AI Agent Process Sending Data to Non-Allowlisted External API
Detects network connection attempts by known AI agent or development-related runtime processes (python, node, etc.) to external endpoints that are not contained within a defined allowlist of LLM and infrastructure providers. This is intended to identify potential data exfiltration or unauthorized command and control communication originating from LLM-powered applications.
Microsoft Sentinel (KQL)

