Coding-Agent CLI Spawns Discovery/Credential-Access Command After Reading Skill/Preflight File
Detects instances where AI coding assistants (e.g., Cursor, Claude, Copilot) are observed interacting with specific configuration or sensitive files and subsequently initiating suspicious shell commands. The rule correlates file read activity (containing keywords like 'skill', 'preflight', '.ssh', or '.aws') followed closely by execution of potentially malicious commands like 'whoami /priv', credential decoding, or registry exploration, indicating potential abuse of the assistant's context.
Microsoft Sentinel (KQL)

