Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

10 detections

This rule detects potentially malicious command execution initiated within Claude Code's zsh shell-snapshot environment on macOS. It triggers when a zsh process executes a command via the internal shell-snapshot wrapper and subsequently performs high-risk activities such as credentialized HTTP requests, unauthorized data exfiltration/upload, download-and-execute shell chains, tunneling (e.g., ngrok, cloudflared, SSH port forwarding), persistence mechanism manipulation (e.g., LaunchAgents/LaunchDaemons, PlistBuddy), credential access (e.g., keychain queries), or defense evasion techniques (e.g., clearing quarantine attributes or ad-hoc codesigning).
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
4026
Detects a shell spawned by Claude.app or Cursor.app with the --allow-dangerously-skip-permissions flag, indicating the coding agent's safety/permission prompts have been bypassed, widening the blast radius of subsequent agent-driven commands.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
8115
Detects the macOS security CLI dumping the Claude Code OAuth credential item from Keychain (find-generic-password -w targeting 'Claude Code-credentials') by a process other than Claude Code itself, indicating credential theft targeting the coding agent's stored token.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
7012
Detects a process other than Claude Code or a recognized backup/editor/IDE tool writing to a Claude project's durable MEMORY.md file, indicating unexpected tampering with the coding agent's persistent memory store.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
2010
Detects a process other than Claude Code or a recognized backup/editor/IDE tool writing to a Claude project's durable MEMORY.md file, indicating unexpected tampering with the coding agent's persistent memory store.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
2108
Detects a process other than Claude Code or a recognized backup/editor/IDE tool writing to a Claude project's durable MEMORY.md file, indicating unexpected tampering with the coding agent's persistent memory store.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
207
Detects a shell spawned by Claude.app or Cursor.app with the --allow-dangerously-skip-permissions flag, indicating the coding agent's safety/permission prompts have been bypassed, widening the blast radius of subsequent agent-driven commands.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
107
Detects a Claude Code shell-snapshot source invocation followed by additional chained commands (e.g. curl, jq, eval) rather than a clean startup guard, indicating anomalous use of the coding agent's session-init mechanism to smuggle in follow-on actions.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
206
Detects a shell spawned by Claude.app or Cursor.app with the --allow-dangerously-skip-permissions flag, indicating the coding agent's safety/permission prompts have been bypassed, widening the blast radius of subsequent agent-driven commands.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
505
Detects the macOS security CLI dumping the Claude Code OAuth credential item from Keychain (find-generic-password -w targeting 'Claude Code-credentials') by a process other than Claude Code itself, indicating credential theft targeting the coding agent's stored token.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103