Skip to content
Shadow AI Discovery

Find the AI Tools Nobody Told You About

Five detection layers surface every AI coding tool, local inference server, and unreviewed LLM destination on your fleet - including the ones with no signature.

The Situation

Adoption Ran Ahead of Governance

Somewhere between the pilot program and the policy document, AI coding tools became standard equipment. Engineers installed what worked, connected the MCP servers they needed, and in some cases ran models locally so nothing left the laptop at all.

Security learns the actual footprint during an incident, an audit, or a surprise invoice - rarely before.

What Goes Wrong Today

Inventory Methods That Miss

  • Software inventory misses CLIs. Package-manager installs and single-binary tools do not show up like enterprise applications do.
  • Network monitoring misses local models. Ollama and LM Studio never leave the machine, so egress-only approaches see nothing.
  • Signature lists lag. New AI tools ship weekly and custom scripts calling an LLM API have no signature at all.
  • Surveys are self-reported. Asking developers what they run produces an optimistic subset of the truth.
What Kraitos AIDR Does

Detection That Does Not Depend on Knowing the Tool

DiscoveryConfig directories, VS Code and JetBrains extensions, process names - 14 tools by name
NetworkConnection monitoring - 25+ cloud LLM APIs and 7 local inference servers identified by destination
BehavioralBehavioral heuristics recognize how AI tools act, catching unknown and custom tools
TelemetryDeep session telemetry for Claude Code - sessions, tokens, MCP destinations
DependencyDependencies across 9 package formats, with known vulnerabilities flagged

Then it stays current

  • New tools appearing on any endpoint trigger an alert the moment they show up
  • Auto-discovered AI systems land in the AI Register as shadow / unclassified and enter a review queue
  • Unapproved destinations are flagged in the egress console for one-click reclassification or blocking
  • Local model inventory records name, size, quantization, and last-used time for self-hosted inference
What You End Up With

A Real Inventory, Kept Current by the Platform

  • Every AI tool on every endpoint, by name where a name exists and by behavior where it does not
  • A live register of AI systems with risk tier and approval status
  • Alerts the first time an unapproved tool appears anywhere in the fleet
  • Asset-inventory evidence for NIST CM-8 and ISO A.5.9 generated as a byproduct
Per-device AI tool inventory listing each detected tool with version, first seen, and last seen dates
Per-device AI tool inventory - every tool found by name or by network destination, with version and first and last seen.

See Kraitos AIDR in Action

Deploy in 60 seconds. Get answers in 24 hours. Stop guessing what your AI-augmented organization is doing.

[email protected]kraitos.io