Detecting OpenClaw using advanced posture checks
ID: 99f515de-6d9b-5061-9d5d-ef7c491e59a2
STIX ID: report--99f515de-6d9b-5061-9d5d-ef7c491e59a2
Feed Name: Okta Threat Intelligence
Threat Score
This SQL-based detection rule aggregates counts of filesystem paths, processes, package names, listening ports, applications, and Docker artifacts matching 'openclaw' to compute a score and flag systems likely hosting the OpenClaw tool; it is a telemetry query intended for hunting or automated detection rather than an incident narrative.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
