Vendor: QUSH

June 14, 2023 · View on GitHub

Product: Reveal

Use-Case: Cryptomining

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
20211
Event TypeRulesModels
web-activity-allowedT1071.001 - Application Layer Protocol: Web Protocols
WEB-Shadow-Mining: User has browsed to a known coinmining/shadowmining domain

T1496 - Resource Hijacking
A-WEB-Shadow-Mining: Host has browsed to a known coinmining/shadowmining domain
WEB-Shadow-Mining: User has browsed to a known coinmining/shadowmining domain