AI-PAM Engine

AI-PAM: Autonomous ML & Multi-Agent Security

IsolationForest anomaly detection and Model Context Protocol agent governance — the engine that keeps every privileged action, human or autonomous, inside mathematically verified boundaries.

OmniPriv AI-PAM & ML Architecture

Autonomous ML Engine & Multi-Agent AI Security

From real-time IsolationForest anomaly detection to Model Context Protocol (MCP) agent scoping, OmniPriv ensures autonomous AI agents and human administrators operate with mathematically verified, least-privilege boundaries.

ISOLATIONFOREST ENGINE

Behavioral Anomaly Detection

Evaluates 39 features with RobustScaler normalization. Scores every closed session 0–1 with tiered escalation: Dashboard Alert → Admin Alert → Auto-Block.

REAL-TIME SWEEPER

10s Auto-Block Sweeper

Runs an autonomous 10-second live sweep across active sessions. Isolates verified offenders with grace period before force-close, while superadmins remain immune.

AUTONOMOUS PIPELINE

Auto-Retraining Pipeline

Self-training triggers automatically after 300 new analyses per organization. Warm-starts the model, creates .bak backup, and swaps model_bundle.pkl live.

MODEL EVALUATION TOOL

export_eval.py Engine

Performs 80/20 train/test split, threshold sweep optimization, feature separation analysis, and outputs comprehensive Excel workbooks for audit and tuning.

Live Rule Lanes

Real-Time In-Session Threat Detection Lanes

Live command detector scans typed commands as they happen. Live script scanner flags executed scripts (.sh, .ps1, .bat) with offender-only quarantine.

6 DETECTION LANES ACTIVE
Authentication LaneHIGH RISK

Brute Force

Rapid failed-login patterns across protocol gateways → real-time scoring + instant socket kill.

Action:Instant IP + User Auto-Block
Pivot & ReconnaissanceCRITICAL

Lateral Movement

Pivot commands (sshpass, wmiexec, crackmapexec, impacket) + behavioral network pivot indicators.

Action:10s Sweeper Isolation & Alert
Persistence DetectionCRITICAL

Backdoor Accounts

Backdoor command indicators, rogue user script authoring, and backdoor risk assessments per identity.

Action:Account Lockout & Admin Alert
Secret ExtractionCRITICAL

Credential Harvesting

Credential-grabbing commands (mimikatz, dump, sam, lsass queries) and harvesting risk scoring.

Action:Process Killed & Session Severed
Behavioral ContextELEVATED

Login-from-Nowhere / Off-Hours

Impossible travel geolocation, unusual source IPs, and hour deviation from the user's learned baseline.

Action:Step-Up Auth / Quarantine
In-Session ScannerHIGH RISK

Script Execution Abuse

Executed script files (.sh, .ps1, .bat) scanned live in-flight; malicious payloads flagged instantly.

Action:Live Script Blocked

See the engine on your own infrastructure

We will walk through live anomaly scoring, MCP agent scoping and the 10-second auto-block sweeper against your environment.