Embedding Security in LLM Workflows: Elastic's Proactive Approach
ID: de2053ef-a5c7-588b-ba23-8cc3e87731cb
STIX ID: report--de2053ef-a5c7-588b-ba23-8cc3e87731cb
Feed Name: Elastic Security Labs
Elastic Labs demonstrates a proof-of-concept approach to audit and detect malicious LLM activity by proxying LLM requests, enriching logs with security analysis (LLM-Guard, LangKit, Rebuff, etc.), indexing to Elasticsearch, and creating ES|QL detection rules for threats like prompt injection, insecure output handling, model DoS, and sensitive information disclosure. The write-up includes a Flask proxy example, enrichment function pseudocode, sample detection queries, and recommendations for production alternatives (APM, OpenTelemetry, ECS normalization).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
