AML.T0132 Exposed AI/MCP Service Exploitation
Detects a multi-stage attack pattern against publicly exposed AI service endpoints. The detection correlates: (1) Enumeration of sensitive AI/MCP-related API endpoints (minimum 3 distinct hits) in a 10-minute window; (2) Subsequent POST requests to AI service endpoints within 15 minutes of the enumeration; and (3) A spike of 5 or more server errors (HTTP 5xx) within 10 minutes following the POST activity. This pattern suggests automated reconnaissance followed by attempted exploitation of exposed AI model interfaces or orchestration services. Covers T1595.002, T1190
Microsoft Sentinel (KQL)

