Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
2 detections
Filters
Last updated
All Time
Detection languages
1
1
Contributors
2
Categories
2
2
Platforms
2
Products / Services
10,421
9,526
6,520
4,406
3,688
MITRE Techniques
2
2
Detects a decrypted Keychain dump (security dump-keychain -d) spawned from a Cursor/coding-agent process with output filtered for Linear, MCP, or OAuth-related strings, indicating targeted credential theft of MCP/Linear integration tokens.
Detects a decrypted Keychain dump (security dump-keychain -d) spawned from a Cursor/coding-agent process with output filtered for Linear, MCP, or OAuth-related strings, indicating targeted credential theft of MCP/Linear integration tokens.
