MITRE ATT&CK technique
Resource Hijacking detection rulesT1496
Resource Hijacking (T1496) is a MITRE ATT&CK technique in the Impact tactic. This page lists the 13 community-maintained Sigma detection rules in the library mapped to T1496 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target azure, linux, windows.
Linux Crypto Mining Indicators
highDetects command line parameters or strings often used by crypto miners
linux · process_creation
Linux Crypto Mining Pool Connections
highDetects process connections to a Monero crypto mining pool
linux · network_connection
Monero Crypto Coin Mining Pool Lookup
highDetects suspicious DNS queries to Monero mining pools
dns
Network Communication With Crypto Mining Pool
highDetects initiated network connections to crypto mining pools. It indicates that the system is likely infected with a crypto miner malware or is being used for crypto mining.
windows · network_connection
Potential Crypto Mining Activity
highDetects command line parameters or strings often used by crypto miners
windows · process_creation
Azure Kubernetes Network Policy Change
mediumIdentifies when a Azure Kubernetes network policy is modified or deleted.
azure
Azure Kubernetes RoleBinding/ClusterRoleBinding Modified and Deleted
mediumDetects the creation or patching of potential malicious RoleBinding/ClusterRoleBinding.
azure
Azure Kubernetes Secret or Config Object Access
mediumIdentifies when a Kubernetes account access a sensitive objects such as configmaps or secrets.
azure
Azure Kubernetes Sensitive Role Access
mediumIdentifies when ClusterRoles/Roles are being modified or deleted.
azure
Azure Kubernetes Service Account Modified or Deleted
mediumIdentifies when a service account is modified or deleted.
azure
Azure Container Registry Created or Deleted
lowDetects when a Container Registry is created or deleted.
azure
Azure Kubernetes Cluster Created or Deleted
lowDetects when a Azure Kubernetes Cluster is created or deleted.
azure
DNS Events Related To Mining Pools
lowIdentifies clients that may be performing DNS lookups associated with common currency mining pools.
zeek