Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

3 detections

Detects pgrep searching for ngrok, cloudflared, or wireguard-go process names from within a Claude Code shell-snapshot session, indicating discovery of tunnel/VPN tooling as part of an agent-driven attack chain.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
105
Detects pgrep searching for ngrok, cloudflared, or wireguard-go process names from within a Claude Code shell-snapshot session, indicating discovery of tunnel/VPN tooling as part of an agent-driven attack chain.
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
003
Detects presence of pritunl-client or wireguard-go binary/name strings, tunnel/VPN-class tooling observed landing on host prior to agent-parented tunnel activity
avatar
Duo Tech@duotech
avatar
Detections.ai Community
2 months ago
101