-
Notifications
You must be signed in to change notification settings - Fork 431
Rod- Suspicious Local LLM Frameworks #3780
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: develop
Are you sure you want to change the base?
Conversation
detections/endpoint/suspicious_local_llm_framework_download_and_execution_via_sysmon.yml
Outdated
Show resolved
Hide resolved
detections/endpoint/unauthorized_llm_model_file_creation_on_endpoint.yml
Outdated
Show resolved
Hide resolved
detections/endpoint/suspicious_local_llm_framework_download_and_execution_via_sysmon.yml
Outdated
Show resolved
Hide resolved
detections/endpoint/suspicious_local_llm_framework_download_and_execution_via_sysmon.yml
Outdated
Show resolved
Hide resolved
…d_execution_via_sysmon.yml Co-authored-by: Nasreddine Bencherchali <[email protected]>
detections/endpoint/suspicious_local_llm_framework_download_and_execution_via_sysmon.yml
Outdated
Show resolved
Hide resolved
detections/endpoint/unauthorized_llm_model_file_creation_on_endpoint.yml
Outdated
Show resolved
Hide resolved
|
Working on updating the detection to use CIM where possible. |
|
@rosplk @patel-bhavin made changes to the analytics so they are more CIM friendly and I merged some as they were overlapping. The coverage should be the same. One is failing idk why and i cant see to find the data on Endor to check. So @patel-bhavin when you have some time to check it out, |
|
@rosplk please avoid adding raw links in this format : The preferred way is such that it is a GIT LFS file just like all other yamls - Also, your current attack data size is 21k events for 2 detections: strongly consider shipping atomic datasets specific to the detection for future Fixed that in here: splunk/attack_data#1096 . Also, strongly encouraged to use DMs where feasible and if not use TA built extractions @nasbench - Thank you for fixing up the detections to use TA fields 😸 I have pushed the remaining changes! |
This PR introduces new analytics to detect Local LLM execution and shadow AI artifacts. Below is a breakdown of what was added.
New Analytics [3]
New Analytic Story [1]