The paper presents Cloud Decoy AI Agent, a framework that combines a high-fidelity cloud decoy with an autonomous language-model agent for intrusion investigation. It treats the session, rather than the individual event, as the investigation unit and limits the agent’s evidence horizon through dynamic, two-stage prompt assembly. In ten controlled AWS S3 scenarios, nine were reconstructed completely; no report assertion was untraceable to an observed artifact, and latency was four to five minutes. The prototype does not yet mitigate indirect prompt injection through attacker-controlled telemetry fields.
No heat snapshots are available in the last 24 hours.