Skip to content

Add AI platform providers with an ai tag #302

Description

@liquidsec

Add AI platforms as providers, tagged ai, so that hosts running on AI infrastructure get detected the same way cloud, CDN and WAF hosts are today.

Why: an in-scope hostname that CNAMEs to an AI platform (for example support-bot.example.com pointing at a hosted Dify or Flowise tenant) is a useful signal, especially for finding AI deployments that aren't in an organization's inventory. BBOT's cloudcheck module already checks every event's host, CNAME chain and resolved IPs against this library's catalog and tags the in-scope event with the provider name and tags. So adding the providers here is all it takes for BBOT to pick this up, with no separate module or domain list. This came up in blacklanternsecurity/bbot#3440.

What's needed:

  • A new ai tag, alongside cloud, cdn, waf, gov and security.
  • Provider classes for platforms that host customer-facing apps or endpoints, since those are what a target's DNS would point at. Candidates to research:
    • agent and LLM app builders with hosted tenants: Dify, Flowise, Langflow, n8n;
    • model hosting and inference: Hugging Face (Spaces), Replicate, Modal, Baseten, RunPod, Together AI, Fireworks AI, Groq;
    • hyperscaler AI endpoints: Azure OpenAI (openai.azure.com) and similar.

For each one, the work is finding the domains customers actually CNAME to, and CIDRs/ASNs where the platform publishes them. Consumer AI products (chat assistants, coding assistants and so on) are out of scope, since a target's own DNS doesn't point at them.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions