Detection-as-Code for AI Threats: Writing Splunk Detections for LLM-Powered Attacks
Extending detection-as-code pipelines to cover AI-specific threat patterns — from prompt injection detection and anomalous agent behavior to LLM data exfiltration indicators, with production-ready Splunk SPL and ESCU-compatible YAML.
