XMRig Cryptominer Masquerading as systemd-logind on Linux
Detects the execution of the XMRig cryptominer masquerading as the legitimate systemd-logind service. The rule identifies suspicious command-line arguments indicative of mining activity, or instances where systemd-logind is spawned from unauthorized parent processes such as shell interpreters, container engines, or nsenter, which is often characteristic of post-exploitation activity like privileged Docker container escapes.
Sigma

