Use Case: Cryptomining

December 5, 2023 · View on GitHub

Use Case: Cryptomining

Vendor: APC

ProductMITRE ATT&CK® TTPContent
APCT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Absolute

ProductMITRE ATT&CK® TTPContent
Absolute DDST1496 - Resource Hijacking
  • 1 Rules

Vendor: Akamai

ProductMITRE ATT&CK® TTPContent
Cloud AkamaiT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Amazon

ProductMITRE ATT&CK® TTPContent
AWS CloudTrailT1074 - Data Staged
T1496 - Resource Hijacking
  • 2 Rules
  • 1 Models
AWS GuardDutyT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules
AWS WAFT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules
Amazon EKST1496 - Resource Hijacking
  • 1 Rules
Amazon RDST1496 - Resource Hijacking
  • 1 Rules

Vendor: Apache

ProductMITRE ATT&CK® TTPContent
ApacheT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: BeyondTrust

ProductMITRE ATT&CK® TTPContent
BeyondInsightT1496 - Resource Hijacking
  • 1 Rules
BeyondTrustT1496 - Resource Hijacking
  • 1 Rules

Vendor: Check Point

ProductMITRE ATT&CK® TTPContent
Check Point NGFWT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Cisco

ProductMITRE ATT&CK® TTPContent
Cisco ACST1496 - Resource Hijacking
  • 1 Rules
Cisco Adaptive Security ApplianceT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 2 Rules
Cisco Cloud Web SecurityT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules
Cisco FirepowerT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 2 Rules
Cisco IOST1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 2 Rules
Cisco Meraki MX applianceT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules
Cisco Secure Web ApplianceT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules
Cisco UmbrellaT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules
Duo AccessT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Citrix

ProductMITRE ATT&CK® TTPContent
Citrix GatewayT1496 - Resource Hijacking
  • 1 Rules
Citrix Web App FirewallT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Cloudflare

ProductMITRE ATT&CK® TTPContent
Cloudflare WAFT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Cohesity

ProductMITRE ATT&CK® TTPContent
Cohesity DataPlatformT1496 - Resource Hijacking
  • 1 Rules

Vendor: CrowdStrike

ProductMITRE ATT&CK® TTPContent
FalconT1496 - Resource Hijacking
  • 1 Rules

Vendor: CyberArk

ProductMITRE ATT&CK® TTPContent
CyberArk Privilege Access ManagerT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Delinea

ProductMITRE ATT&CK® TTPContent
Centrify Infrastructure ServicesT1496 - Resource Hijacking
  • 1 Rules

Vendor: Dell

ProductMITRE ATT&CK® TTPContent
SonicwallT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Digital Guardian

ProductMITRE ATT&CK® TTPContent
Digital Guardian Endpoint ProtectionT1496 - Resource Hijacking
  • 1 Rules

Vendor: Dtex Systems

ProductMITRE ATT&CK® TTPContent
DTEX InTERCEPTT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 2 Rules

Vendor: Envoy

ProductMITRE ATT&CK® TTPContent
EnvoyT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Extreme Networks

ProductMITRE ATT&CK® TTPContent
ExtremeCloud IQT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: F5

ProductMITRE ATT&CK® TTPContent
F5 Advanced Web Application FirewallT1496 - Resource Hijacking
  • 1 Rules

Vendor: Forcepoint

ProductMITRE ATT&CK® TTPContent
Forcepoint CASBT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules
Websense Security GatewayT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Fortinet

ProductMITRE ATT&CK® TTPContent
FortiGateT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules
Fortinet UTMT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules
Fortiweb Web Application FirewallT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Gigamon

ProductMITRE ATT&CK® TTPContent
GigaVUE-HC2T1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Google

ProductMITRE ATT&CK® TTPContent
Google Cloud PlatformT1071.001 - Application Layer Protocol: Web Protocols
T1074 - Data Staged
T1496 - Resource Hijacking
  • 2 Rules
  • 1 Models
Google WorkspaceT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: HP

ProductMITRE ATT&CK® TTPContent
HP iLOT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules
HPE ComwareT1496 - Resource Hijacking
  • 1 Rules

Vendor: HelpSystems

ProductMITRE ATT&CK® TTPContent
Powertech Identity and Access ManagerT1496 - Resource Hijacking
  • 1 Rules

Vendor: Huawei

ProductMITRE ATT&CK® TTPContent
Huawei Unified Security GatewayT1496 - Resource Hijacking
  • 1 Rules

Vendor: IBM

ProductMITRE ATT&CK® TTPContent
IBM MainframeT1496 - Resource Hijacking
  • 1 Rules

Vendor: Imperva

ProductMITRE ATT&CK® TTPContent
Imperva IncapsulaT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: InfoWatch

ProductMITRE ATT&CK® TTPContent
InfoWatch DLPT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Infoblox

