AI Coding Assistants Trigger Enterprise Endpoint Attack Alerts
Sophos telemetry collected over a seven‑day period in June‑July 2026 found that AI coding agents such as Claude Code, Cursor, OpenAI Codex and related skill packs are activating endpoint detection rules that were originally written to catch human attackers. The agents’ legitimate actions—browser automation, dependency installation and troubleshooting—frequently involve techniques mapped to MITRE ATT&CK tactics like Credential Access and Execution. For example, PowerShell processes using Windows’ Data Protection API (DPAPI) to decrypt browser‑stored passwords triggered the “Creds_3b” rule, accounting for 56.2 % of blocked activity, while the use of built‑in Windows utilities (certutil, bitsadmin, cmdkey) and startup‑folder writes generated further alerts.
Although none of the observed behavior was malicious, the similarity to adversary techniques caused false positives, prompting Sophos to recommend scoping rules to the agents’ parent processes and adjusting detection thresholds. “This is not surprising at all and we will likely see many more examples in the future,” said Scott Miserendino, CTO of DataBee, a Comcast company. The findings highlight a growing challenge for security teams as AI‑driven automation blurs the line between benign activity and indicators of compromise.
The research underscores the need for endpoint protection vendors to adapt policies and for organizations to establish clear AI‑agent usage guidelines to prevent unnecessary security alerts while maintaining protection against real threats.