Endpoint Denial of Service: Application Exhaustion Flood T1499.003

Tactic: Impact

Adversaries may target resource intensive features of applications to cause a denial of service (DoS), denying availability to those applications. For example, specific features in web applications may be highly resource intensive. Repeated requests to those features may be able to exhaust system resources and deny access to the application or the server itself.

Authoring guide

Patterns shared across the 2 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.

Fields filtered most (3 distinct)

The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.

FieldRulesHowSample values
EventType1in 1application.integration.rate_limit_exceeded, core.concurrency.org.limit.violation, system.org.rate_limit.violation
action1in 1bulk_session_reset_by_admin, user_session_invalidated, user_session_reset_by_admin
data_stream.dataset1eq 1okta.system

Top indicator values (8 distinct)

Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.

FieldKindValueRules (here)Corpus reach
EventTypein
application.integration.rate_limit_exceeded
1
EventTypein
core.concurrency.org.limit.violation
1
EventTypein
system.org.rate_limit.violation
1
EventTypein
system.org.rate_limit.warning
1
actionin
bulk_session_reset_by_admin
1
actionin
user_session_invalidated
1
actionin
user_session_reset_by_admin
1
data_stream.dataseteq
okta.system
148

Rules under this technique

Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.

Platform (all)
Domain (all)

Elastic 1 rule

Panther 1 rule