AI Detection & Response (AIDR) provides IT administrators with complete visibility into AI tool usage across their managed endpoint fleet. As employees adopt generative AI tools, often connecting them to corporate systems without IT oversight, organizations face growing exposure to unmanaged software, unauthorized data sharing, and potential data loss.
In this initial release of AIDR, admins can discover every AI tool in use across endpoints and tag tools as authorized or unauthorized. This functionality is free for all Nebula customers.
How it works
AIDR uses two signals already collected by the ThreatDown Endpoint Agent:
Software Inventory: Provides visibility into AI applications installed on endpoints, including desktop apps and coding assistants. This covers tools that never make network requests. Local Large Language Models (LLMs) are not supported in this phase.
Domain traffic monitoring (Web Protection): Surfaces outbound connections to AI service domains. This covers browser-based AI tools (ChatGPT, Gemini, Claude, Midjourney, etc.) and API-accessed services that don't install locally. Browser extensions are not supported in this phase.
Together, these two signals give you a complete picture of AI in your environment. Data appears on the AIDR dashboard after an asset scan of installed software, and within a few minutes for AI domain activity.
Features
- See every AI tool detected across your environment, including endpoint count and access method.
- Tag tools as Authorized or Unauthorized.
- Monitor AI usage at the environment and endpoint levels.
- Get alerted when a new ungoverned tool is detected.
Back to AIDR guide.