AI Series: Most Significant TTP – Claude Code / Agentic CLI Recon-to-Exfiltratio

Detects a chained sequence of suspicious activity initiated by agentic AI development tools (e.g., Claude Code, Aider, AutoGen). The rule identifies the execution of these tools followed by local reconnaissance commands, lateral movement attempts, and outbound network connections originating from the same host, indicating potential automated exploitation or credential abuse.