Anomalous GPU compute provisioning by identity with no ML history (LLMjacking)
Detects instances where an identity with no prior compute-provisioning history in the last 14 days successfully provisions high-performance GPU-enabled virtual machines in Azure. This behavior is indicative of potential resource hijacking, such as LLMjacking, where compromised identities are leveraged to deploy infrastructure for unauthorized resource-intensive workloads.
Microsoft Sentinel (KQL)

