Netskope è nuovamente riconosciuto come Leader nel Quadrante™ Magico di Gartner® per le piattaforme SASE e il Security Service Edge
Authored by the Netskope Security Incident Response Team
This document is the standard operating procedure (SOP) Netskope’s security incident response team uses to investigate incidents involving AI models, large language models (LLMs), and agentic AI systems.
Agentic AI systems don’t fail the way traditional software does. When something goes wrong, the evidence lives in reasoning traces, tool calls, vector retrievals, and model outputs, and some of it disappears the moment a session ends.
Most incident response playbooks assume static logs and predictable systems. They can’t answer questions like: did the agent invent that tool parameter, or was it told to? Was a poisoned document the entry point, or did someone tamper with the model itself? Was this a human-driven attack, or a confident hallucination?
This paper is a practical, four-layer framework for security teams, covering evidence acquisition through root cause and reporting. We are sharing this for the benefit of other incident response teams who need to move as fast as the systems they’re defending.
Scopri: