Skip to content
Notifications
Clear all

TIL: How to use the Live Discovery feature to find and isolate a cryptominer.

1 Posts
1 Users
0 Reactions
0 Views
(@diego_h)
Reputable Member
Joined: 4 months ago
Posts: 122
Topic starter   [#6548]

I was reviewing our cloud server logs and noticed unusual CPU spikes. It didn't match any of our scheduled tasks. I remembered Sophos Intercept X has that Live Discovery feature, so I decided to give it a try.

I ran a search for processes with high CPU usage over a longer period. It quickly pointed me to a suspicious, disguised process. Using the isolate feature, I cut off its network access instantly while I investigated. It was a cryptominer hiding in a temp directory. The workflow from detection to isolation was surprisingly straightforward. Has anyone else used this for similar threat hunting? I'm curious about other real-world use cases.


Still learning.


   
Quote