Technique with 4 sub-techniques.View on attack.mitre.org
Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.
Resource hijacking may take a number of different forms. For example, adversaries may:
* Leverage compute resources in order to mine cryptocurrency
* Sell network bandwidth to proxy networks
* Generate SMS traffic for profit
* Abuse cloud-based messaging services to send large quantities of spam messages
In some cases, adversaries may leverage multiple types of Resource Hijacking at once.
Rules on DetectionCode tagged with T1496 or one of its sub-techniques.
| Rule | Level | Log source | Technique |
|---|---|---|---|
| Linux Crypto Mining Indicators | high | linux / process_creation | T1496 |
| Linux Crypto Mining Pool Connections | high | linux / network_connection | T1496 |
| Monero Crypto Coin Mining Pool Lookup | high | NULL / dns | T1496 |
| Network Communication With Crypto Mining Pool | high | windows / network_connection | T1496 |
| Potential Crypto Mining Activity | high | windows / process_creation | T1496 |
| Azure Kubernetes Network Policy Change | medium | azure / NULL | T1496 |
| Azure Kubernetes RoleBinding/ClusterRoleBinding Modified and Deleted | medium | azure / NULL | T1496 |
| Azure Kubernetes Secret or Config Object Access | medium | azure / NULL | T1496 |
| Azure Kubernetes Sensitive Role Access | medium | azure / NULL | T1496 |
| Azure Kubernetes Service Account Modified or Deleted | medium | azure / NULL | T1496 |
| Azure Container Registry Created or Deleted | low | azure / NULL | T1496 |
| Azure Kubernetes Cluster Created or Deleted | low | azure / NULL | T1496 |
| DNS Events Related To Mining Pools | low | zeek / NULL | T1496 |
None recorded.
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.