Skip to main content
Network Detection & Response

AIQSO Faron · formerly Network Sentinel

Bring your shadow AI into the light.

Faron reveals every AI service on your network — agentlessly, from passive traffic alone. No endpoint. No interception. See what you couldn't see, in hours.

DNSTLS SNIJA3 / JA4Flow shape

Agentless · Passive · No Endpoint · Self-Hosted

Key Takeaways

  • Agentless shadow-AI detection — see which AI services are in use across your network in hours, nothing to install
  • Honest by design: Faron detects communication with AI services, never claims to read prompts or payloads from passive traffic
  • Unified risk scoring across your entire security stack — not siloed alerts from separate tools
  • Self-hosted deployment means your data never leaves your infrastructure
  • Maps to compliance frameworks including NIST CSF, CIS Controls v8, SOC 2, and CMMC
The Faron wedge

Four passive signals. Zero agents.

Faron answers is AI being used, which service, and which host — from traffic your network already carries.

DNS Queries

Lookups to AI providers — api.openai.com, claude.ai, gemini.google.com — reveal which hosts are reaching which AI services, before a single byte of content is exchanged.

TLS SNI

The server name in the ClientHello is still sent in the clear for most traffic. Faron reads it to attribute encrypted sessions to a specific AI service — without ever decrypting them.

JA3 / JA4 Fingerprints

TLS client fingerprints separate an SDK client (httpx, requests) from a browser — telling apart "an app making API calls" from "an employee chatting in a browser."

Traffic Shape

Streaming LLM responses have a tell-tale flow — a small request up, a long-lived token-trickle down. Faron classifies that pattern from flow metadata alone.

In the product

The dashboard, not a mockup

Captured from the live Faron deployment monitoring our own network — the same system we demo. Device addresses relabeled.

Faron Overview dashboard showing a live security posture score, device and alert counts, and AI-generated recommendations to improve the score
OverviewSecurity posture at a glance — live score, device and alert counts, and AI-generated recommendations for raising it.
Faron AI Inventory page listing detected AI services (Anthropic Claude, OpenAI) marked unsanctioned, and the devices using them
AI InventoryThe shadow-AI ledger — which AI services are on the network, which devices are talking to them, and whether each is sanctioned.
Detection limits

Honest about what we can — and can't — see

Security-literate buyers trust a tool that names its blind spots. This section is the product argument, not the fine print.

SignalWhat it tells usWhere it ends
DNS queriesWhich hosts resolve AI-provider domains, and how oftenDNS-over-HTTPS/TLS hides queries from passive view — but Faron flags that DoH itself is in use, which is a policy signal of its own
TLS SNIWhich AI service an encrypted session is talking toEncrypted Client Hello (ECH) will erode SNI over time — Faron treats ECH adoption itself as an evasion signal worth surfacing
JA3 / JA4Whether the client is an SDK, a CLI, or a browserFingerprints classify the client type; they do not identify the person or read the session
Flow metadataStreaming-response patterns characteristic of LLM trafficPrompts and payloads are never visible from passive traffic — reading content would require a TLS-inspecting proxy or an endpoint agent, which Faron is not

Documented blind spots

Local models (Ollama, llama.cpp) generate no external traffic — a documented blind spot
VPNs, personal hotspots, and cellular paths fall outside passive network visibility
Faron sees communication with AI services — never the content of that communication
Sensor placement matters: traffic that never crosses the monitored SPAN/TAP is invisible

If a vendor tells you passive monitoring reads AI prompts, ask them how. Faron doesn't claim it — because it isn't true of passive traffic.

Architecture

A mirror port, a sensor, and nothing on your endpoints

Faron listens to a SPAN/mirror port or TAP through a Zeek sensor. Traffic is analyzed in place — nothing is intercepted, nothing leaves your network.

EVERYTHING STAYS ON YOUR INFRASTRUCTUREYour networkSwitch mirror port(SPAN) or TAPREAD-ONLY COPYtraffic copyZeek sensorpassive · no interceptionDNSTLS SNIJA3 / JA4Flow shapemetadata onlyFaron coreAI-service intelligence feedRisk engine (0–100 / device)Device inventory + fingerprintsDashboardsGrafana · complianceAlertsSlack · ntfy · digestsTickets + SIEMZammad · Wazuh
1

Reveal

A passive network sensor reads DNS, TLS SNI, and JA3/JA4 fingerprints to reveal which hosts are talking to which AI services, plus a device inventory synced every 5 minutes. No agent, no interception.

2

Assess

Vulnerability data from Wazuh feeds every 15 minutes. Firewall policies analyzed for exposure. Zeek captures network behavior baselines over rolling 7-day windows.

3

Score

The risk engine calculates a 0-100 score per device: Device Type (30%) + Policy Exposure (35%) + Vulnerabilities (20%) + Behavior (15%). Critical devices surface instantly.

4

Alert

Smart alerting with deduplication and fatigue scoring. Critical findings hit Slack and push notifications immediately. Low-priority items batch into daily digests.

5

Report

Automated daily, weekly, and monthly reports with AI-powered executive summaries. Compliance posture dashboards for NIST CSF, CIS v8, and SOC 2.

Risk = DT(.30) + PE(.35) + V(.20) + B(.15)Device Type + Policy Exposure + Vulnerabilities + Behavior

What Faron Does

One platform to reveal, monitor, score, detect, and respond — across your entire stack.

