{"id":62519,"date":"2026-07-08T18:47:20","date_gmt":"2026-07-08T22:47:20","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=62519"},"modified":"2026-07-08T18:47:20","modified_gmt":"2026-07-08T22:47:20","slug":"ai-coding-agents-trigger-security-rules","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/ai-coding-agents-trigger-security-rules\/","title":{"rendered":"AI Coding Agents Trigger Endpoint Security Rules Meant for Attackers"},"content":{"rendered":"<p>AI coding assistants such as <a href=\"https:\/\/overcentral.com\/en\/anthropic-claude-code-artifacts\/\" title=\"Anthropic Launches Live Claude Code Artifacts for Enterprise Teams\" data-iacss-internal=\"1\">Claude Code<\/a>, Cursor, and OpenAI Codex are triggering endpoint detection rules originally written to catch human attackers, according to new telemetry analysis from <a href=\"https:\/\/www.sophos.com\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Sophos<\/a>. The agents are not malicious, but their routine operations \u2014 decrypting browser credentials, enumerating Windows credential stores, downloading files with built-in system tools, and writing startup scripts \u2014 map almost perfectly onto the behavioral signals that security teams have spent years tuning to detect intrusions. What has changed is who is generating that signal, and defenders are now facing a novel question: how do you distinguish a benign developer assistant from a live attacker when both perform the same actions on the same endpoints?<\/p>\n<h2>What Set the Alarms Off<\/h2>\n<p>Sophos examined seven days of telemetry from June 2026, drawn from its behavioral engine on Windows endpoints and measured by unique machines rather than raw event volume. The window is narrow and limited to one vendor&#8217;s fleet, but the pattern is striking. Credential access accounted for 56.2 percent of the blocked agent activity, and execution accounted for 28.8 percent \u2014 the agents were reaching for stored secrets and running code in ways that defensive engines treat as high-confidence indicators of compromise.<\/p>\n<p>The single largest credential-access rule, representing 42.6 percent of that category, fires when a process uses Windows&#8217; built-in Data Protection API (DPAPI) to decrypt browser-stored credential data. Sophos identifies GStack as a widely adopted skill pack for coding agents, and its <code>\/browse<\/code>codecodecodecode skill does exactly this: it runs PowerShell that calls DPAPI to unlock saved browser data. Sophos observed this behavior running under Claude Code. In operational context, it is almost certainly browser automation executing on the user&#8217;s behalf. To the detection engine, it is credential theft, and the rule is correct to fire.<\/p>\n<p>Some examples from the telemetry looked even more concerning on paper. In one instance, Claude Code shut down the running browser and executed a script that extracted data from its credential store. Separately, it ran <code>cmdkey \/list<\/code>codecodecodecode to enumerate credentials held in Windows Credential Manager. Sophos notes that in this case Claude Code operated with its <code>--dangerously-skip-permissions<\/code>codecodecodecode flag enabled \u2014 a mode that Anthropic&#8217;s own documentation warns against and provides administrators with the means to block through managed settings.<\/p>\n<p>When one approach is blocked, the agent tries another. OpenAI Codex demonstrated exactly that behavior: it fetched a Python installer from the legitimate python.org, first attempting to download it with <code>certutil<\/code>codecodecodecode. That was blocked, so it switched to <code>bitsadmin<\/code>codecodecodecode. Both are legitimate Windows utilities that attackers routinely abuse to pull payloads \u2014 classic living-off-the-land techniques. The target in this case was harmless, but Sophos&#8217;s point is that this pivot-when-blocked behavior has long been a hallmark of live human attackers, and benign agents now exhibit it as well.<\/p>\n<p>Cursor triggered a persistence rule by using PowerShell to drop a startup-folder script that would execute every time the machine booted. Sophos could not confirm the script&#8217;s purpose, but writing to startup outside a trusted installer is exactly the kind of action that defenders flag on sight.<\/p>\n<h2>AI Agents on Both Sides of the Line<\/h2>\n<p>The dual-use nature of these tools is already visible. A month before this telemetry analysis, Sophos documented an attacker who used <a href=\"https:\/\/overcentral.com\/en\/woodside-ai-agents-lng-startup\/\" title=\"Woodside Deploys 50 AI Agents to Optimize LNG Plant Startups\" data-iacss-internal=\"1\">AI agents<\/a> to build and test malware against EDR products, with Claude Opus 4.5 coordinating the work. That was development-time abuse: agents helping an attacker write better tooling. But agents can also be turned against their own users at runtime. In a separate case, researchers demonstrated that a coding agent could be tricked into executing attacker code through poisoned inputs \u2014 a chain that can bypass endpoint detection because the agent operates within the user&#8217;s trusted session.