Hub rules-claude-mythos

rules-claude-mythos

v2 public Verified

Claude-mythos

Advanced security hardening rules for sophisticated AI agent capabilities. These rules defend against memory exploitation, network egress threats, and Living off the Land abuse.

@sigmashakeinc 2 pulls 31 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-claude-mythos →
Severity
25 error 6 warn 0 info
demo.cast
Advanced security hardening rules for sophisticated AI agent capabilities. These rules defend against memory exploitation, network egress threats, and Living off the Land abuse.

Rules index

31 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

00-sensitive-paths

ask-diagnostic-tools error ask

Requires approval: diagnostic/memory tools need explicit authorization.

Rule source requires an active Pro or Enterprise subscription.
block-git-config-read error block

Blocked: Git configuration files may contain credentials.

Rule source requires an active Pro or Enterprise subscription.
block-proc-access error block

Blocked: /proc access is restricted — contains kernel memory and process internals.

Rule source requires an active Pro or Enterprise subscription.
block-proc-read error block

Blocked: reading /proc is restricted — contains sensitive kernel and process data.

Rule source requires an active Pro or Enterprise subscription.
block-ssh-keys error block

Blocked: SSH key directory is off-limits.

Rule source requires an active Pro or Enterprise subscription.

01-anti-concealment

block-git-history-rewrite error block

Blocked: git history rewriting is forbidden — it can conceal malicious changes.

Rule source requires an active Pro or Enterprise subscription.
block-governance-tampering error block

Blocked: direct access to governance internals is forbidden.

Rule source requires an active Pro or Enterprise subscription.
block-governance-write error block

Blocked: writing to governance files is forbidden — only ssg itself may modify these.

Rule source requires an active Pro or Enterprise subscription.

02-network-egress

ask-network-egress warning ask

Requires approval: network egress to unrecognized domain.

Rule source requires an active Pro or Enterprise subscription.
block-pastebins error block

Blocked: uploading to paste/file-sharing services is forbidden.

Rule source requires an active Pro or Enterprise subscription.

03-destructive-ops-hitl

ask-destructive-fs error ask

Requires human approval: destructive filesystem operation.

Rule source requires an active Pro or Enterprise subscription.
ask-destructive-process error ask

Requires human approval: forceful process termination.

Rule source requires an active Pro or Enterprise subscription.
ask-destructive-sql error ask

Requires human approval: destructive SQL operation.

Rule source requires an active Pro or Enterprise subscription.
ask-migration-write warning log

Requires human approval: migration with destructive SQL detected.

Rule source requires an active Pro or Enterprise subscription.

04-custom-exploit-compilation

ask-foreign-compilers warning ask

The agent is using modern compilers (Go, Rust, Zig, Nim) to build binaries into a temporary directory. These languages are increasingly used for LotL abuse and malware due to static linking capabilities.

Rule source requires an active Pro or Enterprise subscription.
ask-suspicious-compilation warning ask

The agent is compiling C/C++ code directly into a temporary directory (/tmp or /dev/shm). This is a common pattern for dropping and executing local privilege escalation exploits or custom malware.

Rule source requires an active Pro or Enterprise subscription.
deny-exploit-headers error block

Blocked: Attempt to write source code that includes kernel memory, BPF, or ptrace headers. These are strictly used for kernel rootkits, process injection, and advanced exploits.

Rule source requires an active Pro or Enterprise subscription.

05-lotl-abuse

ask-suspicious-downloads warning ask

The agent is attempting to download a remote script and immediately pipe it into an interpreter (curl | sh). This is a known execution vector for malicious payloads.

Rule source requires an active Pro or Enterprise subscription.
block-base64-execution error block

Blocked: The agent is executing an obfuscated (Base64) payload directly in a subshell. This is an evasion technique used to bypass text-based pattern constraints.

Rule source requires an active Pro or Enterprise subscription.
block-lotl-shells error block

Blocked: The agent is attempting to spawn a reverse shell or unmonitored PTY session using a LotL binary (Python, Perl, Ruby, Awk). This bypasses governance logs and isolates the agent.

Rule source requires an active Pro or Enterprise subscription.

06-kernel-and-injection

deny-kernel-modules error block

Blocked: The agent is attempting to load or manipulate kernel modules. This is a severe sandbox escape vector and is never permitted for autonomous agents.

Rule source requires an active Pro or Enterprise subscription.
deny-ld-preload error block

Blocked: The agent is attempting to manipulate LD_PRELOAD, LD_LIBRARY_PATH (with temporary directories), or PROMPT_COMMAND. This is a well-known process injection and hook interception technique.

Rule source requires an active Pro or Enterprise subscription.
deny-ptrace-dmesg error block

Blocked: The agent is searching for kernel base addresses (KASLR defeats) by reading dmesg, kallsyms, or accessing process memory directly. This indicates an active kernel exploitation attempt.

Rule source requires an active Pro or Enterprise subscription.

07-advanced-memory-threats

deny-cred-smashing error block

Blocked: The agent is referencing internal kernel credential management (commit_creds/init_cred). Extremely high indicator of local privilege escalation exploit compilation.

Rule source requires an active Pro or Enterprise subscription.
deny-jit-spraying error block

Blocked: Use of V8 debug native flags or arraybuffer-based JIT-spraying patterns to escape Javascript sandboxes.

Rule source requires an active Pro or Enterprise subscription.
deny-kaslr-defeats error block

Blocked: Attempt to use KASLR subversion primitives, per_cpu variables mapping, or specific direct map addresses. Found in autonomous privilege escalation tooling.

Rule source requires an active Pro or Enterprise subscription.
deny-slub-spraying error block

Blocked: Highly specific SLUB allocator heap spray behaviors using Message Queues (msgsnd) inside memory management hooks. Associated with advanced vulnerability chaining.

Rule source requires an active Pro or Enterprise subscription.
deny-unsafe-ffi error block

Blocked: Code execution using direct unsafe FFI memory primitives (e.g. sun.misc.Unsafe, python ctypes.memmove, Rust unsafe raw pointers). Used in VM Guest-to-Host escapes.

Rule source requires an active Pro or Enterprise subscription.

08-advanced-network-threats

ask-ipset-overflows warning ask

The agent is executing specific low-level ipset creations utilizing bitmap:ip combined with exclusive flags. This has been used to exploit integer underflows in netfilter.

Rule source requires an active Pro or Enterprise subscription.
deny-oob-socket-abuse error block

Blocked: Attempt to create Out-Of-Band (MSG_OOB) domain sockets or raw AF_PACKET rings combined with internal sk_buff manipulation. Often utilized for kernel UAF network exploits.

Rule source requires an active Pro or Enterprise subscription.
deny-rpc-chunking error block

Blocked: Attempting to abuse FreeBSD RPCSEC_GSS stack buffers or chunking kernel ROP chains over packets.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v2
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
1f3731c8cdda07cf0f7b2ce4054ce4430d5cde00928c396f536320ccd7e3c93a
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-claude-mythos/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-claude-mythos. The published version only bumps when a maintainer resyncs.

No commit history available.