Detecting Coin Miners with Palo Alto Networks NGFW
ID: a28d5e3d-6816-5a0c-bf01-2eaf3ab5d54a
STIX ID: report--a28d5e3d-6816-5a0c-bf01-2eaf3ab5d54a
Feed Name: Expel Blog
Date Published: 2022-06-30
Date Updated: 2026-04-27
Author: Myles Satterfield; Brian Bahtiarian; Tucker Moran
This post details how Expel detects and investigates cryptojacking incidents using Palo Alto Networks NGFW and automated Ruxie actions: it walks through a CoinMiner alert, netflow and PCAP evidence showing json-rpc traffic to a mining pool (example IP 45.9.148.21), and provides mitigations such as patching public apps, protecting cloud keys, and monitoring for json-rpc/mining-pool connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
