Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,7 @@ security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/m365_copilot/copilot_prompt_logs.csv
- data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/m365_copilot/copilot_prompt_logs.csv
sourcetype: csv
source: csv
test_type: experimental
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/m365_copilot/copilot_prompt_logs.csv
- data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/m365_copilot/copilot_prompt_logs.csv
sourcetype: csv
source: csv
test_type: experimental
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -89,7 +89,7 @@ security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/m365_copilot/copilot_prompt_logs.csv
- data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/m365_copilot/copilot_prompt_logs.csv
sourcetype: csv
source: csv
test_type: experimental
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -63,7 +63,7 @@ security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/m365_copilot/copilot_prompt_logs.csv
- data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/m365_copilot/copilot_prompt_logs.csv
sourcetype: csv
source: csv
test_type: experimental
Expand Down
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
name: Ollama Abnormal Network Connectivity
id: 19ec30ad-faa2-496a-a6a9-f2e5f778fbdb
version: 5
version: 6
creation_date: '2025-10-13'
modification_date: '2026-05-13'
modification_date: '2026-09-24'
author: Rod Soto
status: experimental
status: production
type: Anomaly
description: Detects abnormal network activity and connectivity issues in Ollama including non-localhost API access attempts and warning-level network errors such as DNS lookup failures, TCP connection issues, or host resolution problems that may indicate network-based attacks, unauthorized access attempts, or infrastructure reconnaissance activity.
data_source:
Expand Down Expand Up @@ -61,5 +61,4 @@ tests:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/ollama/app.log
sourcetype: ollama:server
source: app.log
test_type: experimental
description: This test is a legacy experimental test and may not be accurate.
test_type: unit
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
name: Ollama Abnormal Service Crash Availability Attack
id: 327fa152-9b56-4e4e-bc0b-2795d4068afa
version: 4
version: 5
creation_date: '2025-10-13'
modification_date: '2026-05-13'
modification_date: '2026-09-24'
author: Rod Soto
status: experimental
status: production
type: Anomaly
description: Detects critical service crashes, fatal errors, and abnormal process terminations in Ollama that may indicate exploitation attempts, resource exhaustion attacks, malicious input triggering unhandled exceptions, or deliberate denial of service attacks designed to disrupt AI model availability and degrade system stability.
data_source:
Expand Down Expand Up @@ -46,5 +46,4 @@ tests:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/ollama/app.log
sourcetype: ollama:server
source: app.log
test_type: experimental
description: This test is a legacy experimental test and may not be accurate.
test_type: unit
13 changes: 6 additions & 7 deletions detections/application/ollama_excessive_api_requests.yml
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
name: Ollama Excessive API Requests
id: 1cfab663-9adc-4169-a88c-6bae29ba3c70
version: 4
version: 5
creation_date: '2025-10-13'
modification_date: '2026-05-13'
modification_date: '2026-09-29'
author: Rod Soto
status: experimental
status: production
Comment thread
nasbench marked this conversation as resolved.
type: Anomaly
description: Detects potential Distributed Denial of Service (DDoS) attacks or rate limit abuse against Ollama API endpoints by identifying excessive request volumes from individual client IP addresses. This detection monitors GIN-formatted Ollama server logs to identify clients generating abnormally high request rates within short time windows, which may indicate automated attacks, botnet activity, or resource exhaustion attempts targeting local AI model infrastructure.
data_source:
- Ollama Server
search: '`ollama_server` | rex field=_raw "\|\s+(?<client_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\s+\|" | eval src=coalesce(src, client_ip) | eval dest=coalesce(dest, url, uripath, endpoint) | bin _time span=5m | stats count as request_count by _time, src, dest, host | where request_count > 120 | eval severity="high" | eval attack_type="Rate Limit Abuse / DDoS" | stats count by _time, host, src, dest, request_count, severity, attack_type | `ollama_excessive_api_requests_filter`'
search: '`ollama_server` | rex field=_raw "\|\s+(?<client_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\s+\|" | eval src=coalesce(src, client_ip) | eval dest=coalesce(dest, url, uripath, endpoint) | bin _time span=5m | stats count as request_count, values(dest) as dest by _time, src, host | where request_count > 120 | eval severity="high" | eval attack_type="Rate Limit Abuse / DDoS" | `ollama_excessive_api_requests_filter`'
how_to_implement: 'Ingest Ollama logs via Splunk TA-ollama add-on by configuring file monitoring inputs pointed to your Ollama server log directories (sourcetype: ollama:server), or enable HTTP Event Collector (HEC) for real-time API telemetry and prompt analytics (sourcetypes: ollama:api, ollama:prompts). CIM compatibility using the Web datamodel for standardized security detections.'
