AML.T0132 Exposed AI/MCP Service Exploitation Chain

Detects a sequence of potentially malicious activity targeting LLM-related API endpoints. The rule identifies a client IP performing rapid, distinct endpoint discovery, followed by a POST request to sensitive paths, and concluding with a spike in 5xx server-side errors, indicating potential exploitation attempts or fuzzing against Large Language Model interfaces.