Cloud IMDS Credential Theft and Exfiltration

Detects processes attempting to query the Cloud Instance Metadata Service (IMDS) endpoint (169.254.169.254) that are not recognized as legitimate cloud agent software (such as AWS, Azure, or Google cloud agents). This behavior is often indicative of SSRF or unauthorized discovery attempts by an adversary on a compromised cloud instance.