Product
medium
advisory
Detection of Local LLM Framework DNS Queries
1 rule 3 TTPs 18 IOCsThis brief details the detection of DNS queries originating from local Large Language Model (LLM) frameworks like Ollama, LM Studio, and GPT4All on Windows endpoints, leveraging Sysmon Event ID 22 to identify potential unauthorized AI tool usage or data exfiltration risks associated with model downloads, updates, and telemetry from repositories such as huggingface.co and ollama.ai.
Claude +16
local-llm
shadow-ai
dns-monitoring
data-exfiltration
policy-violation
windows
endpoint-security
1r
3t
18i
critical
advisory
Unsecured Model Context Protocol (MCP) Server Deployments Expose AI Integrations
2 rules 8 TTPs 1 IOCUnsecured Model Context Protocol (MCP) servers, used to connect AI agents to enterprise tools, lack authentication and audit trails, leading to data exfiltration, private repo leaks, cross-tenant exposure, and remote code execution due to AI agents using valid user credentials to make API calls based on potentially poisoned context.
Claude +4
ai
mcp
zero-trust
data-exfiltration
rce
2r
8t
1i