heroui logo

Claude Cowork VM Boot Image Tamper

Elastic Detection Rules

View Source
Summary
Detects unexpected modification of Claude Desktop Cowork VM boot images (initrd, initrd.zst, vmlinuz, rootfs.img, smol-bin.vhdx) located in Claude's AppData/Application Support folders on Windows and macOS. It flags creation, modification, overwrite, or rename of these boot image files when the file paths under Claude vm_bundles are altered, a technique attackers can exploit to cause subsequent Cowork sessions to boot attacker-controlled code inside a guest VM that may evade host EDR visibility. The rule excludes legitimate Claude processes (claude.exe under WindowsApps and Claude.app on macOS) to reduce false positives. It maps to MITRE ATT&CK T1564.006 (Run Virtual Instance) under Defense Evasion. The alert is triggered for successful file write events to the specified paths on Windows/macOS, with a distinct focus on boot artifacts that enable persistent control over a virtualized guest. The accompanying notes provide triage steps (identify writer process, file changed, and scope around the host for ~30 minutes), false positive considerations (legitimate updates or packaging changes), and recommended remediation (restore/verify the vm_bundles, re-download trusted images, isolate the host, rotate credentials, and hunt for initial access).
Categories
  • Endpoint
  • Windows
  • macOS
Data Sources
  • File
  • Process
ATT&CK Techniques
  • T1564
  • T1564.006
Created: 2026-08-05