Cloud Security 16 min read
Detecting Rogue MCP Servers and Shadow AI Agents on Endpoints with Wazuh
A custom Wazuh rule pack and reproducible Docker lab that catches rogue MCP servers, shadow AI agent activity, and indirect prompt-injection chains on engineering endpoints. 5 decoders, 13 rules, MITRE ATT&CK mapped.