Process Discovery via pgrep for Tunnel/Service Processes
Detects pgrep searching for ngrok, cloudflared, or wireguard-go process names from within a Claude Code shell-snapshot session, indicating discovery of tunnel/VPN tooling as part of an agent-driven attack chain.
Sigma

