Terminology Index
Glossary
1801 terms
Showing 449-480 of 1801 terms
Cryptomining Incident Response
The response to a cryptomining (cryptojacking) incident in the cloud, confirming the unauthorized mining, scoping how the attacker got in, containing and removing the mining workloads, and closing the entry point, often using a predefined playbook.
Cryptomining IR treats the mining itself as a symptom of a real compromise. Responders confirm the activity (anomalous CPU and cost), investigate how the attacker gained access, often stolen credentials or an exposed orchestrator, contain by isolating and removing the mining workloads, and remediate the root cause so it cannot recur. Because the entry point could be used for worse than mining, scoping the full compromise matters as much as stopping the miner.
Introduced in: Cloud Incident Response
Examples
- Confirming cryptomining from a cost and CPU spike, then tracing the entry point.
- Isolating and removing hijacked mining workloads from a cluster.
- Closing the exposed API or rotating the stolen credentials that enabled it.
No related terms linked yet.
