Loading interactive filters…
1200KM / detection
T1496 Resource Hijacking — Detection Rules
Detection workspace for T1496 Resource Hijacking: 13 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.
Source-backed rule directory
- Azure Container Registry Created or Deleted · test · low · {"product":"azure","service":"activitylogs"}
- Azure Kubernetes Cluster Created or Deleted · test · low · {"product":"azure","service":"activitylogs"}
- Azure Kubernetes Network Policy Change · test · medium · {"product":"azure","service":"activitylogs"}
- Azure Kubernetes Sensitive Role Access · test · medium · {"product":"azure","service":"activitylogs"}
- Azure Kubernetes RoleBinding/ClusterRoleBinding Modified and Deleted · test · medium · {"product":"azure","service":"activitylogs"}
- Azure Kubernetes Secret or Config Object Access · test · medium · {"product":"azure","service":"activitylogs"}
- Azure Kubernetes Service Account Modified or Deleted · test · medium · {"product":"azure","service":"activitylogs"}
- Linux Crypto Mining Pool Connections · stable · high · {"product":"linux","category":"network_connection"}
- Linux Crypto Mining Indicators · test · high · {"product":"linux","category":"process_creation"}
- Monero Crypto Coin Mining Pool Lookup · stable · high · {"category":"dns"}
- DNS Events Related To Mining Pools · test · low · {"service":"dns","product":"zeek"}
- Network Communication With Crypto Mining Pool · stable · high · {"category":"network_connection","product":"windows"}
- Potential Crypto Mining Activity · stable · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1496 Resource Hijacking
MATCH(known_mining_process_or_pool_destination) OR resource_usage >= fixed_threshold FOR fixed_duration -> ALERT
Anomaly models
Unauthorized computation or resource abuse — T1496 Resource Hijacking
Comparison unit: workload resource-consumption series.
Expected behavior: compute, power, cost, and network use follow workload schedules.
Deviation: sustained level shift, tail consumption, or emerging upward trend.
ATT&CK analytic guidance
Persistent high CPU utilization combined with suspicious command-line execution (e.g., mining tools or obfuscated scripts) and outbound connections to mining/proxy networks.
Abnormal CPU/memory usage by unauthorized processes with outbound connections to known mining pools or using cron jobs/scripts to maintain persistence.
Background launch agents/daemons with high CPU use and network access to external mining services.
Sudden spikes in cloud VM CPU usage with outbound traffic to mining pools and unauthorized instance creation.
High CPU usage by unauthorized containers running mining binaries or public proxy tools.
Abuse of cloud messaging platforms to send mass spam or consume quota-based resources.
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.