Tag
medium
advisory
Detection of Local LLM Model File Creation on Endpoints
2 rules 5 TTPsThis brief describes how the creation of Large Language Model (LLM) files, including formats like .gguf, .safetensors, .ggml, and Modelfiles, by local AI inference frameworks such as Ollama, llama.cpp, GPT4All, and LM Studio can be detected on Windows endpoints, indicating potential shadow AI deployments, unauthorized model downloads, or rogue LLM infrastructure which poses data exfiltration risks and policy violations.
Ollama +9
shadow-it
llm
data-exfiltration
policy-violation
endpoint
shadow-ai
local-llm
intellectual-property-theft
+2
2r
5t
medium
advisory
M365 Copilot Access from Non-Compliant Devices
2 rules 1 TTPDetects Microsoft 365 (M365) Copilot access from non-compliant or unmanaged devices, potentially indicating shadow IT, BYOD policy violations, or compromised endpoints accessing sensitive data.
M365 Copilot +1
m365
copilot
device-compliance
byod
shadow-it
2r
1t