Tag
Detection of Unauthorized Amazon Bedrock Parameter Manipulation
1 ruleAdversaries are exploiting Amazon Bedrock APIs by submitting malformed inference parameters to trigger repeated validation exceptions, potentially for model evasion, cost harvesting, or testing defensive boundaries.
Detection of Prohibited Network Traffic Permitted by Firewall Policy
1 TTPThis analytic identifies instances where network traffic, specifically using prohibited ports and protocols such as FTP or Telnet, is allowed by Cisco Secure Firewall, signaling potential misconfigurations or unauthorized activity.
Detection of Local LLM Framework DNS Queries
1 rule 3 TTPs 18 IOCsThis brief details the detection of DNS queries originating from local Large Language Model (LLM) frameworks like Ollama, LM Studio, and GPT4All on Windows endpoints, leveraging Sysmon Event ID 22 to identify potential unauthorized AI tool usage or data exfiltration risks associated with model downloads, updates, and telemetry from repositories such as huggingface.co and ollama.ai.
Detection of Local LLM Model File Creation on Endpoints
2 rules 5 TTPsThis brief describes how the creation of Large Language Model (LLM) files, including formats like .gguf, .safetensors, .ggml, and Modelfiles, by local AI inference frameworks such as Ollama, llama.cpp, GPT4All, and LM Studio can be detected on Windows endpoints, indicating potential shadow AI deployments, unauthorized model downloads, or rogue LLM infrastructure which poses data exfiltration risks and policy violations.
Prohibited Network Traffic Allowed
2 rules 1 TTPThis analytic detects instances where prohibited network traffic is allowed, highlighting potential misconfigurations or policy violations that could lead to unauthorized access or data exfiltration, ultimately allowing attackers to bypass network defenses.
Wallpaper Modification Detection
3 rules 1 TTPDetection of unauthorized or suspicious wallpaper modifications on endpoints can indicate malicious activity or policy violations.