LLM-Weaponized Recon: Non-Dev Process Outbound HTTPS to AI APIs

This rule detects potentially unauthorized or suspicious outbound network connections to common Generative AI service APIs (OpenAI, Anthropic, Mistral) originating from command-line interpreters (cmd.exe, powershell.exe) or python.exe instances running from temporary directories, which could indicate data exfiltration or the use of AI tools for malicious automation.