Crypto miner environment variables observed

Goal

Detect when a process launches with environment variables associated with cryptocurrency miners.

Strategy

Some cryptocurrency miners support environment variables such as POOL_USER or POOL_URL to define configuration settings. This can be used to identify suspicious processes with high confidence.

Requires Agent version 7.27 or later.

PREVIEWING: james.pond/cloudcraft-1192-update-eks-docs