Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
4 detections
Filters
Last updated
All Time
Detection languages
2
2
Contributors
4
Categories
4
4
Platforms
4
Products / Services
10,421
9,526
6,520
4,406
3,688
MITRE Techniques
4
2
Detects the macOS security CLI dumping the Claude Code OAuth credential item from Keychain (find-generic-password -w targeting 'Claude Code-credentials') by a process other than Claude Code itself, indicating credential theft targeting the coding agent's stored token.
Detects a decrypted Keychain dump (security dump-keychain -d) spawned from a Cursor/coding-agent process with output filtered for Linear, MCP, or OAuth-related strings, indicating targeted credential theft of MCP/Linear integration tokens.
Detects a decrypted Keychain dump (security dump-keychain -d) spawned from a Cursor/coding-agent process with output filtered for Linear, MCP, or OAuth-related strings, indicating targeted credential theft of MCP/Linear integration tokens.
Detects the macOS security CLI dumping the Claude Code OAuth credential item from Keychain (find-generic-password -w targeting 'Claude Code-credentials') by a process other than Claude Code itself, indicating credential theft targeting the coding agent's stored token.
