Research
MCP Tool Traffic Looks Like Cobalt Strike Beaconing and Enterprise IDS Does Not Flag It
arXiv 2609.19091 (16 Sep 2026) measures remote MCP over Streamable HTTP against the machine-like cadence that network defenders have long treated as an indicator of compromise. Across a Docker testbed with eleven defined traffic profiles and three TLS conditions (opaque, TLS-inspected, cleartext), Suricata signature matching and RITA behavioral beacon scoring did not classify MCP JSON-RPC tool usage as anomalous, regardless of jitter or TLS handling. The finding cuts both ways: agent traffic slips past existing detection, and the same structural resemblance means real C2 can now hide inside legitimate agent chatter.
↳ Follow the thread