Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
2 detections
Filters
Last updated
All Time
Detection languages
1
1
Contributors
2
Categories
2
2
2
Platforms
2
Products / Services
10,421
9,526
6,520
4,406
3,688
MITRE Techniques
2
2
2
2
2
Detects a python3 script executed from /tmp under a zsh parent with command-line indicators of network activity (URLs, sockets, requests/urllib, curl/wget, or tunnel tool names), indicating a coding-agent-staged script establishing outbound network or tunnel connections.
Detects a python3 script executed from /tmp under a zsh parent with command-line indicators of network activity (URLs, sockets, requests/urllib, curl/wget, or tunnel tool names), indicating a coding-agent-staged script establishing outbound network or tunnel connections.
