software, but also its activity: running commands, working with files, and other actions on the device. This will help companies control the risks associated with AI access to corporate data and systems.
Company employees are increasingly using AI agents to work with code and other tasks directly on their work computers. Intelligent assistants can get the project context, read and modify files, run commands, access external and local models, and use browser plug-ins and automation tools.
"The use of AI tools in itself is not a sign of an information security breach. At the same time, the AI agent acts on behalf of the user and inherits his powers, which means it can potentially access repositories, access keys, configuration files, and other data available to the account. In this regard, when evaluating the activity of an agent, we consider it necessary to take into account which user it works on behalf of, what data it accesses, and what actions it performs. The appeals of AI processes to such objects require special attention during the investigation. Our goal is to provide customers with a tool that allows them to see the real activity of AI agents and assess the risks associated with it," said Dmitry Prendetsky, CEO of RT—IB.
RT-IB specialists analyzed common AI tools, including Claude Code, OpenAI Codex, GitHub Copilot CLI, Gemini CLI, Cursor, Cline and OpenHands, as well as the local Ollama model launch environment. Experts have studied the specifics of how they work on a computer: the processes they run, the files and directories they use, the installation methods, and network accesses. Based on these data, it was possible to identify the signs by which the system can detect the activity of various AI agents.
The study showed that it is impossible to detect such activity only by network traffic or the presence of an installed program. Local models can run directly on a computer without accessing external services, and the AI tools themselves can be run in different ways and are not always displayed in the list of corporate software. Based on the results of the study, RT-IB experts have formed two packages of detection expertise and investigation sequence for RT Protect EDR. The AI Agent Control package captures the launch and behavior of the agent on the host, connects it to the user account, and shows which data and commands it accesses. The "Shadow AI" package includes unauthorized clients, local models, and channels for accessing external services.
This approach makes it possible to distinguish an established but unused tool from an AI agent that performs actions in a work environment and also retains its applicability when new solutions appear.
