elasticseclabs

@elasticseclabs · Twitter ·

We gave hundreds of developers an AI agent that can run shell commands, edit files, and call MCP servers on their laptops. Then we realized we had no record of what it actually did. So we built one. 1 bash script, 280 lines, no dependencies. Cursor hooks fire it on every tool call. Elastic Agent ships the log to Elasticsearch. Since the May rollout: 13M+ tool-call events across 1,100+ machines. What the data showed: - File reads outnumber shell commands roughly 4 to 1: agents mostly read your codebase before acting - 300+ distinct MCP servers in use, 86% of them by only 1 or 2 people - The CLI surface alone produced nearly a fifth of all events "Which hosts ran an agent that read a .pem file last week?" is now 1 ES|QL query. We log commands, paths, and tool names. Never file contents, prompts, or responses. Full writeup from Wieger van der Meulen on the InfoSec team: the collector script, hooks.json, the 2 deployment gotchas that cost the most time, and the ES|QL hunting queries. https://go.es.io/4wHDZID