Cross-source coverage

T1496 / ATT&CK

Resource Hijacking

91 rules · 88 families across 9 sources.

25 deprecated hidden · include

Showing atomic-IOC rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.

Resource hijacking may take a number of different forms. For example, adversaries may:

  • Leverage compute resources in order to mine cryptocurrency
  • Sell network bandwidth to proxy networks
  • Generate SMS traffic for profit
  • Abuse cloud-based messaging services to send large quantities of spam messages

In some cases, adversaries may leverage multiple types of Resource Hijacking at once.

Tactics
Impact
Platforms
Windows · IaaS · Linux · macOS · Containers · SaaS
Telemetry
WinEventLog:SysmonWindows:perfmonauditd:SYSCALLlinux:procfsNSM:Flowmacos:unifiedlogAWS:CloudTrailAWS:CloudWatchAWS:VPCFlowLogscontainerd:eventsprometheus:metricscontainer:cnim365:unifiedsaas:application

How MITRE says to detect it DET0267

Resource Hijacking Detection Strategy

Windows Analytic 0741

Persistent high CPU utilization combined with suspicious command-line execution (e.g., mining tools or obfuscated scripts) and outbound connections to mining/proxy networks.

  • WinEventLog:Sysmon EventCode=1
  • Windows:perfmon High sustained CPU usage by a single process
  • WinEventLog:Sysmon EventCode=3, 22

Linux Analytic 0742

Abnormal CPU/memory usage by unauthorized processes with outbound connections to known mining pools or using cron jobs/scripts to maintain persistence.

  • auditd:SYSCALL execve
  • linux:procfs Sustained high /proc/[pid]/stat usage
  • NSM:Flow Outbound traffic to mining pools or proxies

macOS Analytic 0743

Background launch agents/daemons with high CPU use and network access to external mining services.

  • macos:unifiedlog launchctl activity and process creation
  • macos:unifiedlog Persistent outbound traffic to mining domains

IaaS Analytic 0744

Sudden spikes in cloud VM CPU usage with outbound traffic to mining pools and unauthorized instance creation.

  • AWS:CloudTrail RunInstances
  • AWS:CloudWatch Sustained EC2 CPU usage above normal baseline
  • AWS:VPCFlowLogs Outbound flow logs to known mining pools

Containers Analytic 0745

High CPU usage by unauthorized containers running mining binaries or public proxy tools.

  • containerd:events New container with suspicious image name or high resource usage
  • prometheus:metrics Container CPU/Memory usage exceeding threshold
  • container:cni Outbound network traffic to mining proxies

SaaS Analytic 0746

Abuse of cloud messaging platforms to send mass spam or consume quota-based resources.

  • m365:unified SendMessage
  • saas:application High-volume API calls or traffic via messaging or webhook service

Sub-techniques with coverage

Counted in the 91 above — a rule tagged a sub-technique covers this technique too.


Emerging Threats Open

45 rules · 43 families
Detection Severity Format
ET ADWARE_PUP Installer Analytics Checkin (POST) High Suricata
ET ADWARE_PUP Onestart AI Host Profile Checkin (POST) High Suricata
ET ADWARE_PUP Onestart AI Program Version Checkin (POST) High Suricata
ET COINMINER CoinMiner Exfiltration via IRC Config Inbound (Italian) High Suricata
ET COINMINER CoinMiner Malicious Authline Seen After CVE-2017-10271 Exploit High Suricata
ET COINMINER Cryptexplorer API Check - Potential CoinMiner Traffic High Suricata
ET COINMINER Observed DNS Query to Browser Coinminer (crypto-loot[.]com) High Suricata
ET COINMINER Observed DNS Query to herominers Domain (herominers .com) High Suricata
ET COINMINER PrimeCoinMiner.Protominer High Suricata
ET COINMINER W32/BitCoinMiner.MultiThreat Getblocktemplate Protocol Server Coinbasetxn Begin Mining Response High Suricata

+ 35 more from Emerging Threats Open → showing the 10 highest-severity

SigmaHQ/sigma

13 rules
Detection Severity Format
Linux Crypto Mining Indicators High Sigma
Linux Crypto Mining Pool Connections High Sigma
Monero Crypto Coin Mining Pool Lookup High Sigma
Network Communication With Crypto Mining Pool High Sigma
Potential Crypto Mining Activity High Sigma
Azure Kubernetes Network Policy Change Medium Sigma
Azure Kubernetes RoleBinding/ClusterRoleBinding Modified and Deleted Medium Sigma
Azure Kubernetes Secret or Config Object Access Medium Sigma
Azure Kubernetes Sensitive Role Access Medium Sigma
Azure Kubernetes Service Account Modified or Deleted Medium Sigma

+ 3 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

11 rules
Detection Severity Format
AWS Potential Cryptomining via ECS Task Definition Deployment High Elastic TOML
AWS SNS Topic Message Publish by Rare User High Elastic TOML
Newly Observed Process Exhibiting High CPU Usage High Elastic TOML
Potential Redis CONFIG SET Cron Directory Persistence (RedisRaider) High Elastic TOML
AWS Bedrock Provisioned Model Throughput Tampering Medium Elastic TOML
AWS Lambda Function High-Frequency Invocation by a Single Principal Medium Elastic TOML
Memory Swap Modification Medium Elastic TOML
Potential Malware-Driven SSH Brute Force Attempt Medium Elastic TOML
Suspicious Mining Process Creation Event Medium Elastic TOML
AWS SNS Rare Protocol Subscription by User Low Elastic TOML

+ 1 more from elastic/detection-rules → showing the 10 highest-severity

elastic/protections-artifacts

7 rules
Detection Severity Format
DNS Request to Crypto Miner Service Undefined Elastic TOML
MSR Write Access Enabled Undefined Elastic TOML
Potential Coin Miner Execution Undefined Elastic TOML
Potential Coin Miner Execution via Shell Undefined Elastic TOML
Potential Crypto Mining Activity Undefined Elastic TOML
Potential Mining Pool Command Detection Undefined Elastic TOML
Scripting or Unsigned Binary Performing DNS Lookups to Ethereum RPC Providers Undefined Elastic TOML

Azure/Azure-Sentinel

5 rules
Detection Severity Format
A host is potentially running a crypto miner (ASIM Web Session schema) Medium KQL
DNS events related to mining pools (ASIM DNS Schema) Low KQL
Anomalous Resource Creation and related Network Activity Undefined KQL
User Granted Access and associated audit activity Undefined KQL
User Granted Access and created resources Undefined KQL

panther-labs/panther-analysis

4 rules
Detection Severity Format
Crowdstrike Cryptomining Tools Critical Panther Python
AWS DNS Crypto Domain High Panther Python
Anthropic Spend Limit Deleted Medium Panther Python
AWS Bedrock Model Invocation Abnormal Token Usage Informational Panther Python

falcosecurity/rules

3 rules
Detection Severity Format
Detect crypto miners using the Stratum protocol Critical Falco YAML
Detect outbound connections to common miner pool ports Critical Falco YAML
Known Cryptominer Process Executed Critical Falco YAML

chronicle/detection-rules

2 rules
Detection Severity Format
aws_guardduty_crypto_currency_activity_detected High YARA-L
aws_ses_service_modification Medium YARA-L

socfortress/Wazuh-Rules

1 rule
Detection Severity Format
High CPU usage process detected: /usr/bin/yes may indicate resource hijacking (T1496). Medium Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.