Non-Agent Process Access to Cloud Instance Metadata Endpoint

Detects unauthorized processes attempting to access the cloud instance metadata service (169.254.169.254). Adversaries frequently target this endpoint to extract sensitive instance information, such as IAM credentials or configuration data, typically as part of post-exploitation discovery or SSRF-based attacks.