AI Agent Runtime Spawning Shell/Script Interpreter (Prompt Injection)
Detects instances where common AI agent orchestration runtimes (e.g., LangChain, AutoGPT, CrewAI) spawn command-line or scripting interpreters as child processes. This behavior is highly suspicious and often indicative of malicious command execution triggered by prompt injection attacks, where an adversary manipulates the agent into executing arbitrary system commands.
Microsoft Sentinel (KQL)

