• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Outbound TLS to Bitbucket from Internal AI Coding Agent Hosts

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 21 days ago•0•0•5

    Detects outbound network traffic directed to Bitbucket (via TLS/443) or using the git protocol (via port 9418). Such connections from internal systems to unverified or unauthorized external Git repositories may indicate malicious activity, including the potential installation of malicious plugins or code via supply chain compromises (e.g., Plugin4Shell).

    Suricata

    Tags

    T1195.002 - Compromise Software Supply ChainT1071.001 - Web ProtocolsNetwork Connection OutboundIDS IPS AlertNetwork GenericSuricata IDSSnort IDSTlsPolicy Violation

    Found in

    • Plugin4Shell: AI Coding Agent Supply Chain VulnerabilityLast updated 21 days ago
    • Plugin4Shell: AI Coding Agent Supply Chain VulnerabilityLast updated 21 days ago
    • Plugin4Shell: AI Coding Agent Supply Chain VulnerabilityLast updated 21 days ago
    • Plugin4Shell: AI Coding Agent Supply Chain VulnerabilityLast updated 21 days ago
    • Plugin4Shell: AI Coding Agent Supply Chain VulnerabilityLast updated 21 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?