MITRE ATLAS Mapped 2026 Top AI API Access Detection – Unauthorized AI Model Inference API Access (AML.T0040)
Detects suspicious AI inference API activity indicative of credential compromise or misuse. The rule identifies three main signals: rapid authentication failures (credential stuffing), anomalous geolocation/ASN usage for successful requests, and successful API calls occurring after a key rotation event.
YARA-L

