Skip to main content
ShadowAI Defense GitHub

Methodology

How the library is built

Quality bar

Read the DETECTION_QUALITY.md for the contribution standard. Each rule must include working query syntax, required data sources, prerequisites, expected volume guidance, false-positive guidance, tuning steps, and at least one framework mapping.

Authorship

Every rule is authored by a practitioner with field experience. No vendor-supplied marketing rules. Where a rule comes from a community contributor, attribution is permanent.

Stack realism

Each rule is mapped to one or more specific stack profiles. Where a rule cannot be implemented on a stack, that's stated explicitly with compensating controls.

Honest about limits

The library does not claim coverage where it doesn't exist. Personal-device, BYO-API-key, and mobile-data-plan channels remain hard or impossible to detect from the corporate environment; the library says so.

Review cadence

  • Service signatures: monthly (LLM services move fast).
  • Detection rules: quarterly (platform changes, query syntax evolution).
  • Runbooks: annually or on a material program development.
  • Stack profiles: quarterly.