Configuring AI Detection & Response (AIDR)

Introduction

Field Effect MDR's AI Detection & Response (AIDR) leverages our endpoint agent, the network sensor, and the DNS Firewall to help you understand, govern, and secure AI tool usage in your network. 


This functionality is built directly into our MDR platform, and geared at addressing challenges such as: 

  • Shadow AI (employees using AI tools without approval)
  • Unauthorized or rogue AI applications
  • Over-permissioned AI integrations
  • Data leakage and privacy risks
  • AI governance and compliance concerns
  • Prompt manipulation and other AI-specific attack vectors


This article covers the following topics: 


Core AIDR Features

FeatureDescriptionExamples

AI Discovery


Uncover shadow AI that might otherwise go unnoticed.


Identify:
- Which AI tools are being used
- Who is using them
- Where they are being used
- How they connect to business systems and data sources


AI Assessment


See where AI is introducing risk and prioritize mitigation efforts.


Gain visibility into:
- AI application access to business data
- Connected systems and services
- Potential security and governance risks
- Anomalous AI-related activity


AI Governance


Enable AI innovation without losing control of organizational data and systems


Organizations can:
- Block unapproved AI tools
- Establish approved AI policies
- Apply zero-trust principles to AI access
- Monitor adoption of sanctioned AI services


Enable AIDR Functionality in Field Effect MDR

The following sections outline how to enable our AIDR features for your Field Effect MDR deployment. 


The DNS Firewall

We recommend blocking all AI sites via the DNS Firewall and allowing only those permitted under your AI governance policies. 


See Control AI Tool Access Using the DNS Firewall to learn more. 



Endpoint Agents

You can enforce additional AIDR functionality via the endpoint agent. We recommend that administrators deny all AI tools by default and allow only those allowed by governance policy for users. 


There are two ways to configure AI Security at endpoints - please select your preferred option:


ToolIntended AudienceHelp Center Article
VisionPartners


AI Security: Configuration (Vision)

MDR SIEM PortalDirect clients
AI Security: Configuration (MDR SIEM Portal)



Leverage AIDR Functionality

Once AIDR functionality is enabled, you can begin to view AI usage taking place in your environment, and as take actions to contain unauthorized AI use.  


Learn more about monitoring AI use with Field Effect MDR: 


ToolIntended AudienceHelp Center Article

Vision


Partners


AI Monitoring (Vision)


MDR SIEM Portal

Direct clientsAI Monitoring (MDR SIEM Portal)


Every time a detection is made, it's listed on the Policy Detections page, which is available via Vision or the MDR SIEM Portal. Learn more about viewing policy detections: 


ToolIntended AudienceHelp Center Article

Vision


Partners


Policy Detections (Vision)


MDR SIEM Portal

Direct Clients
Policy Detections (MDR SIEM Portal)






Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article