Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0267 — Resource Hijacking Detection Strategy
DET0267

Resource Hijacking Detection Strategy

6 analytic(s) · 1 technique(s) detected

Analytics

6
AN0741 Analytic 0741
Windows

Persistent high CPU utilization combined with suspicious command-line execution (e.g., mining tools or obfuscated scripts) and outbound connections to mining/proxy networks.

WinEventLog:Sysmon EventCode=1 Windows:perfmon High sustained CPU usage by a single process WinEventLog:Sysmon EventCode=3, 22
[TimeWindow] Duration threshold for sustained CPU activity (e.g., >15 minutes)
[DestinationIPList] Known mining pool IPs or proxy service endpoints
[ExecutableNamePatterns] Regex list of suspicious or known mining tools
AN0742 Analytic 0742
Linux

Abnormal CPU/memory usage by unauthorized processes with outbound connections to known mining pools or using cron jobs/scripts to maintain persistence.

auditd:SYSCALL execve linux:procfs Sustained high /proc/[pid]/stat usage NSM:Flow Outbound traffic to mining pools or proxies
[ProcessPath] Location of resource-heavy binaries (e.g., /tmp/.xmr)
[CPUThreshold] Acceptable baseline for CPU overuse
[KnownMiningDomains] List of domains/IPs for known cryptomining services
AN0743 Analytic 0743
macOS

Background launch agents/daemons with high CPU use and network access to external mining services.

macos:unifiedlog launchctl activity and process creation macos:unifiedlog Persistent outbound traffic to mining domains
[launchdLabel] Suspicious or unknown launch agents
[TrafficVolumeThreshold] Outbound bandwidth usage thresholds
AN0744 Analytic 0744
IaaS

Sudden spikes in cloud VM CPU usage with outbound traffic to mining pools and unauthorized instance creation.

AWS:CloudTrail RunInstances AWS:CloudWatch Sustained EC2 CPU usage above normal baseline AWS:VPCFlowLogs Outbound flow logs to known mining pools
[CPUUtilizationThreshold] CloudWatch alarm trigger for sustained CPU
[UnusualRegionList] Instances launched in unexpected regions
AN0745 Analytic 0745
Containers

High CPU usage by unauthorized containers running mining binaries or public proxy tools.

containerd:events New container with suspicious image name or high resource usage prometheus:metrics Container CPU/Memory usage exceeding threshold container:cni Outbound network traffic to mining proxies
[ImageName] Suspicious or unknown container image used
[CPUQuotaThreshold] Container-level resource limits
AN0746 Analytic 0746
SaaS

Abuse of cloud messaging platforms to send mass spam or consume quota-based resources.

m365:unified SendMessage saas:application High-volume API calls or traffic via messaging or webhook service
[MessageRateThreshold] Max allowable outbound message rate per user/account
[APIKeyList] Known authorized API clients for messaging usage

Detected Techniques

1

Details

MITRE ID
DET0267
STIX ID
x-mitre-detection-strategy--440ddaf2-4e80-4699-90d7-0bdccdfeece6
Analytics
6
Techniques Detected
1
By Tactic
Impact
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.