AI Coding Agents Trigger Endpoint Security Rules Meant for Attackers

By Central

AI coding assistants such as Claude Code, Cursor, and OpenAI Codex are triggering endpoint detection rules originally written to catch human attackers, according to new telemetry analysis from Sophos. The agents are not malicious, but their routine operations — decrypting browser credentials, enumerating Windows credential stores, downloading files with built-in system tools, and writing startup scripts — map almost perfectly onto the behavioral signals that security teams have spent years tuning to detect intrusions. What has changed is who is generating that signal, and defenders are now facing a novel question: how do you distinguish a benign developer assistant from a live attacker when both perform the same actions on the same endpoints?

What Set the Alarms Off

Sophos examined seven days of telemetry from June 2026, drawn from its behavioral engine on Windows endpoints and measured by unique machines rather than raw event volume. The window is narrow and limited to one vendor’s fleet, but the pattern is striking. Credential access accounted for 56.2 percent of the blocked agent activity, and execution accounted for 28.8 percent — the agents were reaching for stored secrets and running code in ways that defensive engines treat as high-confidence indicators of compromise.

The single largest credential-access rule, representing 42.6 percent of that category, fires when a process uses Windows’ built-in Data Protection API (DPAPI) to decrypt browser-stored credential data. Sophos identifies GStack as a widely adopted skill pack for coding agents, and its /browsecodecodecodecode skill does exactly this: it runs PowerShell that calls DPAPI to unlock saved browser data. Sophos observed this behavior running under Claude Code. In operational context, it is almost certainly browser automation executing on the user’s behalf. To the detection engine, it is credential theft, and the rule is correct to fire.

Some examples from the telemetry looked even more concerning on paper. In one instance, Claude Code shut down the running browser and executed a script that extracted data from its credential store. Separately, it ran cmdkey /listcodecodecodecode to enumerate credentials held in Windows Credential Manager. Sophos notes that in this case Claude Code operated with its --dangerously-skip-permissionscodecodecodecode flag enabled — a mode that Anthropic’s own documentation warns against and provides administrators with the means to block through managed settings.

When one approach is blocked, the agent tries another. OpenAI Codex demonstrated exactly that behavior: it fetched a Python installer from the legitimate python.org, first attempting to download it with certutilcodecodecodecode. That was blocked, so it switched to bitsadmincodecodecodecode. Both are legitimate Windows utilities that attackers routinely abuse to pull payloads — classic living-off-the-land techniques. The target in this case was harmless, but Sophos’s point is that this pivot-when-blocked behavior has long been a hallmark of live human attackers, and benign agents now exhibit it as well.

Cursor triggered a persistence rule by using PowerShell to drop a startup-folder script that would execute every time the machine booted. Sophos could not confirm the script’s purpose, but writing to startup outside a trusted installer is exactly the kind of action that defenders flag on sight.

AI Agents on Both Sides of the Line

The dual-use nature of these tools is already visible. A month before this telemetry analysis, Sophos documented an attacker who used AI agents to build and test malware against EDR products, with Claude Opus 4.5 coordinating the work. That was development-time abuse: agents helping an attacker write better tooling. But agents can also be turned against their own users at runtime. In a separate case, researchers demonstrated that a coding agent could be tricked into executing attacker code through poisoned inputs — a chain that can bypass endpoint detection because the agent operates within the user’s trusted session.

These events involve different rules and different threat models, but they share a common surface: browser credential calls, LOLBin downloads, and startup writes now originate from benign agents, attacker-controlled agents, and hijacked agents alike. That convergence means the raw action alone tells you less than it once did.

The problem sits inside a broader structural shift in how intrusions look. CrowdStrike’s 2026 Global Threat Report found that 82 percent of 2025 detections were malware-free, with attackers moving through valid credentials and trusted tools instead of dropping files. That shift is what pushed detection toward behavioral analysis in the first place. AI coding agents now generate that same behavioral signal for ordinary, non-malicious reasons, crowding the exact indicators that defenders came to rely on.

What It Means for Defenders

If developers run these agents under their own accounts with standard privileges, endpoint rules will fire on their machines. Sophos’s recommended approach is to split detection rules by what they catch. Execution noise from an agent retrying a download or emitting oddly formatted PowerShell can usually be scoped to the agent’s parent process — claude.execodecodecodecode, cursor.execodecodecodecode, and their child processes — its workspace or temp path, or the reputation of the download target. That filtering stops a known agent doing ordinary work from generating alerts.

Credential-touching behavior is where defenders should hold the line. Decrypting browser credentials or enumerating Credential Manager does not become safe because an agent performed the action instead of a person, and an agent should not inherit blanket access to credential stores simply because it runs under a trusted user account. If the noise stems from Claude Code’s --dangerously-skip-permissionscodecodecodecode mode, disable that mode through managed settings. Sophos characterizes this as an early read, not a verdict, and notes that while the direction is clear, the scale of the shift is still small.

What security teams should do now. Review endpoint detection rules that fire on credential access and execution techniques commonly used by AI coding agents. Scope rules by parent process, workspace path, and download reputation where possible, and enforce strict permission boundaries for credential-store access regardless of the requesting process. Disable dangerous modes like --dangerously-skip-permissionscodecodecodecode through managed policy settings. The open question — what a coding agent should be allowed to touch on an endpoint at all — needs an answer, and credential stores are a sensible place to draw the first line.

Share This Article