known_false_positives: Legitimate automated services (CI/CD pipelines, monitoring tools, batch jobs), multiple users behind NAT/proxy infrastructure, or authorized load testing activities may trigger this detection during normal operations. Operator must adjust threshold accordingly.
references:
Expand All @@ -28,7 +28,7 @@ intermediate_findings:
- field: src
type: system
score: 20
message: Possible DDoS attack from $src$ against Ollama server detected with request count $request_count$ in 1 minute, potentially causing service degradation or complete unavailability.
message: Possible DDoS attack from $src$ against Ollama server detected with request count $request_count$ in 5 minutes, potentially causing service degradation or complete unavailability.
analytic_story:
- Suspicious Ollama Activities
asset_type: Web Application
Expand All @@ -46,5 +46,4 @@ tests:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/ollama/server.log
sourcetype: ollama:server
source: server.log
test_type: experimental
description: This test is a legacy experimental test and may not be accurate.
test_type: unit
Original file line number Diff line number Diff line change
@@ -1,20 +1,22 @@
name: Ollama Possible API Endpoint Scan Reconnaissance
id: ad3f352a-0347-48ee-86b9-670b5025a548
version: 5
version: 6
creation_date: '2025-10-13'
modification_date: '2026-05-13'
modification_date: '2026-09-29'
author: Rod Soto
status: experimental
status: production
Comment thread
nasbench marked this conversation as resolved.
type: Anomaly
description: Detects API reconnaissance and endpoint scanning activity against Ollama servers by identifying sources probing multiple API endpoints within short timeframes, particularly when using HEAD requests or accessing diverse endpoint paths, which indicates systematic enumeration to map the API surface, discover hidden endpoints, or identify vulnerabilities before launching targeted attacks.
data_source:
- Ollama Server
search: |-
`ollama_server` "[GIN]"
| rex field=_raw "\|\s+(?<status_code>\d+)\s+\|\s+(?<response_time>[\d\.]+)s\s+\|\s+(?<src_ip>[\:\da-f\.]+)\s+\|\s+(?<http_method>\w+)\s+\"(?<uri_path>[^\"]+)\""
| eval src=src_ip
| bin _time span=5m
| stats count as total_requests, values(dest) as dest, values(http_method) as methods, values(status) as status_codes
| stats count as total_requests, dc(uri_path) as distinct_endpoints, count(eval(http_method="HEAD")) as head_requests, values(uri_path) as dest, values(http_method) as methods, values(status_code) as status_codes
BY _time, src, host
| where total_requests > 120
| where total_requests > 120 AND (distinct_endpoints >= 3 OR (distinct_endpoints >= 2 AND head_requests > 0))
| eval severity="medium"
| eval attack_type="API Activity Surge"
| stats count
Expand Down Expand Up @@ -58,5 +60,4 @@ tests:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/ollama/server.log
sourcetype: ollama:server
source: server.log
test_type: experimental
description: This test is a legacy experimental test and may not be accurate.
test_type: unit
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
name: Ollama Possible Memory Exhaustion Resource Abuse
id: ca96297f-e82e-4749-8cc9-d1ab555abb57
version: 4
version: 5
creation_date: '2025-10-13'
modification_date: '2026-05-13'
modification_date: '2026-09-29'
author: Rod Soto
status: experimental
status: production
Comment thread
nasbench marked this conversation as resolved.
type: Anomaly
description: Detects abnormal memory allocation patterns and excessive runner operations in Ollama that may indicate resource exhaustion attacks, memory abuse through malicious model loading, or attempts to degrade system performance by overwhelming GPU/CPU resources. Adversaries may deliberately load multiple large models, trigger repeated model initialization cycles, or exploit memory allocation mechanisms to exhaust available system resources, causing denial of service conditions or degrading performance for legitimate users.
