Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

4 detections

Detects the macOS security CLI dumping the Claude Code OAuth credential item from Keychain (find-generic-password -w targeting 'Claude Code-credentials') by a process other than Claude Code itself, indicating credential theft targeting the coding agent's stored token.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
7012
Detects a decrypted Keychain dump (security dump-keychain -d) spawned from a Cursor/coding-agent process with output filtered for Linear, MCP, or OAuth-related strings, indicating targeted credential theft of MCP/Linear integration tokens.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
005
Detects a decrypted Keychain dump (security dump-keychain -d) spawned from a Cursor/coding-agent process with output filtered for Linear, MCP, or OAuth-related strings, indicating targeted credential theft of MCP/Linear integration tokens.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103
Detects the macOS security CLI dumping the Claude Code OAuth credential item from Keychain (find-generic-password -w targeting 'Claude Code-credentials') by a process other than Claude Code itself, indicating credential theft targeting the coding agent's stored token.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
103