Suspicious heavy allocation of compute resources - possible mining activity
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Impact (TA0040), Initial Access (TA0001)
ATT&CK Technique
Resource Hijacking (T1496), Valid Accounts (T1078)
Severity
Medium
Description
An identity allocated an unusual heavy compute resource, suspected as mining activity. Heavy machines normally have a high amount of CPU cores or attached with GPU, which are targeted by adversaries to mine Cryptocurrency.
Attacker's Goals
Leverage cloud compute resources to earn virtual currency.
Investigative actions
Check the identity created resources and its legitimacy.
Look for any unusual behavior originated from the suspected identity, and check if they're compromised, e.g. access key, service account, etc.
Variations
Was this helpful?
