Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
7 detections
Filters
Last updated
All Time
Detection languages
3
3
1
Contributors
7
Categories
7
5
5
Platforms
7
Products / Services
10,421
9,526
6,520
4,406
3,688
MITRE Techniques
5
5
2
2
2
Detects pgrep enumerating ngrok, cloudflared, or ssh processes from within a Claude Code or Cursor coding-agent session, indicating discovery of existing tunnel/remote-access tooling as part of an agent-driven attack chain.
Detects cloudflared launched with 'tunnel --url' against localhost or api.trycloudflare.com without managed-tunnel authentication flags, indicating deployment of an ad-hoc Cloudflare Quick Tunnel exposing a local service to the internet.
Detects pgrep enumerating ngrok, cloudflared, or ssh processes from within a Claude Code or Cursor coding-agent session, indicating discovery of existing tunnel/remote-access tooling as part of an agent-driven attack chain.
Detects pgrep searching for ngrok, cloudflared, or wireguard-go process names from within a Claude Code shell-snapshot session, indicating discovery of tunnel/VPN tooling as part of an agent-driven attack chain.
Detects cloudflared launched with 'tunnel --url' against localhost or api.trycloudflare.com without managed-tunnel authentication flags, indicating deployment of an ad-hoc Cloudflare Quick Tunnel exposing a local service to the internet.
Detects pgrep searching for ngrok, cloudflared, or wireguard-go process names from within a Claude Code shell-snapshot session, indicating discovery of tunnel/VPN tooling as part of an agent-driven attack chain.
Detects pgrep enumerating ngrok, cloudflared, or ssh processes from within a Claude Code or Cursor coding-agent session, indicating discovery of existing tunnel/remote-access tooling as part of an agent-driven attack chain.
