8 clasificadores que transforman eventos crudos en Behaviors tipificados.
Detecta en conexiones de red:
| Condición | Behavior |
|---|---|
| Host en SUSPICIOUS_HOST_PATTERNS + bytesSent > 1MB | code_upload |
| Host en patrones + path AI API | ai_prompt_sent |
| Host en patrones (sin lo anterior) | suspicious_connection |
| Host desconocido + path AI API + >50KB | code_upload |
| Host desconocido + path AI API | ai_prompt_sent |
| Body HTTP contiene "git bundle" | git_bundle_uploaded |
| DNS query matchea patrones | dns_suspicious |
| SNI matchea patrones | tls_suspicious |
Detecta en procesos:
| Condición | Behavior |
|---|---|
| Nombre/cmdline contiene AI agent (grok, cursor, claude, etc.) | process_suspicious |
cmdline contiene taskkill/Stop-Process/wmic process + sentinel o PID Sentinel |
monitor_disabled |
| cmdline matchea monitor detection commands | monitor_awareness_detected |
cmdline contiene git bundle create, git archive |
git_bundle_created / git_archive_created |
cmdline contiene git rev-list --all, git pack-objects, etc. |
repo_indexed |
cmdline contiene curl + --data-binary/-d/-F/-T/--upload-file |
code_upload |
cmdline contiene nslookup + -type=txt/dominio `.attacker |
.exfil |
cmdline contiene tar + .git + -czf/-zcf/--create |
git_archive_created |
Skip rules (no generan behavior):
node.exeejecutandodist/cli/main.jsoscripts/record-session.js(propia infraestructura)mscopiloto\microsoft\copilot\(proceso legítimo del SO)
Orden de evaluación: monitor_disabled se evalúa antes que monitor_awareness_detected para que un intento de Stop-Process contra sentinel no sea clasificado erróneamente como simple conciencia del monitor.
| Condición | Behavior |
|---|---|
Path contiene .git + objects |
git_objects_read |
Path contiene .git + logs/index/config/head |
git_history_read |
Path termina en .bundle o .gitbundle |
git_bundle_created |
Path contiene secret fragments (.env, secrets, credentials, etc.) |
secrets_scanned |
| Acción git | Behavior |
|---|---|
bundle |
git_bundle_created |
archive |
git_archive_created |
rev-list, log |
git_history_read |
push --mirror/--all/--force |
full_repo_snapshot |
cat-file, ls-tree, show-ref, for-each-ref |
git_objects_read |
clone, fetch, pull |
No genera (normal) |
status, add, commit, diff, etc. |
No genera (normal) |
Comandos de preparación/reconocimiento:
| Comando | |
|---|---|
whoami, ipconfig, netstat, hostname |
|
arp, route, systeminfo |
|
nslookup |
|
git cat-file, git rev-list, git ls-tree |
|
git count-objects, git show-ref, git for-each-ref |
|
git diff --cached, git stash list, git stash |
|
git bundle list-heads |
Requieren FileAccessEvent (no implementado en Windows actualmente).