pack:
  id: behavioural-chains
  version: 1.0.0
  created: 2026-07-28T00:00:00Z
  provenance:
    sources:
      - internal_research
    incident_refs: []
  minimum_engine_version: 0.6.0
  rules:
    - id: credential-exfiltration-chain
      severity: critical
      name: Credential exfiltration chain
      description: >
        Detects the full harvest-then-exfiltrate shape: enumerating
        sensitive credential directories, reading a specific credential
        file, archiving it, then reaching out to an external network
        destination — all within a short window. Each step alone can be
        legitimate; the completed chain is what marks this as a credible
        exfiltration attempt.
      response_level: block
      type: sequence
      sequence:
        - action_type: READ
          step: enumerate_sensitive_paths
          conditions: {}
        - action_type: READ
          step: read_credential_file
          conditions: {}
        - action_type: EXECUTE
          step: create_archive
          conditions: {}
        - action_type: NETWORK_CONNECT
          step: connect_external_domain
          conditions: {}
      window_seconds: 300
      action: block_and_isolate

    - id: privilege-escalation-chain
      severity: critical
      name: Privilege escalation chain
      description: >
        Detects enumeration of sensitive paths followed by spawning a
        privileged process (sudo/runas/admin elevation) followed by a
        git-history rewrite — a pattern consistent with an agent gaining
        elevated access and then covering its tracks in version control.
      response_level: block
      type: sequence
      sequence:
        - action_type: READ
          step: enumerate_sensitive_paths
          conditions: {}
        - action_type: EXECUTE
          step: spawn_privileged_process
          conditions: {}
        - action_type: EXECUTE
          step: modify_git_history
          conditions: {}
      window_seconds: 180
      action: block_and_isolate

    - id: workspace-escape-chain
      severity: high
      name: Workspace escape chain
      description: >
        Detects an agent writing or reading outside its declared
        workspace boundary, then installing a package not present in any
        lockfile, then connecting to an external network destination —
        consistent with an agent breaking its sandbox and reaching for
        unvetted code plus an outbound channel.
      response_level: block
      type: sequence
      sequence:
        - action_type: WRITE
          step: workspace_escape
          conditions: {}
        - action_type: EXECUTE
          step: install_unknown_package
          conditions: {}
        - action_type: NETWORK_CONNECT
          step: connect_external_domain
          conditions: {}
      window_seconds: 300
      action: block_and_isolate

    - id: mass-deletion-chain
      severity: critical
      name: Mass deletion chain
      description: >
        Detects an attempt to disable Shield monitoring/auditing
        immediately followed by mass file deletion — the classic
        "blind the guard, then destroy the evidence/workspace" pattern.
      response_level: block
      type: sequence
      sequence:
        - action_type: WRITE
          step: disable_monitoring
          conditions: {}
        - action_type: DELETE
          step: mass_file_deletion
          conditions: {}
      window_seconds: 120
      action: block_and_isolate

    - id: monitoring-disable-chain
      severity: high
      name: Monitoring disable chain
      description: >
        Detects an attempt to disable Shield monitoring/auditing,
        followed by a git-history rewrite, followed by an outbound
        network connection — consistent with an agent silencing
        oversight, rewriting the record of what it did, and exfiltrating
        before the disabled monitoring is noticed.
      response_level: block
      type: sequence
      sequence:
        - action_type: WRITE
          step: disable_monitoring
          conditions: {}
        - action_type: EXECUTE
          step: modify_git_history
          conditions: {}
        - action_type: NETWORK_CONNECT
          step: connect_external_domain
          conditions: {}
      window_seconds: 300
      action: block_and_isolate

  signature: ""
