Look for shifts in tool use, request volume, and destination systems, especially when the agent starts enumerating services, parsing schemas, or reaching endpoints unrelated to the original task. Those changes indicate that purpose has drifted even if the identity has not changed.
How to tell coding behaviour from reconnaissance
Detection works best when teams compare the agent’s current action pattern against its original task. A coding assistant should stay inside a narrow set of repositories, files, APIs, or build systems. Reconnaissance looks different: the agent broadens its tool use, increases request volume, and starts touching unrelated services, schemas, or endpoints while still appearing productive.
The practical signal is not identity change, it is purpose drift. An agent can remain authenticated and still shift from producing code to collecting environmental knowledge. That is why the strongest indicator set combines destination diversity, command shape, and the sequence of requests, rather than any single alert.
Security teams get better detection when they baseline normal developer and agent workflows first. The same tool can be legitimate in one phase and suspicious in another, so context matters: enumerating service names, probing metadata, parsing OpenAPI or database schemas, and querying adjacent systems are all common reconnaissance patterns when they appear outside the original coding scope. For agent-specific guidance, see AI Coding Agents Security Guide and AI Agent Observability, Audit and Incident Response Guide.
What telemetry usually reveals the pivot
The earliest clue is often a change in the shape of work. Coding activity tends to repeat within one codebase and its dependencies, while reconnaissance fans out across hosts, services, and data models. If the agent begins issuing more requests per minute, expanding the set of touched systems, or asking for unrelated resource names, you are likely seeing discovery behaviour rather than implementation.
Destination systems matter as much as volume. A coding task may call package registries, CI systems, or one application API, but reconnaissance often reaches service registries, internal docs, metadata services, admin endpoints, or endpoints that reveal structure instead of functionality. The transition is especially clear when the agent starts enumerating services or parsing schemas that were never needed for the original task.
Sequence is the third signal. Look for a move from narrow, task-directed actions to a pattern of probe, inspect, enumerate, then broaden. That progression is useful because a single request can be ambiguous, but a run of increasingly exploratory calls usually is not. Teams that log tool calls, targets, and response shapes can detect this shift much earlier than teams that only watch final outputs. If you are building that telemetry layer, Agentic AI Security Guide and AI Agent Identity Security Buyer’s Guide are useful navigation points.
How to separate benign exploration from risky reconnaissance
Not every broad query is malicious. Good detection practice distinguishes normal troubleshooting, dependency resolution, and documentation lookup from behaviour that expands the agent’s authority boundary. A benign coding agent may inspect related services to fix a broken integration, but a suspicious one keeps widening scope after the original work is already satisfiable.
One useful discriminator is whether the agent’s requests are still explainable by the current ticket or prompt. If the agent begins collecting facts that would only help an attacker, such as asset names, service relationships, or schema details with no coding need, that is a meaningful escalation in intent. Another discriminator is repetition without progress, because reconnaissance often produces many discovery calls with little code generation or commit-worthy output.
Teams should also watch for cross-boundary access. When the agent starts contacting systems outside its usual workspace, switching from development resources to production-adjacent resources, or using tools in ways that increase visibility rather than complete the task, the behaviour deserves review. A strong operational control view is available in Zero Trust for AI Agents and AI Agent Authorisation Guide.
Risk and Threat Considerations
The main risk is that reconnaissance can happen while the agent still looks like it is doing legitimate development work. That makes alerting harder, because the same identities, tools, and sessions may be used for both coding and discovery. Once an agent can enumerate systems or schemas beyond the task boundary, it can collect high-value context for later abuse, lateral movement, or more targeted exploitation.
Failure mechanism: The control fails when teams monitor only final outputs or broad authentication events, but do not measure behavioural drift across tools, destinations, and request patterns. A task that starts in a codebase can quietly expand into discovery of adjacent services, and that transition may not change the agent’s identity at all.
Impact: Unchecked drift increases blast radius, leaks environment knowledge, and can precede unauthorized access to services, schemas, or operational endpoints. It also reduces confidence in the agent’s activity trail, because later actions become harder to distinguish from the original task.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI02 — Tool Misuse | Detects agents using tools beyond the intended coding task. |
| ASI03 — Identity & Privilege Abuse | Purpose drift can turn legitimate agent access into broader privilege use. | |
| Recommendation — Monitor tool calls for scope expansion and block unrelated discovery actions. Constrain per-action authority and alert on access beyond the task boundary. | ||
| MITRE ATT&CK | T1613 — Container and Resource Discovery | Reconnaissance often appears as discovery of services, schemas, or resources. |
| T1087 — Account Discovery | Agent recon may include enumeration of users, services, or identities. | |
| Recommendation — Map discovery bursts to ATT&CK and hunt for enumerating activity across systems. Correlate enumeration patterns with account discovery and investigate unusual lookups. | ||
| NIST CSF 2.0 | DE.AE-03 — Anomalous Activity is Detected and Analyzed | Behavioural drift is an anomaly that should be analyzed in context. |
| PR.AA-05 — Credentials and Access Management | Task-bound access helps limit an agent’s ability to explore unrelated systems. | |
| Recommendation — Analyze deviations in tool use, volume, and destinations as anomalous activity. Limit agent access to task-scoped systems and revoke unused reach promptly. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Detection depends on reviewing tool and destination telemetry for drift. |
| Recommendation — Review agent audit trails for widening scope and unusual request sequences. | ||
Practitioner Guidance
What to verify: Baseline each agent by task type, then verify whether the current run stays within the expected repository, service set, and request cadence. If the agent starts touching new destinations, treat that as an investigation trigger even if the output still looks code-related.
Decision rule: If the agent is querying for structure, inventory, or relationships rather than implementation details, reclassify the session as exploratory and require closer review. If the requests are both broader and more repetitive than the original job needs, assume the agent has crossed from coding into reconnaissance until proven otherwise.
Practitioner takeaway: The safest detection strategy is to score purpose drift, not just unusual access, because reconnaissance usually reveals itself through widening scope before it reveals itself through outright compromise.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org