Add AI platforms as providers, tagged ai, so that hosts running on AI infrastructure get detected the same way cloud, CDN and WAF hosts are today.
Why: an in-scope hostname that CNAMEs to an AI platform (for example support-bot.example.com pointing at a hosted Dify or Flowise tenant) is a useful signal, especially for finding AI deployments that aren't in an organization's inventory. BBOT's cloudcheck module already checks every event's host, CNAME chain and resolved IPs against this library's catalog and tags the in-scope event with the provider name and tags. So adding the providers here is all it takes for BBOT to pick this up, with no separate module or domain list. This came up in blacklanternsecurity/bbot#3440.
What's needed:
- A new
ai tag, alongside cloud, cdn, waf, gov and security.
- Provider classes for platforms that host customer-facing apps or endpoints, since those are what a target's DNS would point at. Candidates to research:
- agent and LLM app builders with hosted tenants: Dify, Flowise, Langflow, n8n;
- model hosting and inference: Hugging Face (Spaces), Replicate, Modal, Baseten, RunPod, Together AI, Fireworks AI, Groq;
- hyperscaler AI endpoints: Azure OpenAI (
openai.azure.com) and similar.
For each one, the work is finding the domains customers actually CNAME to, and CIDRs/ASNs where the platform publishes them. Consumer AI products (chat assistants, coding assistants and so on) are out of scope, since a target's own DNS doesn't point at them.
Add AI platforms as providers, tagged
ai, so that hosts running on AI infrastructure get detected the same way cloud, CDN and WAF hosts are today.Why: an in-scope hostname that CNAMEs to an AI platform (for example
support-bot.example.compointing at a hosted Dify or Flowise tenant) is a useful signal, especially for finding AI deployments that aren't in an organization's inventory. BBOT'scloudcheckmodule already checks every event's host, CNAME chain and resolved IPs against this library's catalog and tags the in-scope event with the provider name and tags. So adding the providers here is all it takes for BBOT to pick this up, with no separate module or domain list. This came up in blacklanternsecurity/bbot#3440.What's needed:
aitag, alongsidecloud,cdn,waf,govandsecurity.openai.azure.com) and similar.For each one, the work is finding the domains customers actually CNAME to, and CIDRs/ASNs where the platform publishes them. Consumer AI products (chat assistants, coding assistants and so on) are out of scope, since a target's own DNS doesn't point at them.