Block the Hermes Agent, another 'Claw-like assistant

Observable: hermes-agent.nousresearch[.]com

Observable Type: Domain

Admiralty: A1

Details:

Hermes is a newer 'Claw-like AI assistant. It has some nifty features, but ultimately its autonomous nature means it can’t be trusted in your environment. If you feel the need to block OpenClaw because of how it behaves rather than any specific vulnerability, you should block this one too.

Hi,

Another one I saw a few days ago. I think this is becoming a trend, and we may see more in the following months.

Definitely. Here’s another one in the list:

Unfortunately ZeroClaw uses GitHub directly for installation, but worth monitoring process/file creations.

Hi,

I quickly wrote a couple of Sigma rules for process creation and Powershell ScriptBlock. I have the feeling that the list is going to grow quickly.

I briefly tried looking for “unusual programs connecting to AI API endpoints”, using DNS data. It is a mess.

posh_ps_ai_agent_installation.txt (1.1 KB)

proc_creation_win_ai_agent_installation.txt (1.1 KB)

1 Like

We’re building a list of AI API endpoints but yeah, it’s a lot.

Have you submitted the Sigma rules to the official repo? Might be worth doing.