Skip to content

Latest commit

 

History

History
14 lines (12 loc) · 989 Bytes

r_m_gigamon_gigavue-hc2_Cryptomining.md

File metadata and controls

14 lines (12 loc) · 989 Bytes

Rules by Product and UseCase

Vendor: Gigamon

Product: GigaVUE-HC2

Use-Case: Cryptomining

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
3 0 2 1 4
Event Type Rules Models
web-activity-allowed T1496 - Resource Hijacking
WEB-Shadow-Mining-IP: User has connected to a known coinmining/shadowmining IP
A-WEB-Shadow-Mining: Host has browsed to a known coinmining/shadowmining domain
A-NET-Coin-IP: Connection to IP associated with cryptocurrency mining

T1071.001 - Application Layer Protocol: Web Protocols
WEB-Shadow-Mining-IP: User has connected to a known coinmining/shadowmining IP