data_source:
- Ollama Server
search: '`ollama_server` ("*llama_kv_cache*" OR "*compute buffer*" OR "*llama runner started*" OR "*loaded runners*") | rex field=_raw "count=(?<runner_count>\d+)" | rex field=_raw "size\s*=\s*(?<memory_mb>[\d\.]+)\s+MiB" | rex field=_raw "started in\s*(?<load_time>[\d\.]+)\s*seconds" | rex field=_raw "source=(?<code_source>[^\s]+)" | bin _time span=5m | stats count as operations, sum(runner_count) as total_runners, dc(code_source) as unique_sources, values(code_source) as code_sources, avg(memory_mb) as avg_memory, max(memory_mb) as max_memory, sum(memory_mb) as total_memory, avg(load_time) as avg_load_time, max(load_time) as max_load_time by _time, host | where operations > 5 OR total_runners > 0 OR max_memory > 400 OR total_memory > 500 | eval avg_memory=round(avg_memory, 2) | eval max_memory=round(max_memory, 2) | eval total_memory=round(total_memory, 2) | eval avg_load_time=round(avg_load_time, 2) | eval severity=case( max_memory > 500 OR total_memory > 1000, "critical", max_memory > 400 OR operations > 20, "high", operations > 10, "medium", 1=1, "low" ) | eval attack_type="Resource Exhaustion / Memory Abuse" | sort -_time | table _time, host, operations, total_runners, unique_sources, avg_memory, max_memory, total_memory, avg_load_time, max_load_time, severity, attack_type | `ollama_possible_memory_exhaustion_resource_abuse_filter`'
search: '`ollama_server` ("*llama_kv_cache*" OR "*compute buffer*" OR "*llama runner started*" OR "*loaded runners*") | rex field=_raw "count=(?<runner_count>\d+)" | rex field=_raw "size\s*=\s*(?<memory_mb>[\d\.]+)\s+MiB" | rex field=_raw "started in\s*(?<load_time>[\d\.]+)\s*seconds" | rex field=_raw "source=(?<code_source>[^\s]+)" | bin _time span=5m | stats count as operations, max(runner_count) as total_runners, dc(code_source) as unique_sources, values(code_source) as code_sources, avg(memory_mb) as avg_memory, max(memory_mb) as max_memory, sum(memory_mb) as total_memory, avg(load_time) as avg_load_time, max(load_time) as max_load_time by _time, host | where operations > 10 OR total_runners > 5 OR max_memory > 400 OR total_memory > 500 | eval avg_memory=round(avg_memory, 2) | eval max_memory=round(max_memory, 2) | eval total_memory=round(total_memory, 2) | eval avg_load_time=round(avg_load_time, 2) | eval severity=case( max_memory > 500 OR total_memory > 1000 OR total_runners > 10, "critical", max_memory > 400 OR operations > 20 OR total_runners > 5, "high", operations > 10, "medium", 1=1, "low" ) | eval attack_type="Resource Exhaustion / Memory Abuse" | sort -_time | table _time, host, operations, total_runners, unique_sources, avg_memory, max_memory, total_memory, avg_load_time, max_load_time, severity, attack_type | `ollama_possible_memory_exhaustion_resource_abuse_filter`'
how_to_implement: 'Ingest Ollama logs via Splunk TA-ollama add-on by configuring file monitoring inputs pointed to your Ollama server log directories (sourcetype: ollama:server), or enable HTTP Event Collector (HEC) for real-time API telemetry and prompt analytics (sourcetypes: ollama:api, ollama:prompts). CIM compatibility using the Web datamodel for standardized security detections.'
known_false_positives: Legitimate high-volume production workloads processing multiple concurrent requests, users loading large language models (7B+ parameters) that naturally require substantial memory allocation, simultaneous multi-model deployments during system scaling, batch processing operations, or initial system startup sequences may generate similar memory allocation patterns during normal operations.
references:
Expand Down Expand Up @@ -46,5 +46,4 @@ tests:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/ollama/server.log
sourcetype: ollama:server
source: server.log
test_type: experimental
description: This test is a legacy experimental test and may not be accurate.
test_type: unit
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
name: Ollama Possible Model Exfiltration Data Leakage
id: c9fd1a54-0eab-4470-8970-d5fcc3c740fb
version: 4
version: 5
creation_date: '2025-10-13'
modification_date: '2026-05-13'
modification_date: '2026-09-29'
author: Rod Soto
status: experimental
status: production
Comment thread
nasbench marked this conversation as resolved.
type: Anomaly
description: Detects data leakage and exfiltration attempts targeting Ollama model metadata and configuration endpoints. Adversaries repeatedly query /api/show, /api/tags, and /api/v1/models to systematically extract sensitive model information including architecture details, fine-tuning parameters, system paths, Modelfile configurations, and proprietary customizations. Multiple inspection attempts within a 15-minute window indicate automated exfiltration of valuable intellectual property such as custom model configurations, system prompts, and internal model specifications. This activity represents unauthorized data disclosure that could enable competitive intelligence gathering, model replication, or preparation for advanced attacks against the AI infrastructure.
