Gurucul 宣布推出 Gurucul AI Risk and Response 的正式版本,将行为人工智能引入日益扩大的攻击面,这一攻击面随着人工智能从助手向行动者的角色转变而不断形成。通过数百项连接活动与身份、权限、数据及更广泛安全遥测数据的人工智能检测,该解决方案帮助 SOC(安全运营中心)和内部风险团队看清是谁或什么在采取行动,在威胁发展过程中识别它们,调查证据并在风险升级之前做出响应。
现已提供预览的 AI Prevention 功能增加了旨在阻止特定高风险人工智能交互的控制措施,这些控制措施作用于使用点。Gurucul 还向组织免费提供基于真实数据的 AI 风险评估和报告。
近期涉及人工智能系统与真实世界环境互动的事故,包括被恶意 OpenAI 代理入侵的 Hugging Face 系统,凸显了自主人工智能行为所带来的安全影响已超出传统的提示词和聊天机器人交互范畴。
与此同时,Anthropic 最新的威胁情报报告记录了利用 Claude 进行的日益复杂的网络行动,其中包括自主代理在极少人工参与的情况下执行侦察、利用和数据窃取。随着 Google Gemini 等人工智能系统能够越来越直接地与计算机交互并执行复杂任务,安全团队不仅需要了解被要求人工智能做什么,还需要了解它实际在做什么、它能访问什么以及其行为如何与生态系统的其余部分相关联。
Gurucul AI Risk and Response 通过将人工智能活动置于其周围完整的安全环境中来解决这一新兴需求:是谁或什么发起了该活动,使用了哪些身份和权限,触及了哪些数据和系统,以及行为随时间发生了怎样的变化。该方案建立在十余年的行为人工智能基础之上,将用户和自主代理视为持久实体进行分析,以揭示影子 AI、过度访问权限以及新兴的行为风险。
安全团队能够获得基于证据的事件回顾视角,了解事件发生的原因及其重要性,以及如何响应,同时利用剧本和现有控制措施。AI Risk and Response 帮助团队尽早发现高风险行为并在其升级之前加以阻止。
随着 AI Risk and Response 的预防功能现已进入预览阶段,组织可以通过在源头识别并阻止高风险人工智能活动获得额外的保护层。该解决方案建立在 Gurucul 市场领先的安全信息和事件管理(SIEM)、用户实体行为分析(UEBA)以及人工智能内部风险管理(AI-IRM)能力之上,以实时检测、调查和响应与人工智能相关的风险。
与独立的人工智能网关和其他单点解决方案不同,Gurucul AI Risk and Response 提供了跨企业更广泛的人工智能风险行为视角。它将人工智能平台数据与现有的代理、端点检测与响应(EDR)、身份、操作系统和云遥测数据相结合,为安全团队提供连接的人工智能活动及其更广泛安全环境的整体视图。
通过将行为人工智能应用于这种连接环境,并结合映射到 MITRE ATLAS 全部 16 种战术以及 LLM 应用 OWASP Top 10 的数百项检测,Gurucul 使安全团队能够利用跨企业的机器速度分析来检测、调查和响应与人工智能相关的风险。
对于托管安全服务提供商(MSSP)而言,保护客户免受人工智能风险的威胁不仅仅需要洞察人工智能的使用情况。他们需要富含证据的发现结果,以便能够快速部署到多样化的客户环境中,并在不增加运营复杂性的情况下采取行动。
Blue Mantis的首席信息安全官(CISO)兼网络安全副总裁Jay Martin表示:“我们的客户不仅需要了解AI在何处被使用,还需要知道这种使用何时会对敏感信息和关键系统造成风险。Gurucul AI Risk and Response可以利用客户环境中已有的遥测数据快速启用,无需定制工程或额外的终端代理即可提供快速的可见性。”
该解决方案能够识别正在与未经批准的生成式AI服务共享的敏感非公开信息,并将这些活动与分析师需要调查的用户和终端行为相关联。这减少了实施时间、运营开销和成本,同时使我们的安全运营团队能够在对客户环境影响最小的情况下更快地做出响应。
对于像Blue Mantis这样的托管安全服务提供商(MSSP)而言,看到AI活动与拥有其背后的上下文和证据之间的区别,就在于仅仅是转发另一条警报与帮助客户理解并解决真正风险的区别。”
Gurucul AI Risk and Response 让安全团队能够:
利用现有数据揭示AI活动和暴露情况。AI数据管道摄取并规范化来自主要AI平台的活动,包括Anthropic Claude AI、Gemini Enterprise Agent Platform、Google Gemini、OpenAI ChatGPT、Azure AI Foundry Inventory以及Microsoft 365 Copilot,并与现有的代理、EDR(端点检测与响应)、身份、操作系统和云遥测数据相结合。组织可以识别经批准和未经批准的AI使用情况,建立代理、模型、工具和主机的清单,并将这些活动与所有者、权限和可访问资源联系起来。团队可以从他们已收集的数据开始,并添加直接的AI平台集成,以获取更深入的提示(prompt)、代理和审计上下文。
检测已知威胁和新兴的AI风险。行为式AI和确定性检测逻辑协同工作,以识别影子AI、敏感数据暴露、高风险自主代理、过度访问、AI供应链风险以及固定规则可能遗漏的行为变化。数百种检测覆盖五大AI安全家族,其覆盖范围映射到MITRE ATLAS的所有16种战术以及LLM应用程序的OWASP Top 10。统一实体智能(Unified Entity Intelligence)将这些发现整合为一个有证据支持的活跃风险评分。
将AI警报转化为已解析身份的调查。将AI活动与其背后的人类或非人类身份,以及涉及的系统、工具、数据和关系连接起来。分析师可以看到发生了什么变化、该活动如何与实体的历史及同行进行比较、AI可以访问什么内容,以及独立事件如何组合成不断发展的风险。AI安全概览(AI Security Overview)、代理工作区(Agent Workspace)和图探索器(Graph Explorer)提供了从初步发现到受影响实体、相关活动和底层证据的直接路径。
通过现有的控制和流程进行响应。自动化和审批驱动的工作手册帮助团队通过连接的身份、终端、网络和支持的AI平台控制来遏制风险。AI辅助建议为分析师提供清晰的响应选项,同时让他们对后果严重的行动负责。与企业ITSM路由的集成通过既定的安全和IT流程跟踪并引导补救措施,消除了为AI建立单独响应工作流的需求。
