Execution of zsh Shell-Snapshot Scripts from GenAI Coding Agent
This rule detects potentially malicious command execution initiated within Claude Code's zsh shell-snapshot environment on macOS. It triggers when a zsh process executes a command via the internal shell-snapshot wrapper and subsequently performs high-risk activities such as credentialized HTTP requests, unauthorized data exfiltration/upload, download-and-execute shell chains, tunneling (e.g., ngrok, cloudflared, SSH port forwarding), persistence mechanism manipulation (e.g., LaunchAgents/LaunchDaemons, PlistBuddy), credential access (e.g., keychain queries), or defense evasion techniques (e.g., clearing quarantine attributes or ad-hoc codesigning).
Cortex XDR

