Most Popular Detection 2026 – AI Agent Sandbox Escape via Malicious Batch Script Persistence

Detects the creation or modification of script files (bat, ps1, vbs, cmd) within the Windows Startup folder initiated by processes commonly associated with AI agents or developer frameworks (e.g., dotnet, python, w3wp). This activity indicates an AI agent environment being exploited to establish persistence, potentially facilitating delayed remote code execution upon user logon.