在交互点阻止选定的高风险AI活动。自动化控制识别并阻止支持的高风险AI交互,防止其升级。一个轻量级的浏览器插件提供了针对提示、粘贴内容、可读文件上传和AI目的地的额外控制点,帮助组织在AI活动发生的地方应用策略,同时让分析师掌控执行决策和例外情况。
随着人工智能最新进展所证明的,应对AI风险比以往任何时候都更为重要。“随着AI从生成答案转向采取行动,风险不再局限于单个提示词或应用程序。它随时间推移在身份、权限、数据、工具和行动中演变。内部团队和SecOps(安全运营)团队需要将这些信号连接起来,以了解发生了什么变化、为何重要以及风险将走向何方,”Gurucul首席执行官Saryu Nayyar表示。
“Gurucul AI Risk and Response应用行为AI、实体智能和有证据支持的风险评分,将AI活动置于更广泛的安全环境中进行分析。这使分析师能够清晰、可操作地查看正在发展的威胁,并通过他们已使用的流程和工作流对其进行早期干预。随着运行时防护功能现已进入预览阶段,我们正在迈出下一步:在源头以机器速度阻止高风险的AI行为,”Nayyar总结道。
Gurucul has announced the general availability of Gurucul AI Risk and Response, bringing behavioral AI to the growing attack surface created as AI moves from assistant to actor. With hundreds of AI detections connecting activity to identity, access, data and broader security telemetry, the solution helps SOC and Insider Risk teams see who or what is acting, recognize threats as they develop, investigate the evidence and respond before risk escalates.
AI Prevention, now available in preview, adds controls designed to stop selected high-risk AI interactions at the point of use. Gurucul is also offering organizations an AI Risk Assessment and Report on real data, at no cost.
Recent incidents involving AI systems interacting with real-world environments, including the compromise of Hugging Face systems by rogue OpenAI agents, have highlighted how autonomous AI behavior has security consequences beyond traditional prompts and chatbot interactions.
At the same time, Anthropic’s latest threat intelligence report documents increasingly sophisticated cyber operations using Claude, including autonomous agents conducting reconnaissance, exploitation and data theft with limited human involvement. As AI systems such as Google Gemini become increasingly capable of interacting directly with computers and executing complex tasks, security teams need to understand not only what AI is asked to do, but also what it’s actually doing, what it can access and how its behavior connects to the rest of the ecosystem.
Gurucul AI Risk and Response addresses this emerging need by bringing AI activity into the full security context surrounding it: who or what initiated it, which identity and privileges were used, what data and systems were reached, and how behavior changed over time. Built on more than a decade of behavioral AI, it analyzes users and autonomous agents as persistent entities to reveal shadow AI, excessive access and emerging behavioral risk.
Security teams get an evidence-backed view of what happened, why it matters and how to respond, leveraging playbooks and existing controls. AI Risk and Response helps teams find risky behavior early and stop it before it escalates.
