Detector libraryNetwork egress

Network egress

A new host. A reason to look.

Notice unfamiliar destinations in captured agent commands.

See the problem. Understand the finding.

English narration with captions.

How it gets overlooked

Your agent needs documentation. A moment later, its command points at a host you have never seen in this workflow. The destination may be legitimate. But without context, a new host is just another line in the terminal.

Imagine an agent that normally uses a familiar package index. During a task, an unfamiliar destination appears in its recorded tool arguments. The important question is why that destination belongs in this session.

What ClawMetry detects

ClawMetry compares observed host references with the learned cohort baseline. A host absent from that baseline can raise a network egress warning. The finding identifies the new host and the reason it was considered unusual.

The difference that changes the finding

Triggering example

collector.invalid

Warning finding

Quiet comparison

pypi.org in baseline

No finding for this detector.

In the checked example, the baseline contains the familiar package host. That host stays quiet. A different host raises a first time destination finding. This comparison needs a learned baseline; a fresh install does not already know your normal destinations.

Inspect the detector result
{
  "kind": "network_egress",
  "severity": "warning",
  "evidence": {
    "ground": "first_time",
    "distinct_hosts": 1,
    "hosts": [
      "collector.invalid"
    ],
    "new_hosts": [
      "collector.invalid"
    ],
    "settling_hosts": [],
    "raw_addresses": [],
    "known_host_count": 1,
    "threshold": 8,
    "write_hosts": [],
    "read_only_writes": [],
    "observed": "tool_arguments"
  }
}
Download inputs and complete results (JSON)
How the example was checked

These examples evaluate the published detector with authored event data or disposable configuration files. The videos illustrate those behaviors. They are not recordings of live agents or the product interface. No command in the examples was executed.

The result establishes behavior for these inputs. It does not establish runtime ingestion, prevention or a real compromise. Inspect the pinned source contract.

What to check next

Inspect the command and the surrounding task. Was the agent fetching documentation, installing a dependency or attempting a write? Check the destination ownership and any sensitive activity that came before it. Use those facts to decide whether the action was expected.

  1. Inspect the command
  2. Verify the destination
  3. Check preceding activity

What this signal establishes

Host references come from tool arguments, not packet capture. A new host does not prove a connection succeeded or data was exfiltrated.

Keep the important moments visible.

Follow agent activity, inspect findings and decide what needs your attention.