Most Critical Detection 2026 – Post-Exploitation Child Process Spawn from AI Agent Host (Semantic Kernel)
This rule detects potentially malicious child processes spawned by processes associated with Microsoft Semantic Kernel agents. These agents may be exploited to execute administrative tools, living-off-the-land binaries (LOLBins), or networking utilities commonly used in post-exploitation activities, such as credential dumping, discovery, or command execution.
Microsoft Sentinel (KQL)