<\/p>\n<p>These events involve different rules and different threat models, but they share a common surface: browser credential calls, LOLBin downloads, and startup writes now originate from benign agents, attacker-controlled agents, and hijacked agents alike. That convergence means the raw action alone tells you less than it once did.<\/p>\n<p>The problem sits inside a broader structural shift in how intrusions look. CrowdStrike&#8217;s 2026 Global Threat Report found that 82 percent of 2025 detections were malware-free, with attackers moving through valid credentials and trusted tools instead of dropping files. That shift is what pushed detection toward behavioral analysis in the first place. <a href=\"https:\/\/overcentral.com\/en\/agentjacking-ai-coding-agent-attack\/\" title=\"Agentjacking Tricks AI Coding Agents Into Running Malicious Code\" data-iacss-internal=\"1\">AI coding agents<\/a> now generate that same behavioral signal for ordinary, non-malicious reasons, crowding the exact indicators that defenders came to rely on.<\/p>\n<h2>What It Means for Defenders<\/h2>\n<p>If developers run these agents under their own accounts with standard privileges, endpoint rules will fire on their machines. Sophos&#8217;s recommended approach is to split detection rules by what they catch. Execution noise from an agent retrying a download or emitting oddly formatted PowerShell can usually be scoped to the agent&#8217;s parent process \u2014 <code>claude.exe<\/code>codecodecodecode, <code>cursor.exe<\/code>codecodecodecode, and their child processes \u2014 its workspace or temp path, or the reputation of the download target. That filtering stops a known agent doing ordinary work from generating alerts.<\/p>\n<p>Credential-touching behavior is where defenders should hold the line. Decrypting browser credentials or enumerating Credential Manager does not become safe because an agent performed the action instead of a person, and an agent should not inherit blanket access to credential stores simply because it runs under a trusted user account. If the noise stems from Claude Code&#8217;s <code>--dangerously-skip-permissions<\/code>codecodecodecode mode, disable that mode through managed settings. Sophos characterizes this as an early read, not a verdict, and notes that while the direction is clear, the scale of the shift is still small.<\/p>\n<p><strong>What security teams should do now.<\/strong> Review endpoint detection rules that fire on credential access and execution techniques commonly used by AI coding agents. Scope rules by parent process, workspace path, and download reputation where possible, and enforce strict permission boundaries for credential-store access regardless of the requesting process. Disable dangerous modes like <code>--dangerously-skip-permissions<\/code>codecodecodecode through managed policy settings. The open question \u2014 what a coding agent should be allowed to touch on an endpoint at all \u2014 needs an answer, and credential stores are a sensible place to draw the first line.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>AI coding assistants such as Claude Code, Cursor, and OpenAI Codex are triggering endpoint detection rules originally written to catch human attackers, according to new telemetry analysis from Sophos. The agents are not malicious, but their routine operations \u2014 decrypting browser credentials, enumerating Windows credential stores, downloading files with built-in system tools, and writing startup [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":84246,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/62519.png","fifu_image_alt":"AI Coding Agents Trigger Endpoint Security Rules Meant for Attackers","footnotes":""},"categories":[349],"tags":[],"class_list":["post-62519","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/62519.png","fifu_image_alt":"AI Coding Agents Trigger Endpoint Security Rules Meant for Attackers","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62519","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=62519"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62519\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/84246"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=62519"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=62519"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=62519"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}