Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
5 detections
Filters
Last updated
All Time
Detection languages
2
2
1
Contributors
5
Categories
5
3
3
2
Platforms
5
Products / Services
10,421
9,526
6,520
4,406
3,688
MITRE Techniques
3
3
3
2
2
Detects a shell spawned by Claude.app or Cursor.app with the --allow-dangerously-skip-permissions flag, indicating the coding agent's safety/permission prompts have been bypassed, widening the blast radius of subsequent agent-driven commands.
Detects a shell spawned by Claude.app or Cursor.app with the --allow-dangerously-skip-permissions flag, indicating the coding agent's safety/permission prompts have been bypassed, widening the blast radius of subsequent agent-driven commands.
Detects a decrypted Keychain dump (security dump-keychain -d) spawned from a Cursor/coding-agent process with output filtered for Linear, MCP, or OAuth-related strings, indicating targeted credential theft of MCP/Linear integration tokens.
Detects a shell spawned by Claude.app or Cursor.app with the --allow-dangerously-skip-permissions flag, indicating the coding agent's safety/permission prompts have been bypassed, widening the blast radius of subsequent agent-driven commands.
Detects a decrypted Keychain dump (security dump-keychain -d) spawned from a Cursor/coding-agent process with output filtered for Linear, MCP, or OAuth-related strings, indicating targeted credential theft of MCP/Linear integration tokens.
