AIQSO Faron · formerly Network Sentinel
Bring your shadow AI into the light.
Faron reveals every AI service on your network — agentlessly, from passive traffic alone. No endpoint. No interception. See what you couldn't see, in hours.
Agentless · Passive · No Endpoint · Self-Hosted
Key Takeaways
- •Agentless shadow-AI detection — see which AI services are in use across your network in hours, nothing to install
- •Honest by design: Faron detects communication with AI services, never claims to read prompts or payloads from passive traffic
- •Unified risk scoring across your entire security stack — not siloed alerts from separate tools
- •Self-hosted deployment means your data never leaves your infrastructure
- •Maps to compliance frameworks including NIST CSF, CIS Controls v8, SOC 2, and CMMC
Four passive signals. Zero agents.
Faron answers is AI being used, which service, and which host — from traffic your network already carries.
DNS Queries
Lookups to AI providers — api.openai.com, claude.ai, gemini.google.com — reveal which hosts are reaching which AI services, before a single byte of content is exchanged.
TLS SNI
The server name in the ClientHello is still sent in the clear for most traffic. Faron reads it to attribute encrypted sessions to a specific AI service — without ever decrypting them.
JA3 / JA4 Fingerprints
TLS client fingerprints separate an SDK client (httpx, requests) from a browser — telling apart "an app making API calls" from "an employee chatting in a browser."
Traffic Shape
Streaming LLM responses have a tell-tale flow — a small request up, a long-lived token-trickle down. Faron classifies that pattern from flow metadata alone.
The dashboard, not a mockup
Captured from the live Faron deployment monitoring our own network — the same system we demo. Device addresses relabeled.


Honest about what we can — and can't — see
Security-literate buyers trust a tool that names its blind spots. This section is the product argument, not the fine print.
| Signal | What it tells us | Where it ends |
|---|---|---|
| DNS queries | Which hosts resolve AI-provider domains, and how often | DNS-over-HTTPS/TLS hides queries from passive view — but Faron flags that DoH itself is in use, which is a policy signal of its own |
| TLS SNI | Which AI service an encrypted session is talking to | Encrypted Client Hello (ECH) will erode SNI over time — Faron treats ECH adoption itself as an evasion signal worth surfacing |
| JA3 / JA4 | Whether the client is an SDK, a CLI, or a browser | Fingerprints classify the client type; they do not identify the person or read the session |
| Flow metadata | Streaming-response patterns characteristic of LLM traffic | Prompts and payloads are never visible from passive traffic — reading content would require a TLS-inspecting proxy or an endpoint agent, which Faron is not |
Documented blind spots
If a vendor tells you passive monitoring reads AI prompts, ask them how. Faron doesn't claim it — because it isn't true of passive traffic.
A mirror port, a sensor, and nothing on your endpoints
Faron listens to a SPAN/mirror port or TAP through a Zeek sensor. Traffic is analyzed in place — nothing is intercepted, nothing leaves your network.
Reveal
A passive network sensor reads DNS, TLS SNI, and JA3/JA4 fingerprints to reveal which hosts are talking to which AI services, plus a device inventory synced every 5 minutes. No agent, no interception.
Assess
Vulnerability data from Wazuh feeds every 15 minutes. Firewall policies analyzed for exposure. Zeek captures network behavior baselines over rolling 7-day windows.
Score
The risk engine calculates a 0-100 score per device: Device Type (30%) + Policy Exposure (35%) + Vulnerabilities (20%) + Behavior (15%). Critical devices surface instantly.
Alert
Smart alerting with deduplication and fatigue scoring. Critical findings hit Slack and push notifications immediately. Low-priority items batch into daily digests.
Report
Automated daily, weekly, and monthly reports with AI-powered executive summaries. Compliance posture dashboards for NIST CSF, CIS v8, and SOC 2.
Risk = DT(.30) + PE(.35) + V(.20) + B(.15)Device Type + Policy Exposure + Vulnerabilities + Behavior
What Faron Does
One platform to reveal, monitor, score, detect, and respond — across your entire stack.
Agentless Shadow-AI Detection
See every AI service in use across your network from passive traffic alone — no endpoint agent, no TLS interception. The zero-friction POC that answers "who is using AI, and which service" in hours.
Unified Risk Scoring
Policy-aware risk scores combining device type, firewall exposure, CVE data, and behavioral anomalies. Know which devices need attention — ranked by actual risk, not just alert volume.
Plugin Framework
Swap integrations without changing code. Built-in adapters for Wazuh, UniFi, Elasticsearch, Zammad, Ollama, Slack, and ntfy. Write a custom plugin in ~50 lines.
