<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel>
<title>ThreatNotes</title>
<link>https://threatnotes.dev</link>
<description>Security Research · Detection Engineering · Threat Hunting · AI Security</description>
<language>en-us</language>
<item>
<title>AI Gateway Telemetry in the SOC: From Events to AI Security Detections</title>
<link>https://threatnotes.dev/post/ai-gateway-telemetry-in-the-soc.html</link>
<guid>https://threatnotes.dev/post/ai-gateway-telemetry-in-the-soc.html</guid>
<pubDate>Tue, 21 Jul 2026 00:00:00 +0000</pubDate>
<description>Part 2 of the series. A working demonstration that turns AI Gateway (LLM Guard) telemetry into LogRhythm detections (prompt injection, credential exposure, PII/DLP, prohibited topics, malicious URLs, and token abuse), each blocked at the gateway and made investigable in the SIEM.</description>
</item><item>
<title>AI Gateways and AI Agents: Building a Layered AI Security Architecture</title>
<link>https://threatnotes.dev/post/ai-gateways-ai-agents-layered-security.html</link>
<guid>https://threatnotes.dev/post/ai-gateways-ai-agents-layered-security.html</guid>
<pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
<description>AI Agent monitoring shows what an agent did, but an agent only executes a decision the AI Model already made. A complete AI security strategy secures every layer, starting with the decision itself at the AI Gateway. Here's how the layers fit together.</description>
</item>
</channel></rss>