Plugin4Shell: SHA-pinned git checkout swapped via branch-name collision
Detects instances where AI coding assistants or tools (e.g., Claude, Copilot, Gemini) invoke git.exe to clone or fetch repositories from non-standard (non-GitHub) hosts, followed by a checkout operation within a short timeframe. This behavior may indicate an attacker using automated tools to stage or exfiltrate sensitive code repositories to unauthorized infrastructure.
Microsoft Sentinel (KQL)

