Hunting OpenClaw

I’m building a threat hunt for OpenClaw, but it has gotten significantly trickier since this article.

OpenClaw defaults to loopback for its web UI, recommending exposure either via Tailscale or via SSH port forwarding. That means you won’t likely see much TCP 18789 traffic on the wire. Or you will, but it will likely be unrelated. Other things use that port—VoIP, it seems.

So how would you hunt for this thing? Endpoint data alone? I’m looking now for openclaw folders, because regardless of install method, that should be there. That’s all I got.

Well there’s this: