Non-Browser Process Querying Threat Intelligence APIs

Detects DNS resolutions to popular threat intelligence, reputation, and sandboxing APIs (e.g., VirusTotal, URLScan, AbuseIPDB) originating from non-browser processes on non-analyst workstations. This behavior may indicate an attacker programmatically querying these services to verify if their infrastructure, payloads, or IP addresses are flagged as malicious, or to conduct reconnaissance.