Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

5 detections

Detects pgrep enumerating ngrok, cloudflared, or ssh processes from within a Claude Code or Cursor coding-agent session, indicating discovery of existing tunnel/remote-access tooling as part of an agent-driven attack chain.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
4010
Detects pgrep enumerating ngrok, cloudflared, or ssh processes from within a Claude Code or Cursor coding-agent session, indicating discovery of existing tunnel/remote-access tooling as part of an agent-driven attack chain.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
006
Detects pgrep searching for ngrok, cloudflared, or wireguard-go process names from within a Claude Code shell-snapshot session, indicating discovery of tunnel/VPN tooling as part of an agent-driven attack chain.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
105
Detects pgrep searching for ngrok, cloudflared, or wireguard-go process names from within a Claude Code shell-snapshot session, indicating discovery of tunnel/VPN tooling as part of an agent-driven attack chain.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects pgrep enumerating ngrok, cloudflared, or ssh processes from within a Claude Code or Cursor coding-agent session, indicating discovery of existing tunnel/remote-access tooling as part of an agent-driven attack chain.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
403