Untrusted process contacted LLM API
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Resource Development (TA0042)
ATT&CK Technique
Obtain Capabilities: Artificial Intelligence (T1588.007)
Severity
Informational
Description
An untrusted process contacted an LLM API.
Attacker's Goals
Adversaries may use LLM APIs to create malicious payload dynamically. Each payload will be slightly different making detection more complex.
Investigative actions
Investigate the process that contacted the LLM API.
Check if this LLM API access is legitimate and expected.
Analyze the data potentially sent to the LLM service.
Variations
PreviousUnsigned process injecting into a Windows system binary with no command line
NextUnusual access to Microsoft 365 storage services
Was this helpful?
