BREAKING
AI coding agents trip EDR rules
Claude Code hits credential rule
1browse.exe
2node.exe
3PowerShell
4Creds_3b hit
Legit dev looks like an attack
AI agent intent
Fetch installers
Refactor and debug
Solve tasks by pivoting tools
EDR seesATT&CK
Credential access
LOLBins: certutil, bitsadmin
Startup persistence
Triggers by tool behavior
DPAPI creds1
cmdkey /list1
certutil→bitsadmin1
Startup VBScript1
Creds access led the hits
New challenge for EDR ops
AI NEWS BLITZ
Sophos says AI coding assistants keep tripping detection rules built to catch intruders.