Detections
Detection Rule Library
30 detection rules across 9 platforms. Pick your stack at /stack to filter the list to what's possible on your environment.
Conditional Access
-
DET-MS-CA-001
InformationalEntra Conditional Access — block unmanaged-device access to corporate apps
Conditional Access policy denying access to corporate apps from unmanaged devices, reducing the BYO bypass path for Shadow AI usage.
config · Identity
-
DET-MS-CA-002
MediumConditional Access — Block AI app OAuth grants for non-admin users
Conditional Access policy combined with Entra ID consent settings that prevents non-admin users from granting OAuth consent to AI-related applications, centralizing AI app approval through the admin-consent workflow.
config · Identity
-
DET-MS-CA-003
MediumConditional Access — Require compliant device for AI service access
Conditional Access policy that enforces device compliance requirements before allowing access to AI service applications, ensuring that only managed devices with up-to-date security controls can interact with AI platforms.
config · Identity
CrowdStrike Falcon
-
DET-CS-FALCON-001
InformationalCrowdStrike Falcon — AI client process activity
CrowdStrike Falcon Custom IOA detection for execution and DNS resolution patterns of consumer AI clients on managed endpoints.
Falcon CQL · Endpoint
-
DET-CS-FALCON-002
HighCrowdStrike Falcon Data Protection — sensitive content to AI domains
Falcon Data Protection policy detecting sensitive-content uploads to consumer AI domains.
config · DLP
Defender for Cloud Apps
-
DET-MS-MCAS-001
MediumDefender for Cloud Apps — Shadow AI discovery policy
Cloud-app discovery policy in Defender for Cloud Apps configured to surface AI services from firewall/proxy logs and flag unsanctioned use.
config · Application Connector
-
DET-MS-MCAS-002
HighOAuth grants to AI apps over Microsoft identity
Detects OAuth consent grants to AI-related apps over Microsoft Entra ID, including agentic and integration applications that may receive broad data access.
config · Identity
-
DET-MS-MCAS-003
HighDefender for Cloud Apps — AI application OAuth consent anomaly
Detects unusual OAuth consent grants to AI-related applications, focusing on anomalous patterns such as first-time consent to high-permission AI apps, bulk consent across multiple users, or consent to unverified AI app publishers.
config · Application Connector
-
DET-MS-MCAS-MANUAL-001
InformationalDefender for Cloud Apps — manual log upload from firewall (E3-friendly)
For Microsoft minimal stacks, periodic manual log upload to Defender for Cloud Apps Shadow IT Discovery to catalog AI services seen on the network.
config · Application Connector
Defender for Endpoint
-
DET-MS-MDE-001
MediumUnauthorized AI browser extension installation
Detects installation of browser extensions identified as Shadow AI risk vectors on managed endpoints.
KQL · Endpoint
-
DET-MS-MDE-002
LowLocal AI tool process execution
Detects execution of locally-installed AI clients (desktop apps for consumer LLMs) on managed endpoints.
KQL · Endpoint
-
DET-MS-MDE-003
MediumDefender for Endpoint — AI desktop app installation detection
Detects the installation of AI desktop applications on managed endpoints by monitoring Windows Installer events, MSI/EXE executions, and application registration in Add/Remove Programs.
KQL · Endpoint
Generic Network
-
DET-NET-001
MediumGeneric SWG / proxy — block consumer AI domains
Stack-agnostic secure web gateway / proxy configuration to block consumer AI domains for unauthorized users.
config · Network
-
DET-NET-002
MediumGeneric firewall — block AI API endpoints from non-developer subnets
Block outbound TLS to LLM API endpoints from non-developer subnets to limit script/agent-based use.
config · Network
Microsoft Sentinel
-
DET-MS-SEN-001
MediumOutbound traffic to consumer LLM domains
Detects connections from corporate endpoints to known consumer LLM service domains, indicating Shadow AI use.
KQL · Network
-
DET-MS-SEN-002
LowFirst-seen consumer LLM domain in environment
Surfaces newly emerging consumer LLM service domains observed in network telemetry for the first time, prompting watchlist updates and AUP enforcement.
KQL · Network
-
DET-MS-SEN-003
HighMass adoption of unsanctioned AI tool
Detects when an unsanctioned AI service exceeds a user-count threshold within a short window, indicating organic adoption that warrants program-level response.
KQL · Network
-
DET-MS-SEN-004
MediumAPI-key issuance for unsanctioned LLM platforms
Detects egress to LLM API endpoints (rather than chat endpoints), indicating script/agent-based use that may bypass user-facing controls.
KQL · Network
-
DET-MS-SEN-005
HighSource-code volume to AI services
Detects large outbound transfers to AI service endpoints that statistically match source-code transmission, distinct from typical conversation traffic.
KQL · Network
-
DET-MS-SEN-006
MediumSentinel — AI service usage spike detection (anomaly)
Anomaly detection rule in Microsoft Sentinel that identifies sudden spikes in AI service traffic per user, indicating potential bulk data exfiltration or new Shadow AI adoption patterns.
KQL · Network
-
DET-MS-SEN-007
MediumSentinel — After-hours AI service access
Detects access to consumer AI services outside of defined business hours, which may indicate employees circumventing daytime monitoring controls or engaging in unauthorized data processing during off-peak periods.
KQL · Network
-
DET-MS-SEN-008
HighSentinel — Large payload upload to AI API endpoints
Detects large data uploads (file or POST body) to known AI API endpoints, distinguishing programmatic bulk data submission from interactive chat usage.
KQL · Network
Netskope
-
DET-NS-001
InformationalNetskope — AI SaaS application discovery via Cloud Confidence Index
Discovers AI and generative AI applications in use across the organization by leveraging Netskope's Cloud Confidence Index (CCI) catalog and real-time traffic analysis.
config · Application Connector
-
DET-NS-002
HighNetskope — Real-time DLP for AI service uploads
Data Loss Prevention policy in Netskope that inspects content uploaded to AI services in real time, detecting and blocking sensitive data exfiltration through generative AI platforms.
config · DLP
-
DET-NS-003
MediumNetskope — Inline CASB block of unsanctioned AI domains
Inline enforcement policy using Netskope's CASB to block access to unsanctioned AI service domains, preventing Shadow AI usage at the network layer.
config · Network
Purview DLP
-
DET-MS-PV-001
HighSensitive data uploaded to consumer LLM services
Detects upload of files or text containing organizational sensitive information types to consumer AI services via Edge for Business, prevents the action, and notifies the user with policy guidance.
config · DLP
-
DET-MS-PV-002
HighPurview DLP — Sensitive label content uploaded to AI services
Detects when documents with Microsoft Purview sensitivity labels (Confidential, Highly Confidential, Restricted) are uploaded, pasted, or shared to consumer AI services, leveraging label-based detection for higher precision than content inspection alone.
config · DLP
Zscaler
-
DET-ZS-001
MediumZscaler — AI/ML application category monitoring
Zscaler Internet Access (ZIA) URL filtering policy to monitor and optionally block access to the AI/ML application URL category, providing visibility into Shadow AI usage across the organization.
config · Network
-
DET-ZS-002
HighZscaler — DLP inspection of AI service uploads
Zscaler Internet Access DLP policy that inspects content uploaded to AI services, detecting and preventing sensitive data from being sent to consumer generative AI platforms.
config · DLP
-
DET-ZS-003
MediumZscaler — Cloud browser isolation for AI services
Zscaler Browser Isolation policy that renders AI service sessions in an isolated cloud container, providing full visibility into user interactions while preventing direct data transfer to AI platforms.
config · Network