AI Security: LLM Threats
The AI Security: LLM Threats dashboard is designed to analyze rule matches by OWASP Top 10 for LLM Applications category.
Intended audience: information security analysts and SOC engineers.
Data sources: gen_ai_events*, .smos_incident-*
Main Sections
1. Summary Metrics and Distribution
Shows the number of rule matches during the selected period and the distribution of events across key dimensions:
- total number of rule matches
- counters for the LLM01, LLM04, LLM05, LLM05/08, LLM06, LLM07, and LLM10 categories
- rules with the most matches
- users and agents with the most matches

2. Trends by OWASP Category
Shows how the number of matches in each OWASP category changed over the selected time range:
- trends for LLM01, LLM04, LLM05/08, LLM06, and LLM07
- periods with increased matches in specific categories
- intervals with no matches or with values returning to the baseline

3. Rule Match and Prompt Injection Analysis
Shows a table of rule matches and details for OWASP LLM01 events:
- filters by OWASP category and user or agent
- date and time, OWASP code, rule, and user or agent
- related incident, severity, and processing status
- distribution of prompt injections by subcategory
- latest prompt injections, including the service, user, prompt text, pattern, and type

4. Sensitive Data Disclosure
Shows details for OWASP LLM06 events associated with sensitive information disclosure:
- distribution of leaks by category, including web attacks, personal data, and other types
- matches by pattern, including template injection, email address, phone number, command substitution, IP address, bank identification code, command injection, and API key
- latest leaks, including the service, user, prompt, model response, pattern, type, and matched field
