AI Security: Agent Security and Model Theft
The AI Security: Agent Security and Model Theft dashboard is designed to monitor AI agent permissions and indicators of unauthorized access to model artifacts.
Intended audience: information security analysts and SOC engineers.
Data sources: gen_ai_events*, gen_ai_permissions*, .smos_incident-*
Main Sections
1. Agent and Model Violation Summary
Shows the number of rule matches related to agent permission monitoring and model artifact protection:
- excessive permissions granted to agents, privilege escalation attempts, unusual external connections, and deviations from the baseline profile
- model theft, access to model repositories, outbound transfers of model weights, and artifact exfiltration by a process
- table of agents with excessive permissions

2. Deviations and Privilege Escalation Attempts
Shows events that require a review of agent permissions and profiles:
- deviations from the baseline profile: agent, current and baseline modes, network access, prefixes, sandbox mode, policy, denylist, origins, and deviation description
- privilege escalation attempts: time, agent, user, host, outcome, status, error, and reason
- comparison of the agent's actual configuration with the expected restrictions
