splunk
unknown
spl
Windows Local LLM Framework Execution
The following analytic detects execution of unauthorized local LLM frameworks (Ollama, LM Studio, GPT4All, Jan, llama.cpp, KoboldCPP, Oobabooga, NutStudio) and Python-based AI/ML libraries (HuggingFace Transformers, LangChain) on Windows endpoints by leveraging process creation events.
It identifies cases where known LLM framework executables are launched or command-line arguments reference AI/ML libraries.
This activity is significant as it may indicate shadow AI deployments, unauthorized model