New post: Detecting Misuse with the Claude Compliance API ๐
Mapping the Compliance API feed to your SIEM gets you IAM and access detections โfor freeโ, but the real AI threats live in the message content: prompt injection, jailbreaks, exfiltration prep, shadow data flow.
So I built a prefilter โ LLM judge โ SIEM pipeline to catch them, with a working repo + Sigma rules to run offline.









