What Custom Detection Rules Are You Using To Detect AI Tools?

It seems like every few days there is a new AI Tool that is confirmed to ship Malware in one way or another, with OpenClaw being the latest. I am interested in how everyone here is monitoring these runpaths and installations in their R7 IDR environments?

Thanks in advance, and I hope this can generate some better visibility into this topic for everyone that visits this forum :slight_smile:

For visiblity - Same question and thoughts