Skip to main content
Version: 6.1

AI Security: LLM Threats

The AI Security: LLM Threats dashboard is designed to analyze rule matches by OWASP Top 10 for LLM Applications category.

Intended audience: information security analysts and SOC engineers.

Data sources: gen_ai_events*, .smos_incident-*


Main Sections

1. Summary Metrics and Distribution

Shows the number of rule matches during the selected period and the distribution of events across key dimensions:

  • total number of rule matches
  • counters for the LLM01, LLM04, LLM05, LLM05/08, LLM06, LLM07, and LLM10 categories
  • rules with the most matches
  • users and agents with the most matches

Summary metrics and distribution

Shows how the number of matches in each OWASP category changed over the selected time range:

  • trends for LLM01, LLM04, LLM05/08, LLM06, and LLM07
  • periods with increased matches in specific categories
  • intervals with no matches or with values returning to the baseline

Trends by OWASP category

3. Rule Match and Prompt Injection Analysis

Shows a table of rule matches and details for OWASP LLM01 events:

  • filters by OWASP category and user or agent
  • date and time, OWASP code, rule, and user or agent
  • related incident, severity, and processing status
  • distribution of prompt injections by subcategory
  • latest prompt injections, including the service, user, prompt text, pattern, and type

Rule match and prompt injection analysis

4. Sensitive Data Disclosure

Shows details for OWASP LLM06 events associated with sensitive information disclosure:

  • distribution of leaks by category, including web attacks, personal data, and other types
  • matches by pattern, including template injection, email address, phone number, command substitution, IP address, bank identification code, command injection, and API key
  • latest leaks, including the service, user, prompt, model response, pattern, type, and matched field

Sensitive data disclosure