Vendor: Oracle

June 14, 2023 · View on GitHub

Product: Solaris

Use-Case: Cryptomining

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
20111
Event TypeRulesModels
process-createdT1496 - Resource Hijacking
A-EPA-Shadow-Mining-name: Process ending with 'miner.exe' has been run on this asset
EPA-Shadow-Mining-name: Process ending with 'miner.exe' has been run