Non-browser process calling OpenAI Assistants API (SesameOp-style C2)
Detects outbound network requests to OpenAI Assistants API endpoints (threads, assistants, runs) that do not originate from common web browsers. This activity may indicate malicious usage of AI services, such as command and control communication via AI agents or automated exfiltration scripts, as opposed to legitimate user-initiated browsing.
Sigma