ProductMITRE ATT&CK® TTPContent
BloxOne DDIT1496 - Resource Hijacking
  • 1 Rules

Vendor: Ivanti

ProductMITRE ATT&CK® TTPContent
Ivanti Pulse SecureT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Juniper Networks

ProductMITRE ATT&CK® TTPContent
Junos OST1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 2 Rules

Vendor: Kasada

ProductMITRE ATT&CK® TTPContent
KasadaT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: LanScope

ProductMITRE ATT&CK® TTPContent
LanScope CatT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 2 Rules

Vendor: McAfee

ProductMITRE ATT&CK® TTPContent
McAfee Web GatewayT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Microsoft

ProductMITRE ATT&CK® TTPContent
Active Directory Federation ServicesT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules
Azure MonitorT1496 - Resource Hijacking
  • 1 Rules
  • 1 Models
Azure Monitor - VM InsightsT1496 - Resource Hijacking
  • 1 Rules
Event Viewer - ADFST1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules
Event Viewer - DNSServerT1496 - Resource Hijacking
  • 1 Rules
Event Viewer - PowerShellT1496 - Resource Hijacking
  • 1 Rules
Event Viewer - SecurityT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 2 Rules
Event Viewer - SystemT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 2 Rules
Microsoft 365T1496 - Resource Hijacking
  • 1 Rules
Microsoft Defender for EndpointT1496 - Resource Hijacking
  • 1 Rules
Microsoft ExchangeT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules
Microsoft IIST1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules
Microsoft WMI LogT1496 - Resource Hijacking
  • 1 Rules
SysmonT1496 - Resource Hijacking
  • 1 Rules

Vendor: Mimecast

ProductMITRE ATT&CK® TTPContent
Mimecast Targeted Threat Protection - URLT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Netskope

ProductMITRE ATT&CK® TTPContent
Netskope Security CloudT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: NextDLP

ProductMITRE ATT&CK® TTPContent
RevealT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Okta

ProductMITRE ATT&CK® TTPContent
Okta Adaptive MFAT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: OneWelcome

ProductMITRE ATT&CK® TTPContent
OneWelcome Cloud Identity PlatformT1496 - Resource Hijacking
  • 1 Rules

Vendor: Palo Alto Networks

ProductMITRE ATT&CK® TTPContent
Cortex XSOART1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules
GlobalProtectT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules
Palo Alto NGFWT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules
Prisma CloudT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Password Manager Pro

ProductMITRE ATT&CK® TTPContent
Password Manager ProT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Proofpoint

ProductMITRE ATT&CK® TTPContent
ObserveITT1496 - Resource Hijacking
  • 1 Rules

Vendor: SIGSCI

ProductMITRE ATT&CK® TTPContent
SIGSCIT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: SentinelOne

ProductMITRE ATT&CK® TTPContent
Singularity PlatformT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 2 Rules

Vendor: SkySea

ProductMITRE ATT&CK® TTPContent
SkySea ClientViewT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 2 Rules

Vendor: Skyhigh Security

ProductMITRE ATT&CK® TTPContent
Skyhigh Security CloudT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Sophos

ProductMITRE ATT&CK® TTPContent
Sophos UTMT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Squid

ProductMITRE ATT&CK® TTPContent
SquidT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Symantec

ProductMITRE ATT&CK® TTPContent
Symantec Advanced Threat ProtectionT1496 - Resource Hijacking
  • 1 Rules
Symantec Web Security ServiceT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Tanium

ProductMITRE ATT&CK® TTPContent
Tanium Core PlatformT1496 - Resource Hijacking
  • 1 Rules
Tanium Integrity MonitorT1496 - Resource Hijacking
  • 1 Rules

Vendor: Trend Micro

ProductMITRE ATT&CK® TTPContent
OfficeScanT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Unix

ProductMITRE ATT&CK® TTPContent
AuditbeatT1496 - Resource Hijacking
  • 1 Rules
UnixT1496 - Resource Hijacking
  • 1 Rules
Unix AuditdT1496 - Resource Hijacking
  • 1 Rules

Vendor: VMware

ProductMITRE ATT&CK® TTPContent
Carbon Black App ControlT1496 - Resource Hijacking
  • 1 Rules
Carbon Black CEST1496 - Resource Hijacking
  • 1 Rules
Carbon Black EDRT1496 - Resource Hijacking
  • 1 Rules

Vendor: Varonis

ProductMITRE ATT&CK® TTPContent
Varonis Data Security PlatformT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Vectra

ProductMITRE ATT&CK® TTPContent
Vectra Cognito StreamT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Zeek

ProductMITRE ATT&CK® TTPContent
ZeekT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor: Zscaler

ProductMITRE ATT&CK® TTPContent
Zscaler Internet AccessT1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 1 Rules

Vendor:

ProductMITRE ATT&CK® TTPContent
T1071.001 - Application Layer Protocol: Web Protocols
T1496 - Resource Hijacking
  • 2 Rules