AI Coding-Assistant Plugin Exfiltrating Credential-Like Content
Detects the transmission of sensitive credential-like patterns (such as API keys, private keys, and connection strings) to known external AI coding assistant and IDE plugin endpoints. This rule monitors cloud application events originating from developer workstations or CI/CD runners where such sensitive information may be inadvertently or maliciously sent to third-party AI services.
Microsoft Sentinel (KQL)

