Agentic AI/RPA Runtime Executing Privileged Account/Firewall Actions
Detects the execution of high-privilege administrative, firewall, or file-system commands by processes identified as autonomous agent runtimes (e.g., LangChain, AutoGPT) or Robotic Process Automation (RPA) tools. This rule surfaces potential unauthorized infrastructure changes or automated abuse by agents when direct change management validation is absent.
Microsoft Sentinel (KQL)

