Agentic AI-Orchestrated Attack: LLM API Calls + Enumeration + Lateral Movement
This rule detects scenarios where common administrative or attack tools (e.g., whoami, net, ipconfig, psexec) are used within the same 5-minute window as network communication to known Large Language Model (LLM) service providers. This pattern may indicate an attacker using LLMs to assist with post-exploitation discovery, script generation, or data analysis based on local system reconnaissance.
Splunk (SPL)

