Defend
Detect and respond to Shadow AI in your enterprise.
The detection rule library, response runbooks, employee comms templates, and policy starter for the #1 AI risk on every CISO's desk in 2026. Stack-aware: pick yours, see only what works.
What's inside
Why this exists
Shadow AI is the #1 AI risk on every CISO's desk in 2026. The current public state is fragmented blog posts and scattered KQL. CISOs are paying consultants tens of thousands for what is essentially a curated detection rule set and a runbook. This repo is the canonical, free, open alternative.
Authored by an IT auditor who proposed the exact Shadow AI / DLP control at a Tier 1 global multinational on a Microsoft-centric stack (Defender, Purview, Sentinel) plus CrowdStrike. This is the generalized, public version of that work.
About →