Agent Framework Plugin Install from Untrusted Package Index
This rule detects the installation of common AI agent and orchestration frameworks (e.g., LangChain, AutoGen, CrewAI) using command-line package managers (pip, npm, conda) that point to non-standard or unverified package indexes. This behavior is a common indicator of a potential software supply-chain compromise, where an adversary attempts to inject malicious code by forcing the installation of packages from an attacker-controlled source.
Microsoft Sentinel (KQL)

