Meet the Monad team at Black Hat
Join us in Vegas
Join us in Vegas

A Security Field Guide to AI Tooling Visibility

By Darwin Salazar

with Matt Jane, Curtis Redgate, Kenneth Kaye, and Valerie Worman

Click book to download your copy.

Request your physical copy of the book

The ebook is free and linked to the left.

This form is only for a printed copy, U.S. mailing addresses only, while supplies last.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.


AI tools now read and write code, run commands, search business data, and act through connected systems.

What gets logged varies by product.

Claude Code, Claude Cowork, OpenAI Codex, Cursor, GitHub Copilot, enterprise AI platforms, and Gemini in Google Workspace all emit security-relevant records. The hard part is knowing where those records live, what they capture, which identifiers matter, and what never shows up.

This field guide maps those sources and puts the data in context across monitoring, detection, threat hunting, investigations, incident response, governance, and AI asset inventory.

No source tells the whole story. By the end, you will know which records to collect, how to interpret them, which security questions they can answer, and where endpoint, identity, Git, SaaS, and network data must fill the gaps.

Eight AI tooling sources,
one book

Claude Code, Cursor, GitHub Copilot, Anthropic, OpenAI, and more, one chapter each.

What's recorded, what's missing

Every chapter maps the fields that matter and where each source's evidence runs out.

Detection to governance

Use the same records for detection, hunting, investigation, incident response, governance, and inventory.

Trusted by security teams at

  • Robinhood logo
  • CoreWeave logo
  • Rubrik logo
  • Lambda logo
  • Upstart logo
  • Ironclad logo
  • Saviynt logo
  • Greenlight logo