Skip to content
Threat Feed

Tag

Policy Violation

4 briefs RSS
medium advisory

Detection of Local LLM Framework DNS Queries

This brief details the detection of DNS queries originating from local Large Language Model (LLM) frameworks like Ollama, LM Studio, and GPT4All on Windows endpoints, leveraging Sysmon Event ID 22 to identify potential unauthorized AI tool usage or data exfiltration risks associated with model downloads, updates, and telemetry from repositories such as huggingface.co and ollama.ai.

Claude +16 local-llm shadow-ai dns-monitoring data-exfiltration policy-violation windows endpoint-security
1r 3t 18i
medium advisory

Detection of Local LLM Model File Creation on Endpoints

This brief describes how the creation of Large Language Model (LLM) files, including formats like .gguf, .safetensors, .ggml, and Modelfiles, by local AI inference frameworks such as Ollama, llama.cpp, GPT4All, and LM Studio can be detected on Windows endpoints, indicating potential shadow AI deployments, unauthorized model downloads, or rogue LLM infrastructure which poses data exfiltration risks and policy violations.

Ollama +9 shadow-it llm data-exfiltration policy-violation endpoint shadow-ai local-llm intellectual-property-theft +2
2r 5t
high advisory

Prohibited Network Traffic Allowed

This analytic detects instances where prohibited network traffic is allowed, highlighting potential misconfigurations or policy violations that could lead to unauthorized access or data exfiltration, ultimately allowing attackers to bypass network defenses.

Secure Firewall Threat Defense +3 network policy-violation firewall traffic-monitoring
2r 1t
low advisory

Wallpaper Modification Detection

Detection of unauthorized or suspicious wallpaper modifications on endpoints can indicate malicious activity or policy violations.

Windows endpoint wallpaper modification registry policy violation
3r 1t