Dev.to
7/12/2026

What Your AI Coding Agent Looks Like to a SIEM
Short summary
Sophos X-Ops telemetry from seven days of Claude Code, Cursor, and OpenAI Codex on Windows shows behavioral detection rules fire heavily on AI coding agents — 56.2% of blocks were credential access, 28.8% suspicious execution. Normal agent activities like DPAPI decryption for browser sessions and PowerShell spawning match infostealer patterns. The article explains why SIEMs can't distinguish legitimate agent behavior from malware and what that means for security teams.
- •56.2% of SIEM blocks on AI coding agents were credential access rules
- •Normal agent behaviors (browser credential decryption, PowerShell) match infostealer patterns
- •Security teams need awareness that AI agents trigger behavioral detection at high rates
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



