Files
splunk-security_content/docs/_stories/cloud_cryptomining.md
T
2021-09-20 20:45:22 -04:00

2.0 KiB

title, last_modified_at, toc, tags
title last_modified_at toc tags
Cloud Cryptomining 2019-10-02 true
Splunk Security Analytics for AWS
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Change

Description

Monitor your cloud compute instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or compute instances started by previously unseen users are just a few examples of potentially malicious behavior.

  • ID: 3b96d13c-fdc7-45dd-b3ad-c132b31cdd2a
  • Product: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel: Change
  • Last Updated: 2019-10-02
  • Author: David Dorsey, Splunk

Detection profiles

Name Technique Type
Abnormally High Number Of Cloud Instances Launched None Anomaly
Cloud Compute Instance Created By Previously Unseen User None Anomaly
Cloud Compute Instance Created In Previously Unused Region None Anomaly
Cloud Compute Instance Created With Previously Unseen Image None Anomaly
Cloud Compute Instance Created With Previously Unseen Instance Type None Anomaly

Reference

source | version: 1