Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
10 detections
Filters
Last updated
All Time
Detection languages
4
4
1
1
Contributors
10
Categories
9
8
5
2
Platforms
10
Products / Services
10,421
9,526
6,520
4,406
3,688
MITRE Techniques
6
5
2
2
2
Detects pgrep enumerating ngrok, cloudflared, or ssh processes from within a Claude Code or Cursor coding-agent session, indicating discovery of existing tunnel/remote-access tooling as part of an agent-driven attack chain.
Detects curl POSTing hardcoded username/password-style credentials to a /login endpoint on a known tunnel domain (ngrok, Cloudflare Quick Tunnel, or localhost.run), indicating credential submission to an attacker-exposed tunnel endpoint.
Detects execution of a generically-named a.out binary from a non-standard path (/tmp or Downloads) or any command line referencing ngrok, indicating an ngrok reverse-tunnel binary disguised under a default compiler output name.
Detects pgrep enumerating ngrok, cloudflared, or ssh processes from within a Claude Code or Cursor coding-agent session, indicating discovery of existing tunnel/remote-access tooling as part of an agent-driven attack chain.
Detects execution of a generically-named a.out binary from a non-standard path (/tmp or Downloads) or any command line referencing ngrok, indicating an ngrok reverse-tunnel binary disguised under a default compiler output name.
Detects curl POSTing hardcoded username/password-style credentials to a /login endpoint on a known tunnel domain (ngrok, Cloudflare Quick Tunnel, or localhost.run), indicating credential submission to an attacker-exposed tunnel endpoint.
Detects pgrep searching for ngrok, cloudflared, or wireguard-go process names from within a Claude Code shell-snapshot session, indicating discovery of tunnel/VPN tooling as part of an agent-driven attack chain.
Detects the malicious signed 64-bit ARM Mach-O ngrok binary distributed as a.out, flagged by multiple AV engines as adware/hacktool ngrok
Detects pgrep searching for ngrok, cloudflared, or wireguard-go process names from within a Claude Code shell-snapshot session, indicating discovery of tunnel/VPN tooling as part of an agent-driven attack chain.
Detects pgrep enumerating ngrok, cloudflared, or ssh processes from within a Claude Code or Cursor coding-agent session, indicating discovery of existing tunnel/remote-access tooling as part of an agent-driven attack chain.
