Excessive Direct API Calls to OpenAI/xAI Endpoints (Denial of Wallet)
Detects high-frequency outbound network connections to known large language model (LLM) API providers (OpenAI, xAI, Anthropic) originating from a single endpoint within a short timeframe. This activity is indicative of potential API key theft, where an attacker uses a compromised legitimate key to exhaust credit quotas or exfiltrate data via unauthorized API calls, bypassing the intended application.
Microsoft Sentinel (KQL)

