AI/LLM CLI Tool Execution via Suspicious Parent or Writable Path
Detects the execution of known AI/LLM command-line interface tools (such as Ollama, OpenAI, or Claude) when spawned by command shells (cmd.exe, powershell.exe) or executed from suspicious locations like user profiles or temporary directories. This pattern is indicative of potential use of LLMs for generating malicious code, analyzing data, or assisting in post-exploitation activities within a compromised environment.
SentinelOne

