IMDS Credential Theft: curl/wget/python/PowerShell Accessing 169.254.169.254

Detects processes attempting to connect to the Cloud Instance Metadata Service (IMDS) IP address (169.254.169.254) or referencing it in the command line. This behavior is often associated with credential theft or reconnaissance on cloud instances.