Skip to main content
Version: 6.1

AI Security: LLM Threats

The AI Security: LLM Threats dashboard is designed to analyze rule matches by OWASP Top 10 for LLM Applications category.

Intended audience: information security analysts and SOC engineers.

Data sources: gen_ai_events*, .smos_incident-*


Main Sections​

1. Summary Metrics and Distribution​

Shows the number of rule matches during the selected period and the distribution of events across key dimensions:

  • total number of rule matches
  • counters for the LLM01, LLM04, LLM05, LLM05/08, LLM06, LLM07, and LLM10 categories
  • rules with the most matches
  • users and agents with the most matches

Summary metrics and distribution

Shows how the number of matches in each OWASP category changed over the selected time range:

  • trends for LLM01, LLM04, LLM05/08, LLM06, and LLM07
  • periods with increased matches in specific categories
  • intervals with no matches or with values returning to the baseline

Trends by OWASP category

3. Rule Match and Prompt Injection Analysis​

Shows a table of rule matches and details for OWASP LLM01 events:

  • filters by OWASP category and user or agent
  • date and time, OWASP code, rule, and user or agent
  • related incident, severity, and processing status
  • distribution of prompt injections by subcategory
  • latest prompt injections, including the service, user, prompt text, pattern, and type

Rule match and prompt injection analysis

4. Sensitive Data Disclosure​

Shows details for OWASP LLM06 events associated with sensitive information disclosure:

  • distribution of leaks by category, including web attacks, personal data, and other types
  • matches by pattern, including template injection, email address, phone number, command substitution, IP address, bank identification code, command injection, and API key
  • latest leaks, including the service, user, prompt, model response, pattern, type, and matched field

Sensitive data disclosure