Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
3 detections
Filters
Last updated
All Time
Detection languages
1
1
1
Contributors
3
Categories
3
3
3
Platforms
3
Products / Services
10,421
9,526
6,520
4,406
3,688
MITRE Techniques
3
3
Detects pgrep enumerating ngrok, cloudflared, or ssh processes from within a Claude Code or Cursor coding-agent session, indicating discovery of existing tunnel/remote-access tooling as part of an agent-driven attack chain.
Detects pgrep enumerating ngrok, cloudflared, or ssh processes from within a Claude Code or Cursor coding-agent session, indicating discovery of existing tunnel/remote-access tooling as part of an agent-driven attack chain.
Detects pgrep enumerating ngrok, cloudflared, or ssh processes from within a Claude Code or Cursor coding-agent session, indicating discovery of existing tunnel/remote-access tooling as part of an agent-driven attack chain.
