Skip to content

Latest commit

 

History

History
42 lines (35 loc) · 1.75 KB

MATCH-S00592.md

File metadata and controls

42 lines (35 loc) · 1.75 KB

Rules: Crypto Miner User Agent

Description

Observes for several known cryptominer user agents

Additional Details

Detail Value
Type Templated Match
Category Unknown/Other
Apply Risk to Entities device_hostname, srcDevice_hostname, user_username, srcDevice_ip
Signal Name Crypto Miner User Agent
Summary Expression User agent string: {{http_userAgent}} contains keywords associated with crypto miners
Score/Severity Static: 5
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0011, _mitreAttackTechnique:T1071.001, _mitreAttackTechnique:T1071, _mitreAttackTechnique:T1496

Vendors and Products

Fields Used

Origin Field
Normalized Schema device_hostname
Normalized Schema http_userAgent
Normalized Schema srcDevice_hostname
Normalized Schema srcDevice_ip
Normalized Schema user_username