AI Agent Attack-Path Adaptation — Rapid Multi-Service Pivoting

Detects autonomous behavior where AI-driven processes attempt multiple network connections (SMB, SSH, HTTP, RDP, WinRM) to diverse targets following failed access attempts. The rule correlates initial failure activity with subsequent credential-related events and new lateral movement traffic from the same agent process within a short window, suggesting adaptive adversary pivoting.