Skip to main content

GCTI threat feed name for Cryptomining domain

  • February 14, 2025
  • 3 replies
  • 26 views

Mufa_shah
Forum|alt.badge.img+4

How to find cryptomining bad domain related threat feed names? for  building rules using graph entity in yara L. 

3 replies

ErikaB
Community Manager
Forum|alt.badge.img+10
  • Community Manager
  • February 15, 2025

Hi @mmufa 

You might find some helpful examples in the community-contributed YARA-L rules on GitHub. https://github.com/chronicle/detection-rules.  Look for rules that detect cryptomining and examine how they access threat intelligence data. 


Mufa_shah
Forum|alt.badge.img+4
  • Author
  • Bronze 2
  • February 20, 2025

@ErikaB Thanks Erica i have gone through this not much helpful need specific  threat feed name related to cryptomining domains


DanDye
Staff
Forum|alt.badge.img+5
  • Staff
  • February 20, 2025

@Mufa_shah navigate to IoC Collections:
https://www.virustotal.com/gui/threat-landscape/ioc-collections
...and then search for "cryptomining"