Rules by Product and UseCase

October 24, 2023 · View on GitHub

Vendor: BeyondTrust

Product: BeyondInsight

Use-Case: Cryptomining

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
10111
Event TypeRulesModels
process-createdT1496 - Resource Hijacking
↳ A-EPA-Shadow-Mining-name: Process ending with 'miner.exe' has been run on this asset

Contents

  1. 1Vendor: BeyondTrust
  2. 1.1Product: BeyondInsight
  3. 1.2Use-Case: Cryptomining