New Securonix Value Package: Threat Detection for AI
We are pleased to announce the availability of the Securonix Threat Detection for AI Value Package.
This release currently provides 43 out-of-the-box policies under the label scx.vp.AI, giving security teams a practical starting point for detecting activity across AI platforms, identities, agents, data movement, endpoint activity, and network telemetry.
The package currently includes coverage for:
- AWS Bedrock —
AWS Cloud Trail - Microsoft Entra ID, app consent and permission changes —
Azure Active Directory - Microsoft Entra ID, sign-in and landspeed anomalies —
Azure Active Directory Sign In - Microsoft Copilot, Copilot Studio, and general M365 activity —
o365 Audit General - File uploads to AI assistants via SharePoint —
Office 365 SharePoint API - Microsoft Foundry —
Azure Monitor - Google Cloud AI-agent activity —
GCP Audit - Endpoint AI-agent and process activity —
Microsoft Windows Sysmon(Windows),Sysmon for Linux(Linux) - AI-related data loss alerts —
Office365 DLP - Web proxy —
Zscaler Proxy - Next-generation firewall —
Palo Alto Next-Generation Firewall,Fortigate
The detections are designed to help teams monitor both control-plane changes and suspicious usage patterns around AI services.
What to expect
The package includes detections for:
- AI platform and configuration changes
- Shadow AI
- Identity and permission abuse
- Anomalous AI usage
- Data exposure and transfer risk
- Endpoint behavior linked to AI activity
- Network activity involving AI destinations
Representative policies include:
CSA-AWS-1044-RU— AWS Bedrock Guardrail ModifiedCSA-AWS-1045-DB— Potential AWS Bedrock Knowledge Base Data Extraction via RAGOGN-ALL-812-TP— Copilot Interaction from Malicious IPOGN-ALL-814-RU— File Uploaded to AI SitesACI-AAD-855-RU— High Scope Permission Assigned to EntraID ApplicationCPA-GCP-965-RU— Sensitive GCP Role Granted by AI AgentEDR-UNX-1435-RU— OpenClaw Process Spawning Reverse Shell Analytic - Sysmon for LinuxPXY-ALL-942-BA— Abnormal Amount of Data Transferred to AI Site - Proxy
Important notes
This package does not introduce new data collection. Each policy depends on the relevant source already being onboarded and parsed in Securonix.
In practice, that means customers should confirm:
- the relevant connectors are enabled,
- the required logs are available,
- parsing is working as expected,
- and the fields needed by each policy are present.
Some log sources may also require additional configuration. For example, AWS Bedrock activity may require CloudTrail data-event selectors, GCP Data Access logs are not enabled by default in many cases, and Microsoft Foundry resource logs require diagnostic settings.
Recommended use
Start with the detections that match the AI services you already run in production, especially control-plane and permission-change policies. Once those are validated, expand into usage anomalies, data-transfer, endpoint, proxy, and firewall coverage.
That sequence helps reduce noise and makes it easier to distinguish between a logging gap and a real detection signal.
Where to learn more
Detailed setup guidance, source requirements, and operational notes are available in the product documentation.
We hope this makes it easier to stay ahead of AI threats and manage detections with more confidence.
Best,
The Securonix Team
