BeyondTrust CVE-2026-1731 - Unauthenticated POST to Privileged Remote Access API Endpoint

This rule detects potential exploitation attempts targeting the BeyondTrust Privileged Remote Access API by identifying unauthenticated POST requests directed at specific sensitive API endpoints (e.g., /api/, /remote-support/). It flags high-frequency or multi-path request patterns indicative of automated vulnerability scanning or exploitation attempts related to CVE-2026-1731, where the absence of authorization headers is a key indicator of unauthorized access.