BREAKING
AI coding agents trip EDR rules
Claude Code hits credential rule
1
browse.exe
↓
2
node.exe
↓
3
PowerShell
↓
4
Creds_3b hit
Legit dev looks like an attack
AI agent intent
●
Fetch installers
●
Refactor and debug
●
Solve tasks by pivoting tools
EDR sees
ATT&CK
●
Credential access
●
LOLBins: certutil, bitsadmin
●
Startup persistence
Triggers by tool behavior
DPAPI creds
1
cmdkey /list
1
certutil→bitsadmin
1
Startup VBScript
1
Creds access led the hits
New challenge for EDR ops
AI NEWS BLITZ
Sophos says AI coding assistants keep tripping detection rules built to catch intruders.