AI inventory

Hugging Face

SIEM · Splunk (demo) Hugging Face · Model hub · fixture host cdn-lfs-us-1.huggingface.co

Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Finding · Open
Risk score
31
Medium
People
1
Usernames from the logs
Uploaded
1 MB
2.0 GB downloaded · 30 days
Events
60
1 source address
siemfixturecorroborated
Next steps

Recommended actions

  1. 01Splunk (demo) confirms what Microsoft 365 signals show for Hugging Face. Use the source list here to find the exact devices and network segments involved.
Splunk (demo) · fixture

What the logs show

Hosts
HostEventsUploaded
cdn-lfs-us-1.huggingface.co601 MB
Top sources
10.20.6.860
Same app, other lanes

Related findings

Who

People

Identifiers come from device telemetry and proxy logs, so they may be account names rather than full directory entries.

PersonDepartmentSourceSign-ins · 30 dGranted
n/aSIEM logs0No direct grant
Why

Evidence

  1. siem_traffic · Sep 8, 2026
    Splunk (demo): 60 events to cdn-lfs-us-1.huggingface.co from 1 user and 1 source in 30 days, 1 MB uploaded
    Detail
    {
      "hosts": [
        {
          "host": "cdn-lfs-us-1.huggingface.co",
          "events": 60,
          "bytesOut": 1048576
        }
      ],
      "bytesIn": 2147483647,
      "bytesOut": 1048576,
      "topUsers": [
        {
          "user": "[email protected]",
          "events": 60
        }
      ],
      "topSources": [
        {
          "events": 60,
          "source": "10.20.6.8"
        }
      ]
    }
  2. corroboration
    Also found by another lane (mde:huggingface)
    Detail
    {
      "findingKey": "mde:huggingface"
    }