Tag
Detection of Newly Observed Processes with High CPU Usage
1 TTPThis detection capability monitors for unauthorized resource hijacking, such as cryptomining or exploit payload execution, by identifying new processes exhibiting sustained CPU usage above 90 percent.
Detection of Security Alerts Correlated with High CPU Utilization
1 TTPA cross-platform detection methodology correlates security alerts with processes exhibiting sustained high CPU utilization to identify potential resource abuse or post-compromise activity.
AWS Potential Cryptomining via ECS Task Definition Deployment
1 TTP 5 IOCsAdversaries, after compromising AWS credentials, deploy cryptomining operations on Amazon ECS and AWS Fargate by registering task definitions with public high-CPU container images and then launching them, leading to unauthorized resource consumption and increased cloud costs.
You do surprise me.exe: Unexpected Crypto-Miner in Hola Browser
3 rules 5 TTPs 4 IOCsSophos X-Ops discovered that Hola Browser version 1.251.91.0 was distributed with an undeclared crypto-mining executable, me.exe, due to a supply chain compromise, leading to resource hijacking on affected Windows systems.
Unusual EC2 Instance Creation with Unseen Instance Type
2 rules 1 TTPAn attacker may create new EC2 instances with previously unseen instance types, indicating potential unauthorized or suspicious activity such as cryptomining or data exfiltration.