Detection rules › Kusto Query Language

DNS events related to mining pools (ASIM DNS Schema)

Author
Microsoft Security Research
Source
upstream

'Identifies IP addresses that may be performing DNS lookups associated with common currency mining pools. This analytic rule uses ASIM and supports any built-in or custom source that supports the ASIM DNS schema'

MITRE ATT&CK coverage

TacticTechniques
ImpactT1496 Resource Hijacking

Event coverage

ProviderEvent IDTitle
Sysmon22DNSEvent (DNS query)

Stages and Predicates

Stage 1: source

_Im_Dns

Stage 2: extend

Stage 3: extend

Stage 4: project-away