AI API key brute-forcing via repeated 401s on LLM endpoints
This rule detects high-frequency HTTP 401 Unauthorized responses directed at API endpoints (specifically matching '/v1/') within a short window, which is indicative of an adversary attempting to brute-force or credential-stuff API keys.
Suricata

