By Darwin Salazar
with Matt Jane, Curtis Redgate, Kenneth Kaye, and Valerie Worman

Click book to download your copy.
The ebook is free and linked to the left.
This form is only for a printed copy, U.S. mailing addresses only, while supplies last.
Claude Code, Claude Cowork, OpenAI Codex, Cursor, GitHub Copilot, enterprise AI platforms, and Gemini in Google Workspace all emit security-relevant records. The hard part is knowing where those records live, what they capture, which identifiers matter, and what never shows up.
This field guide maps those sources and puts the data in context across monitoring, detection, threat hunting, investigations, incident response, governance, and AI asset inventory.
No source tells the whole story. By the end, you will know which records to collect, how to interpret them, which security questions they can answer, and where endpoint, identity, Git, SaaS, and network data must fill the gaps.
Eight AI tooling sources,
one book
Claude Code, Cursor, GitHub Copilot, Anthropic, OpenAI, and more, one chapter each.
What's recorded, what's missing
Every chapter maps the fields that matter and where each source's evidence runs out.
Detection to governance
Use the same records for detection, hunting, investigation, incident response, governance, and inventory.