Network Denial of Service T1498
Tactic: Impact
Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users. Network DoS can be performed by exhausting the network bandwidth services rely on. Example resources include specific websites, email services, DNS, and web-based applications. Adversaries have been observed conducting network DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.
Events covered
2 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Security-Auditing | Event ID 4688 | A new process has been created. |
Authoring guide
These 52 rules share fields, values, and exclusions.
Fields filtered most (74 distinct)
These fields appear most often in rule filters.
Top indicator values (126 distinct)
These values appear most often in rule predicates.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 3 rules
- Deployment Deleted From Kubernetes Cluster
- OpenCanary - NTP Monlist Request
- Potential BlackByte Ransomware Activity
Elastic 6 rules
- Nping Process Activity
- Possible Okta DoS Attack
- Potential DHCP Starvation via High Client MAC Cardinality
- Spike in Firewall Denies
- Spike in host-based traffic
- Spike in Network Traffic
Splunk 7 rules
- Detect ARP Poisoning
- Detect IPv6 Network Infrastructure Threats
- Detect Port Security Violation
- Detect Rogue DHCP Server
- Detect Traffic Mirroring
- Large Volume of DNS ANY Queries
- Ollama Excessive API Requests
Kusto 34 rules
- Apache - Multiple server errors from single IP
- Apache - Request from private IP
- Azure secure score admin MFA
- Cisco ASA - average attack detection rate increase
- Cisco ASA - threat detection message fired
- DDoS attack detected
- DDoS Attack IP Addresses - Percent Threshold
- DDoS Attack IP Addresses - PPS Threshold
- Detect instances of multiple server errors occurring within a brief period of time (ASIM Web Session)
- Infoblox - Data Exfiltration Attack
- Infoblox - High Threat Level Query Not Blocked Detected
- Infoblox - IQ for TD Detected Insights - API Source
- Infoblox - IQ for TD Insight Detected - CDC Source
- Infoblox - Many High Threat Level Queries From Single Host Detected
- Infoblox - Many High Threat Level Single Query Detected
- Infoblox - Many NXDOMAIN DNS Responses Detected
- Infoblox - SOC Insight Detected - API Source
- Infoblox - SOC Insight Detected - CDC Source
- Infoblox - TI - CommonSecurityLog Match Found - MalwareC2
- Infoblox - TI - InfobloxCDC Match Found - Lookalike Domains
- Infoblox - TI - Syslog Match Found - URL
- NGINX - Multiple server errors from single IP address
- Oracle - Multiple server errors from single IP
- Tomcat - Multiple server errors from single IP address
- Tomcat - Server errors after multiple requests from same IP
- UniFi Site Manager: ISP High Latency
- UniFi Site Manager: ISP Packet Loss
- UniFi Site Manager: New WAN issue index recorded
- UniFi Site Manager: New WAN2 (secondary) issue recorded
- UniFi Site Manager: WiFi quality degraded (high TX retry)
- VMware SD-WAN Edge - Device Congestion Alert - Packet Drops
- VMware SD-WAN Edge - Network Anomaly Detection - Potential Fragmentation Attack
- VMware SD-WAN Edge - Network Anomaly Detection - RPF Check Failure
- Votiro - File Blocked from Connector