mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
2.0 KiB
2.0 KiB
title, last_modified_at, toc, tags
| title | last_modified_at | toc | tags | |||||
|---|---|---|---|---|---|---|---|---|
| Cloud Cryptomining | 2019-10-02 | true |
|
Description
Monitor your cloud compute instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or compute instances started by previously unseen users are just a few examples of potentially malicious behavior.
- ID: 3b96d13c-fdc7-45dd-b3ad-c132b31cdd2a
- Product: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel: Change
- Last Updated: 2019-10-02
- Author: David Dorsey, Splunk
Detection profiles
| Name | Technique | Type |
|---|---|---|
| Abnormally High Number Of Cloud Instances Launched | None | Anomaly |
| Cloud Compute Instance Created By Previously Unseen User | None | Anomaly |
| Cloud Compute Instance Created In Previously Unused Region | None | Anomaly |
| Cloud Compute Instance Created With Previously Unseen Image | None | Anomaly |
| Cloud Compute Instance Created With Previously Unseen Instance Type | None | Anomaly |
Reference
source | version: 1