Skip to main content
Version: 6.1

AI Security: Agent Security and Model Theft

The AI Security: Agent Security and Model Theft dashboard is designed to monitor AI agent permissions and indicators of unauthorized access to model artifacts.

Intended audience: information security analysts and SOC engineers.

Data sources: gen_ai_events*, gen_ai_permissions*, .smos_incident-*

Main Sections

1. Agent and Model Violation Summary

Shows the number of rule matches related to agent permission monitoring and model artifact protection:

  • excessive permissions granted to agents, privilege escalation attempts, unusual external connections, and deviations from the baseline profile
  • model theft, access to model repositories, outbound transfers of model weights, and artifact exfiltration by a process
  • table of agents with excessive permissions

Agent and model violation summary

2. Deviations and Privilege Escalation Attempts

Shows events that require a review of agent permissions and profiles:

  • deviations from the baseline profile: agent, current and baseline modes, network access, prefixes, sandbox mode, policy, denylist, origins, and deviation description
  • privilege escalation attempts: time, agent, user, host, outcome, status, error, and reason
  • comparison of the agent's actual configuration with the expected restrictions

Deviations and privilege escalation attempts