attack.t1496

Windows Crypto Mining Pool Connections
level
status stable

Detects process connections to a Monero crypto mining pool

Windows Crypto Mining Indicators
level
status stable

Detects command line parameters or strings often used by crypto miners

Monero Crypto Coin Mining Pool Lookup
level
status stable

Detects suspicious DNS queries to Monero mining pools

DNS Events Related To Mining Pools
level
status experimental

Identifies clients that may be performing DNS lookups associated with common currency mining pools.

Sponsored by

Phish Report logo
With Phish Report you can achieve streamlined phishing takedowns using your existing security team.