Vendor: Imperva

June 14, 2023 · View on GitHub

Product: Incapsula

Use-Case: Cryptomining

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
20222
Event TypeRulesModels
web-activity-allowedT1071.001 - Application Layer Protocol: Web Protocols
WEB-Shadow-Mining: User has browsed to a known coinmining/shadowmining domain

T1496 - Resource Hijacking
A-WEB-Shadow-Mining: Host has browsed to a known coinmining/shadowmining domain
WEB-Shadow-Mining: User has browsed to a known coinmining/shadowmining domain
web-activity-deniedT1071.001 - Application Layer Protocol: Web Protocols
WEB-Shadow-Mining: User has browsed to a known coinmining/shadowmining domain

T1496 - Resource Hijacking
A-WEB-Shadow-Mining: Host has browsed to a known coinmining/shadowmining domain
WEB-Shadow-Mining: User has browsed to a known coinmining/shadowmining domain