data_source:
- Ollama Server
search: '`ollama_server` | rex field=_raw "\|\s+(?<status_code>\d+)\s+\|\s+(?<response_time>[\d\.]+)s\s+\|\s+(?<src_ip>[\:\da-f\.]+)\s+\|\s+(?<http_method>\w+)\s+\"(?<uri_path>[^\"]+)\"" | eval src=src_ip | eval dest=uri_path | where response_time > 55 | bin _time span=15m | stats count, avg(response_time) as avg_response_time, max(response_time) as max_response_time by _time, src, dest, uri_path | eval avg_response_time=round(avg_response_time, 2) | eval max_response_time=round(max_response_time, 2) | eval severity=case( avg_response_time > 50, "high", avg_response_time > 40, "medium", 1=1, "low" ) | eval attack_type="Potential Data Exfiltration" | sort -_time | stats count by _time, src, uri_path, avg_response_time, max_response_time, severity, attack_type | `ollama_possible_model_exfiltration_data_leakage_filter`'
search: '`ollama_server` | rex field=_raw "\|\s+(?<status_code>\d+)\s+\|\s+(?<response_time>[\d\.]+)s\s+\|\s+(?<src_ip>[\:\da-f\.]+)\s+\|\s+(?<http_method>\w+)\s+\"(?<uri_path>[^\"]+)\"" | eval src=src_ip | eval dest=uri_path | where tonumber(response_time) > 55 AND in(uri_path, "/api/show", "/api/tags", "/api/v1/models") | bin _time span=15m | stats count as inspection_attempts, avg(response_time) as avg_response_time, max(response_time) as max_response_time by _time, src, uri_path | where inspection_attempts >= 2 | eval avg_response_time=round(avg_response_time, 2) | eval max_response_time=round(max_response_time, 2) | eval severity=case( avg_response_time > 50, "high", avg_response_time > 40, "medium", 1=1, "low" ) | eval attack_type="Potential Data Exfiltration" | sort -_time | `ollama_possible_model_exfiltration_data_leakage_filter`'
how_to_implement: 'Ingest Ollama logs via Splunk TA-ollama add-on by configuring file monitoring inputs pointed to your Ollama server log directories (sourcetype: ollama:server), or enable HTTP Event Collector (HEC) for real-time API telemetry and prompt analytics (sourcetypes: ollama:api, ollama:prompts). CIM compatibility using the Web datamodel for standardized security detections.'
known_false_positives: Legitimate administrative activities such as model inventory management, monitoring dashboards polling model status, automated health checks verifying model availability, CI/CD pipelines validating deployments, development tools inspecting model configurations, or users browsing available models through management interfaces may trigger this detection during normal operations. Adjust the threshold based on your environment's baseline activity.
references:
Expand All @@ -28,7 +28,7 @@ intermediate_findings:
- field: src
type: system
score: 20
message: Potential model data exfiltration detected from $src$ with $avg_response_time$ attempts across endpoints, indicating systematic extraction of sensitive model configurations, architecture details, and proprietary customizations that may constitute intellectual property theft.
message: Potential model data exfiltration detected from $src$ with $inspection_attempts$ slow inspection attempts to $uri_path$ in 15 minutes, indicating systematic extraction of sensitive model configurations, architecture details, and proprietary customizations that may constitute intellectual property theft.
analytic_story:
- Suspicious Ollama Activities
asset_type: Web Application
Expand All @@ -46,5 +46,4 @@ tests:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/ollama/server.log
sourcetype: ollama:server
source: server.log
test_type: experimental
description: This test is a legacy experimental test and may not be accurate.
test_type: unit
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
name: Ollama Possible RCE via Model Loading
id: 3f28c930-5208-425d-a7b9-53d349756d91
version: 4
version: 5
creation_date: '2025-10-13'
modification_date: '2026-05-13'
modification_date: '2026-09-24'
author: Rod Soto
status: experimental
status: production

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Require RCE-specific evidence before production promotion

Promoting this rule exposes a production RCE finding for any single level=ERROR event containing broad terms such as model or server.go, because the inspected SPL only requires error_count > 0. Ordinary failures already listed under known_false_positives—for example an incompatible or corrupted model—therefore generate a medium-severity potential-RCE finding without any injection, traversal, or execution indicator.

Useful? React with 👍 / 👎.

type: Anomaly
description: Detects Ollama server errors and failures during model loading operations that may indicate malicious model injection, path traversal attempts, or exploitation of model loading mechanisms to achieve remote code execution. Adversaries may attempt to load specially crafted malicious models or exploit vulnerabilities in the model loading process to execute arbitrary code on the server. This detection monitors error messages and failure patterns that could signal attempts to abuse model loading functionality for malicious purposes.
data_source:
Expand Down Expand Up @@ -46,5 +46,4 @@ tests:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/ollama/app.log
sourcetype: ollama:server
source: app.log
test_type: experimental
description: This test is a legacy experimental test and may not be accurate.
test_type: unit
Loading
Loading