Compliance Dashboards
Pre-built frameworks for NIST CSF, CIS v8, and SOC 2 Type II with weighted scoring and maturity levels. Automated evidence collection for audit readiness.
Blast Radius Analysis
1-hop and 2-hop network reachability from any device. See exactly what an attacker could reach if a device is compromised — based on your actual firewall rules.
AI-Powered Analysis
Natural language queries powered by Ollama. Ask "which IoT devices have critical vulnerabilities?" and get actionable answers. AI-generated executive summaries for leadership.
Network Traffic Analysis
Zeek sensor integration for deep flow inspection. Connection logs, DNS queries, HTTP requests, and SSL certificate analysis — with behavioral anomaly detection.
Smart Alerting
Alert deduplication, fatigue scoring, and severity-based routing. Critical alerts go to Slack and push notifications. Low-priority findings batch into daily digests.
Self-Hosted & Private
Deployed on your infrastructure. Your data never leaves your network. Full data sovereignty with multi-tenant isolation for MSPs managing multiple clients.
What We Monitor
From shadow-AI detection to compliance posture — full-stack visibility.
Shadow AI
- AI-service detection via DNS + TLS SNI
- SDK-vs-browser JA3/JA4 fingerprinting
- Streaming-response traffic-shape heuristics
- Curated AI-service intelligence feed
Devices
- Automated device discovery via UniFi/Meraki
- IoT/OT fingerprinting via MAC OUI + DHCP
- Real-time inventory sync (every 5 min)
- Device classification and risk tagging
Vulnerabilities
- CVE tracking from Wazuh feeds (every 15 min)
- Severity scoring (Critical/High/Medium/Low)
- Vulnerability-to-device mapping
- Patch status and remediation tracking
Compliance
- NIST CSF (19 controls)
- CIS v8 (10 controls)
- SOC 2 Type II (9 controls)
- CMMC-aligned continuous monitoring
Bring Your Own Tools
Six plugin categories let you swap integrations without changing core code. Faron is the sensor and intelligence layer that makes your SIEM AI-aware.
| Category | Built-In | Purpose |
|---|---|---|
| SIEM | Wazuh | Security context, vulnerability data, agent status |
| Network | UniFi | Device discovery, networks, firewall rules |
| Data Store | Elasticsearch | Device and alert indexing, search, aggregations |
| Ticketing | Zammad | Incident ticket creation and management |
| AI | Ollama | Alert analysis, executive summaries, NL queries |
| Notifications | Slack + ntfy | Multi-channel alert delivery |
Additional adapters available for Splunk, Meraki, FortiGate, Cisco ISE, Jira, AbuseIPDB, and MISP.
Who It's For
From AI governance teams to defense contractors.
AI Governance & Risk Teams
Employees adopt new AI tools weekly. Faron shows you which AI services are actually in use across the network — the visibility you need to write, enforce, and prove an AI-usage policy.
Managed Service Providers
Multi-tenant architecture lets you monitor all client environments from a single deployment. Per-tenant dashboards, API keys, rate limits, and white-label reporting.
Defense Contractors (CMMC)
Continuous monitoring is a CMMC Level 2 requirement. Faron provides audit trails, access logging, vulnerability tracking, and compliance posture reporting your assessor needs.
Healthcare & Regulated Industries
HIPAA requires monitoring of systems containing ePHI. SOC 2 and NIST CSF compliance frameworks built in. Automated evidence collection reduces audit prep from weeks to hours.
Built With
Open-source foundations. Enterprise-grade results.
Is Faron Right for You?
✓ When to use Faron
- Ifyou need to know which AI services employees and apps are actually using — Faron reveals shadow AI from passive traffic — the visibility to write and enforce AI policy
- Ifyou have multiple security tools generating alerts with no unified view — Faron aggregates and scores risk across your entire stack
- Ifyou need compliance reporting mapped to specific frameworks — built-in mapping to NIST CSF, CIS v8, SOC 2, and CMMC
- Ifyou require self-hosted security infrastructure — deploy on your own servers with full data sovereignty
✗ When not to
- Ifyou need to read the contents of AI prompts or payloads — passive detection cannot see payloads — that requires a TLS-inspecting proxy or endpoint agent
- Ifyou need a fully managed SOC with 24/7 human analysts — Faron is a platform, not a managed service — though it integrates with MDR providers
- Ifyou only need basic antivirus and firewall management — an endpoint protection platform may be a better starting point
See what you couldn't see.
We'll run a 24-hour shadow-AI POC on your network and walk you through a live demo on our own infrastructure — the same system we trust to protect our business.