Anomalous number of instances with high GPU created
Set up the oracle-cloud-infrastructure integration.
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、
お気軽にご連絡ください。
Goal
Detect when an attempt to create a high GPU-based virtual machine (VM) instance in OCI occurs.
Strategy
This rule monitors OCI Audit Logs to determine when an attempt to create an anomalous number of high GPU-based VM instances in Google Compute Engine has occurred. An attacker who has already gained initial access may try to create GPU-based VM instances with goal mining cryptocurrency.
Triage and response
- Determine if
{{@usr.name}}
should be creating the VM instances. - If the action is legitimate, consider including the user in a suppression list. See this article on Best practices for creating detection rules with Datadog Cloud SIEM for more information.
- If the results of the triage indicate that an attacker has taken the action, begin your company’s incident response process and an investigation.