Detect non-whitelisted processes making outbound HTTPS connections to known AI/LLM API endpoints
Detects outbound network connections to major Large Language Model (LLM) API endpoints (OpenAI, Google, Anthropic) initiated by processes not explicitly identified as standard web browsers or command-line utilities. This pattern may indicate automated data exfiltration ('prompt stealing' or unauthorized access to corporate data) using custom or malicious tools executing from suspicious directories like temp, appdata, or public folders.
Microsoft Sentinel (KQL)

