AI Agent Beaconing to Unrecognized C2 Infrastructure

Detects periodic, repetitive outbound HTTPS network connections from AI agent-runtime environments to domains that are not in the predefined allow-list. This behavior is consistent with C2 beaconing disguised as application API traffic, potentially indicating an AI agent has been compromised or misused for unauthorized external command communication.