Liran Lavi
Sarit Yerushalmi
AI agents are already running on developer machines, inside terminals, IDEs, and internal workflows. They are useful, but they can also read code, access files, execute commands, call tools, use credentials, and send data to LLM providers.
In this Arsenal demo, we will present an open-source runtime discovery tool for identifying LLM-powered applications and AI agents on live machines without requiring code changes. The tool correlates local processes with LLM-provider traffic, detects known and unknown AI service usage, monitors subprocess and file activity, and applies basic policy controls for coding agents.
We will show what AI agents look like at runtime, what they do beyond the chat interface, and how AppSec teams can see, understand, and control them.
Liran Lavi
Imperva, Senior Security Researcher
A senior security researcher from Tel Aviv specializing in web application security and advanced bot detection. With over 9 years of experience with small and large companies. To balance my tech-savvy life, you might find me hiking or skydiving - chasing new heights both literally and technically. I am always exploring edge cases and smarter ways to build and break systems.
Sarit Yerushalmi
Imperva, Senior Security Researcher
Sarit Yerushalmi is an experienced security researcher at Imperva. Her research mainly focuses on application security and APIs. She analyzes traffic to detect new threats, writes security blogs and talks at conferences. Some of her work has been presented at security conferences such as Botconf, Bsides TLV, NorthSec, and Kernelcon.