Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

5 detections

Detects a shell spawned by Claude.app or Cursor.app with the --allow-dangerously-skip-permissions flag, indicating the coding agent's safety/permission prompts have been bypassed, widening the blast radius of subsequent agent-driven commands.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
8115
Detects a shell spawned by Claude.app or Cursor.app with the --allow-dangerously-skip-permissions flag, indicating the coding agent's safety/permission prompts have been bypassed, widening the blast radius of subsequent agent-driven commands.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
107
Detects a decrypted Keychain dump (security dump-keychain -d) spawned from a Cursor/coding-agent process with output filtered for Linear, MCP, or OAuth-related strings, indicating targeted credential theft of MCP/Linear integration tokens.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects a shell spawned by Claude.app or Cursor.app with the --allow-dangerously-skip-permissions flag, indicating the coding agent's safety/permission prompts have been bypassed, widening the blast radius of subsequent agent-driven commands.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
505
Detects a decrypted Keychain dump (security dump-keychain -d) spawned from a Cursor/coding-agent process with output filtered for Linear, MCP, or OAuth-related strings, indicating targeted credential theft of MCP/Linear integration tokens.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103