Rule Test Mode
Type any command to see which enforcement rule would fire — no execution, dry-run only.
🔗
Palo Alto Cortex XSIAM
Forward alerts as Cortex-native telemetry
Ship enforcement events directly to Cortex XSIAM as structured AI agent telemetry. Enables correlation with endpoint, network, and identity signals in a single XDR view.
🔬
Unit 42 Threat Intelligence
Auto-update rules from PANW threat research
Pull new AI agent threat signatures directly from Unit 42 research. Enforcement rules update automatically as new attack patterns are identified — no redeployment required.
WOULD COVER
✓ AI agent jailbreak patterns (weekly updates)
✓ LLM prompt injection signatures
✓ Supply chain attack indicators
✓ Zero-day CVE enforcement rules
☁
GCP Cloud Logging
Ship events to Cloud Logging + BigQuery
Forward all enforcement events to GCP Cloud Logging with structured fields. Enables BigQuery analytics, long-term retention, and a cloud-hosted portal accessible from anywhere.
📊
Splunk SIEM
HEC forwarder to Splunk Enterprise / Cloud
Splunk HEC forwarder is active and shipping enforcement events. All three log sources (blocks, alerts, PII detections) are forwarded with structured JSON fields compatible with Splunk ES.
✓ Forwarder running · Events flowing · Index: ai-enforcement
💬
Slack Alerts
Real-time CRITICAL alerts to a Slack channel
Post CRITICAL severity blocks to a Slack channel in real time. Webhook URL is read from /etc/ai-enforcements.env.
🔐
CyberArk Identity
Govern who can modify AI policy
Require CyberArk Identity authentication before any policy rule can be toggled. Policy changes are recorded against the authenticated human identity — not just the session user.