THREAT OPS › Threat News › Monitoring Claude Code/Cowork at scale with OTel in Elastic
Monitoring Claude Code/Cowork at scale with OTel in Elastic
<p>As AI coding assistants become standard tools in engineering workflows, security teams face a new challenge: how do you maintain visibility into what an AI agent is doing (and why) across your organization? When those agents can execute shell commands, read files, call APIs, and interact with internal systems via MCP connectors, you need real-time observability to support threat detection, inci
MITRE ATT&CK techniques
- ServerlessT1583.007
- ServerlessT1584.007
- ServerlessAML.T0008.004
Indicators of compromise
- https://code.claude.com/url
- https://claude.com/docs/coworkurl
- https://opentelemetry.io/url
- https://code.claude.com/docs/en/monitoring-usageurl
- https://claude.com/docs/cowork/monitoringurl
- https://your-elasticsearch:9200url
- https://<your-motlp-endpoint>url
- https://code.claude.com/docs/en/settings#settings-filesurl
- https://your-otel-gateway:443url
- http://attributes.event.nameurl
- https://support.claude.com/en/articles/9970975-access-audit-logsurl
- https://cloud.elastic.co/registrationurl
- https://code.claude.com/docs/en/server-managed-settingsurl
- static-www.elastic.codomain
- docker.elastic.codomain