Skip to main content

Lumen documentation

Shine a light on AI use

Lumen is AI Detection & Response (AIDR). It captures AI interactions across endpoints, browsers, applications, agents and gateways, inspects them in real time for LLM-specific risks, and can Log, Redact or Block per policy.

Install the agent    What is Lumen?

Detect LLM-specific risks

Six detection classes: prompt injection and jailbreaks, sensitive-data exposure, malicious entities, toxic content, language, and topic violations — evaluated inline, in single-digit milliseconds.

Respond inline

Every interaction resolves to one action: Log it, Redact the matched spans before anyone sees them, or Block it outright. A secret split across streaming chunks is caught before either half is delivered.

Cover every layer

A family of collectors: the endpoint agent with its capturing proxy, a managed-browser extension, application SDKs, an MCP proxy for agentic traffic, gateway plugins, and cloud-platform ingestion.

Correlate in your SIEM

Findings live in the Lumen console and export to the Wazuh Indexer, so AI activity correlates with the endpoint, network and identity telemetry you already have.

WazuhPart of the Wazuh Labs ecosystem.