AML.T0124 AI Agent Autonomous Recon-to-Exfil Chain

Detects an suspicious progression of activities originating from identified AI assistant/agent processes. The rule monitors for a chain of behaviors occurring within a 15-minute window: execution of an AI agent/tool, followed by host discovery (network/system enumeration), access to sensitive local credential files, archival of data, and outbound network communication to common file-sharing/exfiltration platforms.