Network Denial of Service T1498

Tactic: Impact

Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users. Network DoS can be performed by exhausting the network bandwidth services rely on. Example resources include specific websites, email services, DNS, and web-based applications. Adversaries have been observed conducting network DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.

Events covered

2 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 52 rules share fields, values, and exclusions.

Fields filtered most (74 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
DeviceEventClassID7contains 4, eq 2, in 1RPZ, 733100, 733101, 733102, 733103
HttpStatusCode5ge 5, le 5500, 599, 100, 399
MultipleServerErrors5gt 5100, 10
count_5gt 5200, 1
facility5eq 5pm, dhcp_snooping, mirror, port_security, sisf
mnemonic5eq 4, in 1err_disable, cfglog_loggedcmd, dhcp_snooping_untrusted_port, eth_span_session_up, ip_theft
Description4contains 3, eq 1Infoblox, Infoblox - HOST - Policy, Infoblox - URL, MalwareC2, attempted-dos
Active3eq 3true
Category3eq 2, contains 1DDoSMitigationFlowLogs, attempted denial of service, denial of service, detection of a denial of service attack
DomainName3is_not_null 3
HitTime3cross_field_compare 3ExpirationDateTime, TimeGenerated
ThreatLevel_Score3ge 380
CommunicationDirection2is_null 2
CurrentMaxCount2cross_field_compare 2PrevMaxCount
DestinationDnsDomain2is_not_null 2

Top indicator values (126 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
HttpStatusCodege
500
55
HttpStatusCodele
599
55
DeviceEventClassIDcontains
RPZ
44
MultipleServerErrorsgt
100
44
Activeeq
true
370
HitTimecross_field_compare
ExpirationDateTime
33
HitTimecross_field_compare
TimeGenerated
33
ThreatLevel_Scorege
80
33
count_gt
200
35
count_gt
1
28
Categoryeq
DDoSMitigationFlowLogs
22
CurrentMaxCountcross_field_compare
PrevMaxCount
22
ResourceTypeeq
PUBLICIPADDRESSES
22
SyslogMessagecontains
vcf drop
22
facilityeq
pm
22
mnemoniceq
err_disable
22
Actionin
alert
15
Actionin
deny
15
Categorycontains
attempted denial of service
1
Categorycontains
denial of service
1
Categorycontains
detection of a denial of service attack
1
CommandLinecontains
-single
1
CommandLinecontains
do start wordpad.exe /p
1
CommandLinecontains
del c:\windows\system32\taskmgr.exe
1
CommandLinematch
;Set-Service -StartupType Disabled $
1
CommandLinematch
powershell -command "$x...
1
ControlName_seq
AzureSecureScoreAdminMFAV2
1
DNS.message_typeeq
query
12
DataObservedViane
CDC
1
Descriptioncontains
Infoblox
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 3 rules

Elastic 6 rules

Splunk 7 rules

Kusto 34 rules

YARA-L 1 rule

Panther 1 rule