Network Denial of Service T1498
Tactic: Impact
Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users. Network DoS can be performed by exhausting the network bandwidth services rely on. Example resources include specific websites, email services, DNS, and web-based applications. Adversaries have been observed conducting network DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.
Events covered
2 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Security-Auditing | Event ID 4688 | A new process has been created. |
Authoring guide
Patterns shared across the 46 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (61 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (115 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 3 rules
- Deployment Deleted From Kubernetes Cluster
- OpenCanary - NTP Monlist Request
- Potential BlackByte Ransomware Activity
Elastic 5 rules
- Nping Process Activity
- Possible Okta DoS Attack
- Spike in Firewall Denies
- Spike in host-based traffic
- Spike in Network Traffic
Splunk 7 rules
- Detect ARP Poisoning
- Detect IPv6 Network Infrastructure Threats
- Detect Port Security Violation
- Detect Rogue DHCP Server
- Detect Traffic Mirroring
- Large Volume of DNS ANY Queries
- Ollama Excessive API Requests
Kusto 29 rules
- Apache - Multiple server errors from single IP
- Apache - Request from private IP
- Azure secure score admin MFA
- Cisco ASA - average attack detection rate increase
- Cisco ASA - threat detection message fired
- DDoS attack detected
- DDoS Attack IP Addresses - Percent Threshold
- DDoS Attack IP Addresses - PPS Threshold
- Detect instances of multiple server errors occurring within a brief period of time (ASIM Web Session)
- Infoblox - Data Exfiltration Attack
- Infoblox - High Threat Level Query Not Blocked Detected
- Infoblox - Many High Threat Level Queries From Single Host Detected
- Infoblox - Many High Threat Level Single Query Detected
- Infoblox - Many NXDOMAIN DNS Responses Detected
- Infoblox - SOC Insight Detected - API Source
- Infoblox - SOC Insight Detected - API Source
- Infoblox - SOC Insight Detected - CDC Source
- Infoblox - SOC Insight Detected - CDC Source
- Infoblox - TI - CommonSecurityLog Match Found - MalwareC2
- Infoblox - TI - InfobloxCDC Match Found - Lookalike Domains
- Infoblox - TI - Syslog Match Found - URL
- NGINX - Multiple server errors from single IP address
- Oracle - Multiple server errors from single IP
- Tomcat - Multiple server errors from single IP address
- Tomcat - Server errors after multiple requests from same IP
- VMware SD-WAN Edge - Device Congestion Alert - Packet Drops
- VMware SD-WAN Edge - Network Anomaly Detection - Potential Fragmentation Attack
- VMware SD-WAN Edge - Network Anomaly Detection - RPF Check Failure
- Votiro - File Blocked from Connector