With AI Risk and Response’s prevention capabilities now in preview, organizations gain an additional layer of protection by identifying and stopping risky AI activity at the source. The solution builds on Gurucul’s market-leading security information and event management (SIEM), user entity behavior analytics (UEBA) and AI insider risk management (AI-IRM) capabilities to detect, investigate and respond to AI-related risk in real time.
Unlike standalone AI gateways and other point solutions, Gurucul AI Risk and Response provides a broader behavioral view of AI risk across the enterprise. It combines AI-platform data with existing proxy, endpoint detection and response (EDR), identity, operating system and cloud telemetry, giving security teams a connected view of AI activity and its broader security context.
By applying behavioral AI to this connected context, along with hundreds of detections mapped to all 16 MITRE ATLAS tactics and the OWASP Top 10 for LLM Applications, Gurucul enables security teams to detect, investigate and respond to AI-related risk with machine-speed analysis across the enterprise.
For managed security service providers (MSSPs), protecting customers from AI risk requires more than visibility into AI usage. They need evidence-rich findings that can be deployed quickly across diverse customer environments and acted on without adding operational complexity.
Jay Martin , CISO and VP of Cybersecurity at Blue Mantis, said: “Our customers need to understand not only where AI is being used, but when that use creates risk to sensitive information and critical systems. Gurucul AI Risk and Response can be enabled quickly using telemetry already available in the customer environment, providing rapid visibility without custom engineering or additional endpoint agents.
The solution identifies sensitive, non-public information being shared with unapproved generative AI services and correlates that activity with the user and endpoint behavior our analysts need to investigate. This reduces implementation time, operational overhead and cost while enabling our Security Operations team to respond more quickly with minimal disruption to customer environments.
For an MSSP like Blue Mantis, the difference between seeing AI activity and having the context and evidence behind it is the difference between forwarding another alert and helping a customer understand and address real risk.”
Gurucul AI Risk and Response lets security teams:
Reveal AI activity and exposure using data already available. AI data pipelines ingest and normalize activity from leading AI platforms, including Anthropic Claude AI, Gemini Enterprise Agent Platform, Google Gemini, OpenAI ChatGPT, Azure AI Foundry Inventory, and Microsoft 365 Copilot, alongside existing proxy, EDR, identity, operating system and cloud telemetry. Organizations can identify sanctioned and unsanctioned AI use, build an inventory of agents, models, tools and hosts, and connect that activity to owners, permissions and accessible resources. Teams can begin with data they already collect and add direct AI platform integrations for deeper prompt, agent and audit context.
Detect and prioritize known threats and emerging AI risk. Behavioral AI and deterministic detection logic work together to identify Shadow AI, sensitive data exposure, risky autonomous agents, excessive access, AI supply-chain risk and changes in behavior that fixed rules may miss. Hundreds of detections span five AI security families, with coverage mapped across all 16 MITRE ATLAS tactics and the OWASP Top 10 for LLM Applications. Unified Entity Intelligence combines those findings into an active risk score backed by the evidence that drove it.
Turn AI alerts into identity-resolved investigations. Connect AI activity to the human or non-human identity behind it, along with the systems, tools, data and relationships involved. Analysts can see what changed, how the activity compares with the entity’s history and peers, what the AI can access and how separate events combine into a developing risk. The AI Security Overview, Agent Workspace and Graph Explorer provide a direct path from an initial finding to the affected entities, related activity and underlying evidence.
Respond through controls and workflows already in place. Automated and approval-gated playbooks help teams contain risk through connected identity, endpoint, network and supported AI-platform controls. AI-assisted recommendations give analysts clear response options while keeping them responsible for consequential actions. Integration with enterprise ITSM routes and tracks remediation through established security and IT processes, eliminating the need for a separate response workflow for AI.
Prevent selected high-risk AI activity at the point of interaction. Automated controls identify and stop supported high-risk AI interactions before they escalate. A lightweight browser plug-in provides an additional point of control for prompts, pasted content, readable file uploads and AI destinations, helping organizations apply policy where AI activity occurs while keeping analysts in control of enforcement decisions and exceptions.
As the latest advances in AI have proven, tackling AI Risk now is more important than ever. “As AI moves from generating answers to taking action, risk no longer lives within a single prompt or application. It develops across identities, permissions, data, tools and actions over time. Insider and SecOps teams need to connect those signals to understand what changed, why it matters and where the risk is headed,” said Saryu Nayyar , CEO of Gurucul.
“Gurucul AI Risk and Response applies behavioral AI, entity intelligence and evidence-backed risk scoring to put AI activity in the context of the broader security environment. This gives analysts a clear, actionable view of developing threats and the control to address them early through the workflows and processes they already use. With runtime prevention now in preview, we are taking the next step: stopping high-risk AI behavior at machine speed at the source,” Nayyar concluded.
首次收录 · 2026-09-25 · 7.47 分