AML.T0133 AI Agent Runtime Capability Discovery

Detects anomalous discovery behavior originating from known AI agent and development tools (e.g., Claude, Cursor, Aider). The rule monitors for a rapid sequence of commands spanning multiple categories of enumeration (Network, File/Directory, Software, and System) within a short timeframe, which indicates an attempt to map the runtime environment, permissions, or system capabilities.