Lumen documentation
Shine a light on AI use
Lumen is AI Detection & Response (AIDR). It captures AI interactions across endpoints, browsers, applications, agents and gateways, inspects them in real time for LLM-specific risks, and can Log, Redact or Block per policy.
Detect LLM-specific risks
Six detection classes: prompt injection and jailbreaks, sensitive-data exposure, malicious entities, toxic content, language, and topic violations — evaluated inline, in single-digit milliseconds.
Respond inline
Every interaction resolves to one action: Log it, Redact the matched spans before anyone sees them, or Block it outright. A secret split across streaming chunks is caught before either half is delivered.
Cover every layer
A family of collectors: the endpoint agent with its capturing proxy, a managed-browser extension, application SDKs, an MCP proxy for agentic traffic, gateway plugins, and cloud-platform ingestion.
Correlate in your SIEM
Findings live in the Lumen console and export to the Wazuh Indexer, so AI activity correlates with the endpoint, network and identity telemetry you already have.
Part of the Wazuh Labs ecosystem.