Edit

Explore risks to pre-deployment generative AI artifacts

The Defender Cloud Security Posture Management (CSPM) plan in Microsoft Defender for Cloud helps you secure your generative AI apps. It scans AI artifacts, such as container images and code repositories, to find known vulnerabilities in AI libraries.

In this article, you use the cloud security explorer in Defender for Cloud to find containers running vulnerable generative AI images and to identify vulnerable code repositories that provision Azure OpenAI. After you complete these steps, you can review findings and remediate recommendations.

Prerequisites

Before you begin, make sure you meet the following prerequisites:

Identify containers running on vulnerable generative AI container images

Use the cloud security explorer to find containers that run generative AI images with known vulnerabilities.

  1. Sign in to the Azure portal.

  2. Search for and select Microsoft Defender for Cloud > Cloud Security Explorer.

  3. Select the Container running container images with known Generative AI vulnerabilities query template.

    Screenshot that shows where to locate the generative AI vulnerable container images query.

  4. Select Search.

  5. Select a result to review its details.

    Screenshot that shows a sample of results for the vulnerable image query.

  6. Select a node to review the findings.

    Screenshot that shows the details of the selected containers node.

  7. In the insights section, select a CVE ID from the drop-down menu.

  8. Select Open the vulnerability page.

  9. Remediate the recommendation.

Identify vulnerable generative AI code repositories

Use the cloud security explorer to find vulnerable generative AI code repositories that provision Azure OpenAI.

  1. Sign in to the Azure portal.

  2. Search for and select Microsoft Defender for Cloud > Cloud Security Explorer.

  3. Select the Generative AI vulnerable code repositories that provision Azure OpenAI query template.

    Screenshot that shows where to locate the generative AI vulnerable code repositories query.

  4. Select Search.

  5. Select a result to review its details.

    Screenshot that shows a sample of results for the vulnerable code query.

  6. Select a node to review the findings.

    Screenshot that shows the details of the selected vulnerable code node.

  7. In the insights section, select a CVE ID from the drop-down menu.

  8. Select Open the vulnerability page.

  9. Remediate the recommendation.