# Custom rule: catch known cryptominer binaries by process name directly. # Added after the 2026-08-06 gitea/xmrig compromise, where the miner was # invoked as `--url=host:port` with no "stratum+tcp" scheme prefix, which # would NOT have matched Falco's stock "Detect crypto miners using the # Stratum protocol" rule. Matching the binary name is the reliable signal. - list: miner_binary_names items: [ xmrig, xmrig-notls, xmr-stak, xmr-stak-cpu, xmr-stak-rx, minerd, cpuminer, ccminer, cgminer, bfgminer, nanominer, t-rex, trex, teamredminer, phoenixminer, lolminer, ethminer, nbminer, gminer, srbminer, xmrigMiner, ] - rule: Detect crypto miner binary execution desc: > A process matching a known cryptocurrency miner binary name was executed. Catches unauthorized miners even when the command line doesn't use a stratum+tcp:// style URL. condition: > spawned_process and proc.name in (miner_binary_names) output: > Cryptominer binary execution detected (user=%user.name command=%proc.cmdline container=%container.name image=%container.image.repository pid=%proc.pid) priority: CRITICAL tags: [miners, process, mitre_impact]