Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

Siemphony’s repertoire

Detect mining pool and miner arguments in process command lines

Matches process creation whose command line carries a cryptocurrency mining configuration: a `stratum://` pool URL, the donation, rig-identity and NiceHash switches that miner families expose, or a RandomX/Monero algorithm selection. MITRE names `Image` as a mutable element for this analytic — campaigns rename and masquerade the binary — so the logic sits entirely on `CommandLine`, which the pool configuration cannot be stripped from and still mine. Sustained CPU consumption and the persistent pool connection are the analytic's real discriminators; neither a resource threshold nor a duration is expressible in Sigma, so this catches the launch rather than the sustained load. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0540, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full description

The detection

The 4 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.

detection.yml

title: Detect mining pool and miner arguments in process command linesid: d61c99a5-3dd7-40da-abb6-f73c320da66bstatus: experimentaldescription: |  Matches process creation whose command line carries a cryptocurrency mining  configuration: a `stratum://` pool URL, the donation, rig-identity and NiceHash  switches that miner families expose, or a RandomX/Monero algorithm selection.  MITRE names `Image` as a mutable element for this analytic — campaigns rename and  masquerade the binary — so the logic sits entirely on `CommandLine`, which the  pool configuration cannot be stripped from and still mine. Sustained CPU  consumption and the persistent pool connection are the analytic's real  discriminators; neither a resource threshold nor a duration is expressible in  Sigma, so this catches the launch rather than the sustained load.  UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0540, not hand-written and not tested by its author. Any lab result is on this rule's own page.references:  - https://attack.mitre.org/techniques/T1496/001  - https://attack.mitre.org/detectionstrategies/DET0540author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags:  - attack.impact  - attack.t1496.001logsource:  category: process_creation  product: windowsdetection:  selection:    CommandLine|contains:      - 'stratum+tcp://'      - 'stratum+ssl://'      - 'stratum1+tcp://'      - 'stratum2+tcp://'      - '--donate-level'      - '--nicehash'      - '--rig-id'      - '--algo=rx/0'      - '--algo=randomx'      - '--coin=monero'      - 'xmrig'      - 'minerd'  condition: selectionfalsepositives:  - "Hosts where mining is intentional — a research, blockchain-development or benchmarking machine, or a workstation whose owner mines out of hours. The command line is identical to the malicious case; only the asset's purpose separates them, so scope this rule by host group rather than by term."  - "Security tooling handling the sample rather than running it. Detonation sandboxes, EDR scanners and an analyst pasting a miner config into a console all put these strings on a legitimate parent's command line. MITRE lists `ParentProcessName` as the mutable element for exactly this — filter on the known-good launcher."  - "Wrapper and orchestration scripts that pass a miner configuration through without being the miner, such as a container entrypoint or a scheduled task whose argument string is logged verbatim. The same launch then re-alerts on every scheduled run."level: high

Sentinel · KQL

Run this as a search.

DeviceProcessEvents| where (ProcessCommandLine contains "stratum+tcp://" or ProcessCommandLine contains "stratum+ssl://" or ProcessCommandLine contains "stratum1+tcp://" or ProcessCommandLine contains "stratum2+tcp://" or ProcessCommandLine contains "--donate-level" or ProcessCommandLine contains "--nicehash" or ProcessCommandLine contains "--rig-id" or ProcessCommandLine contains "--algo=rx/0" or ProcessCommandLine contains "--algo=randomx" or ProcessCommandLine contains "--coin=monero" or ProcessCommandLine contains "xmrig" or ProcessCommandLine contains "minerd")

Splunk · SPL

Run this as a search.

index=* (CommandLine="*stratum+tcp://*" OR CommandLine="*stratum+ssl://*" OR CommandLine="*stratum1+tcp://*" OR CommandLine="*stratum2+tcp://*" OR CommandLine="*--donate-level*" OR CommandLine="*--nicehash*" OR CommandLine="*--rig-id*" OR CommandLine="*--algo=rx/0*" OR CommandLine="*--algo=randomx*" OR CommandLine="*--coin=monero*" OR CommandLine="*xmrig*" OR CommandLine="*minerd*")

Elastic · ES|QL

Run this as a search.

FROM logs-*| WHERE (TO_LOWER(process.command_line) LIKE "*stratum+tcp://*" OR TO_LOWER(process.command_line) LIKE "*stratum+ssl://*" OR TO_LOWER(process.command_line) LIKE "*stratum1+tcp://*" OR TO_LOWER(process.command_line) LIKE "*stratum2+tcp://*" OR TO_LOWER(process.command_line) LIKE "*--donate-level*" OR TO_LOWER(process.command_line) LIKE "*--nicehash*" OR TO_LOWER(process.command_line) LIKE "*--rig-id*" OR TO_LOWER(process.command_line) LIKE "*--algo=rx/0*" OR TO_LOWER(process.command_line) LIKE "*--algo=randomx*" OR TO_LOWER(process.command_line) LIKE "*--coin=monero*" OR TO_LOWER(process.command_line) LIKE "*xmrig*" OR TO_LOWER(process.command_line) LIKE "*minerd*")

Wazuh · XML rule

Deploy to your manager — this is a rule, not a search.

<group name="sigma,windows,process_creation,">  <!-- Rule ids must be unique on your manager; 100000+ is the user range. -->  <rule id="100000" level="12">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="CommandLine" type="pcre2">(?i)(stratum\+tcp://|stratum\+ssl://|stratum1\+tcp://|stratum2\+tcp://|--donate-level|--nicehash|--rig-id|--algo=rx/0|--algo=randomx|--coin=monero|xmrig|minerd)</field>    <description>Detect mining pool and miner arguments in process command lines</description>    <mitre>      <id>T1496.001</id>    </mitre>  </rule></group>

Verdicts · reactions · comments

Community

Verdicts from engineers who actually deployed it, and the conversation around it.

Log in to react
Not yet reported on

Nobody has run this in a real environment and said what happened.

Verdicts from engineers who deployed it

0 cast

No verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.

Log in to report a verdict.

Log in to join the discussion.

No comments yet. Someone who deploys this will have something to say about it.