AI Hooks
Overview
Section titled “Overview”Evidence: AI Hooks
Description: Parse AI hook definitions that auto-execute commands on agent events
Category: AI
Platform: windows
Short Name: aihook
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No
Background
Section titled “Background”Cursor hooks.json and Claude settings can bind shell commands to AI tool events such as session start, prompt submit, or file edit. Hooks run automatically and are a high-risk persistence and remote-code-execution surface.
Data Collected
Section titled “Data Collected”This collector gathers structured data about AI hook definitions, including event, matcher, command, referenced script hashes, and source config paths.
Collection Method
Section titled “Collection Method”This collector parses hook event, matcher, and command entries from Cursor and Claude hook configs, hashes referenced scripts, and preserves source configs.
Forensic Value
Section titled “Forensic Value”Hooks can run shell commands before or after AI tool events without an interactive prompt. They are a high-risk persistence and code-execution surface during AI-assisted investigations.