Agentless Shadow-AI Detection

See every AI service in use across your network from passive traffic alone — no endpoint agent, no TLS interception. The zero-friction POC that answers "who is using AI, and which service" in hours.

Unified Risk Scoring

Policy-aware risk scores combining device type, firewall exposure, CVE data, and behavioral anomalies. Know which devices need attention — ranked by actual risk, not just alert volume.

Plugin Framework

Swap integrations without changing code. Built-in adapters for Wazuh, UniFi, Elasticsearch, Zammad, Ollama, Slack, and ntfy. Write a custom plugin in ~50 lines.

Compliance Dashboards

Pre-built frameworks for NIST CSF, CIS v8, and SOC 2 Type II with weighted scoring and maturity levels. Automated evidence collection for audit readiness.

Blast Radius Analysis

1-hop and 2-hop network reachability from any device. See exactly what an attacker could reach if a device is compromised — based on your actual firewall rules.

AI-Powered Analysis

Natural language queries powered by Ollama. Ask "which IoT devices have critical vulnerabilities?" and get actionable answers. AI-generated executive summaries for leadership.

Network Traffic Analysis

Zeek sensor integration for deep flow inspection. Connection logs, DNS queries, HTTP requests, and SSL certificate analysis — with behavioral anomaly detection.

Smart Alerting

Alert deduplication, fatigue scoring, and severity-based routing. Critical alerts go to Slack and push notifications. Low-priority findings batch into daily digests.

Self-Hosted & Private

Deployed on your infrastructure. Your data never leaves your network. Full data sovereignty with multi-tenant isolation for MSPs managing multiple clients.

What We Monitor

From shadow-AI detection to compliance posture — full-stack visibility.

Shadow AI

  • AI-service detection via DNS + TLS SNI
  • SDK-vs-browser JA3/JA4 fingerprinting
  • Streaming-response traffic-shape heuristics
  • Curated AI-service intelligence feed

Devices

  • Automated device discovery via UniFi/Meraki
  • IoT/OT fingerprinting via MAC OUI + DHCP
  • Real-time inventory sync (every 5 min)
  • Device classification and risk tagging

Vulnerabilities

  • CVE tracking from Wazuh feeds (every 15 min)
  • Severity scoring (Critical/High/Medium/Low)
  • Vulnerability-to-device mapping
  • Patch status and remediation tracking

Compliance

  • NIST CSF (19 controls)
  • CIS v8 (10 controls)
  • SOC 2 Type II (9 controls)
  • CMMC-aligned continuous monitoring

Bring Your Own Tools

Six plugin categories let you swap integrations without changing core code. Faron is the sensor and intelligence layer that makes your SIEM AI-aware.

CategoryBuilt-InPurpose
SIEMWazuhSecurity context, vulnerability data, agent status
NetworkUniFiDevice discovery, networks, firewall rules
Data StoreElasticsearchDevice and alert indexing, search, aggregations
TicketingZammadIncident ticket creation and management
AIOllamaAlert analysis, executive summaries, NL queries
NotificationsSlack + ntfyMulti-channel alert delivery

Additional adapters available for Splunk, Meraki, FortiGate, Cisco ISE, Jira, AbuseIPDB, and MISP.

Who It's For

From AI governance teams to defense contractors.

AI Governance & Risk Teams

Employees adopt new AI tools weekly. Faron shows you which AI services are actually in use across the network — the visibility you need to write, enforce, and prove an AI-usage policy.

Managed Service Providers

Multi-tenant architecture lets you monitor all client environments from a single deployment. Per-tenant dashboards, API keys, rate limits, and white-label reporting.

Defense Contractors (CMMC)

Continuous monitoring is a CMMC Level 2 requirement. Faron provides audit trails, access logging, vulnerability tracking, and compliance posture reporting your assessor needs.

Healthcare & Regulated Industries

HIPAA requires monitoring of systems containing ePHI. SOC 2 and NIST CSF compliance frameworks built in. Automated evidence collection reduces audit prep from weeks to hours.

Built With

Open-source foundations. Enterprise-grade results.

Zeek
Network Sensor
Wazuh
SIEM / XDR
Grafana
Dashboards
Prometheus
Metrics
Elasticsearch
Search / Index
Ollama
AI Engine
n8n
SOAR Playbooks
Cloudflare
Tunnels / CDN

Is Faron Right for You?

✓ When to use Faron

  • If
    you need to know which AI services employees and apps are actually usingFaron reveals shadow AI from passive traffic — the visibility to write and enforce AI policy
  • If
    you have multiple security tools generating alerts with no unified viewFaron aggregates and scores risk across your entire stack
  • If
    you need compliance reporting mapped to specific frameworksbuilt-in mapping to NIST CSF, CIS v8, SOC 2, and CMMC
  • If
    you require self-hosted security infrastructuredeploy on your own servers with full data sovereignty

✗ When not to

  • If
    you need to read the contents of AI prompts or payloadspassive detection cannot see payloads — that requires a TLS-inspecting proxy or endpoint agent
  • If
    you need a fully managed SOC with 24/7 human analystsFaron is a platform, not a managed service — though it integrates with MDR providers
  • If
    you only need basic antivirus and firewall managementan endpoint protection platform may be a better starting point

See what you couldn't see.

We'll run a 24-hour shadow-AI POC on your network and walk you through a live demo on our own infrastructure — the same system we trust to protect our business.

Frequently Asked Questions

Privacy Settings

We use cookies to enhance your browsing experience, provide personalized content, and analyze our traffic. We respect your privacy and will never sell your data. Read our privacy policy