Unusual Process Communicating with Generative AI API Endpoints

This rule detects potentially suspicious outbound network connections or DNS queries to known Generative AI service domains (OpenAI, Anthropic, Google, Mistral, Cohere) from non-browser and non-developer processes. It also triggers on suspicious Windows binaries (e.g., PowerShell, bitsadmin, mshta) initiating external connections to these domains or other destinations over port 443, helping identify potential data exfiltration or automated abuse of LLM APIs.