Non-Browser Process Polling LLM API Endpoint (SesameOp-style C2)

Detects non-browser and non-approved application processes establishing outbound network connections to known public LLM/AI API endpoints, such as OpenAI or Azure OpenAI services. This behavior is indicative of potential command-and-control (C2) activity where an attacker abuses legitimate AI APIs as a bidirectional communication channel to poll for instructions.