Browse Rules

Search and filter across all detection sources

53 rules

sagan critical other

[CISCO-SCA] Suspected Cryptocurrency Activity

[CISCO-SCA] Suspected Cryptocurrency Activity

sagan medium other

[EXTRAHOP] Cryptocurrency Mining Pool Connection Attempt

[EXTRAHOP] Cryptocurrency Mining Pool Connection Attempt

chronicle high yara-l

AWS GuardDuty Cryptocurrency Activity Detected

Amazon GuardDuty detects CryptoCurrency activity in Amazon EC2, AWS Lambda or Amazon EKS Runtimes.

elastic-protections high eql

Access Attempt to Non Existing Cryptocurrency Wallet

Identifies access attempts to non existing cryptocurrency wallet files. Adversaries may perform discovery to steal potential cryptocurrency related files for for financial gains.

sagan critical other

[AWS-GUARDDUTY] GuardDuty event detected (CryptoCurrency:EC2/BitcoinTool.B)

[AWS-GUARDDUTY] GuardDuty event detected (CryptoCurrency:EC2/BitcoinTool.B)

sagan medium other

[EXTRAHOP] New DNS Request for a Cryptocurrency Mining Pool

[EXTRAHOP] New DNS Request for a Cryptocurrency Mining Pool

sagan medium other

[EXTRAHOP] New TLS Connection to a Cryptocurrency Mining Pool

[EXTRAHOP] New TLS Connection to a Cryptocurrency Mining Pool

sagan critical other

[AWS-GUARDDUTY] GuardDuty event detected (CryptoCurrency:EC2/BitcoinTool.B!DNS)

[AWS-GUARDDUTY] GuardDuty event detected (CryptoCurrency:EC2/BitcoinTool.B!DNS)

sublime low mql

Spam: Cryptocurrency airdrop/giveaway

Detects messages promoting cryptocurrency airdrops, token claims, or wallet-related rewards.

sublime low mql

Brand impersonation: Ripple

Attack impersonating Ripple cryptocurrency, potentially in the form of a giveaway scam.

sublime low mql

Brand impersonation: Ledger

Attack impersonating hardware cryptocurrency wallet ledger.com's brand.

chronicle unknown yara-l

darkgate_cryptocurrency_mining_and_ransomware_campaign_sysmon

DarkGate Cryptocurrency Mining and Ransomware Campaign Detector. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

sublime high mql

Link: Cryptocurrency fraud with suspicious links

Detects messages containing financial communications about cryptocurrency or bitcoin with links to suspicious domains, URL shorteners, newly registered domains, or domains with known cryptocurrency fraud indicators. The rule analyzes link behavior including redirects, specific abuse patterns, and JavaScript configurations commonly used in cryptocurrency scams. Excludes legitimate cryptocurrency platforms with proper authentication.

sublime medium mql

Brand impersonation: Binance

Impersonation of the cryptocurrency exchange Binance.

sublime high mql

Brand impersonation: Coinbase

Impersonation of the cryptocurrency exchange Coinbase to harvest Coinbase credentials or related information.

elastic-protections high eql

Suspicious Access to Cryptocurrency Wallet Files

Identifies access attempts to multiple unique cryptocurrency wallet files by the same process. Adversaries may steal those files to for financial gains.

sublime low mql

Brand impersonation: Exodus

Attack impersonating Exodus Wallet.

sublime low mql

Brand impersonation: Stellar Development Foundation (SDF)

Attack impersonating Stellar Development Foundation (SDF).

sentinel low kql

Chia_Crypto_Mining IOC - June 2021

'Identifies a match across IOC's related to Chia cryptocurrency farming/plotting activity'

sublime high mql

beta.DLP: Crypto Wallet Address

Detects messages containing cryptocurrency wallet addresses.

sublime low mql

Attachment: PDF file with link to fake Bitcoin exchange

Fraudulent message containing a PDF notification of unclaimed Bitcoin assets. The PDF file contains a link to a fake Cryptocurrency portal. Attempting to withdraw funds prompts the user to enter payment information.

elastic-protections high eql

Malicious Ledger Live Execution

Detects unsigned binaries masquerading as "Ledger Live" cryptocurrency wallet software. These fake applications steal wallet seed phrases and private keys from victims through social engineering.

elastic-protections high eql

Suspicious Curl User Agent

Detects curl commands using the "cur1" user agent string, associated with BlueNoroff/Lazarus Group campaigns. This deliberate misspelling is a reliable indicator of nation-state attacks targeting cryptocurrency sectors.

sigma medium sigma

Remove Scheduled Cron Task/Job

Detects usage of the 'crontab' utility to remove the current crontab. This is a common occurrence where cryptocurrency miners compete against each other by removing traces of other miners to hijack the maximum amount of resources possible

elastic-protections high eql

DNS Request to Crypto Miner Service

This rule detects DNS queries to miner services via living-off-the-land executables or executables in world/user-writable directories. Malware authors may use these services to mine cryptocurrency to generate revenue.