Agent Browser-Automation Tool Navigating to TI-Flagged Malicious Domains

This rule detects automated browser-based processes (such as chromedriver, msedgedriver, geckodriver, playwright, or node/python scripts leveraging browser automation frameworks) initiating network connections to domains or URLs identified in active threat intelligence as malicious. This behavior is indicative of an AI agent or automated script being steered toward attacker-controlled infrastructure, potentially for drive-by compromise or exploitation.