Endpoint Denial of Service T1499

Tactic: Impact

Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users. Endpoint DoS can be performed by exhausting the system resources those services are hosted on or exploiting the system to cause a persistent crash condition. Example services include websites, email services, DNS, and web-based applications. Adversaries have been observed conducting DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.

Events covered

13 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 47 rules share fields, values, and exclusions.

Fields filtered most (77 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
DeviceEventClassID6ne 4, eq 2asc, audit, campaigns, hsc
DeviceProduct6eq 6X Series
DeviceVendor6eq 6Vectra Networks
EventType4eq 3, in 1DetectionSummaryEvent, application.integration.rate_limit_exceeded, core.concurrency.org.limit.violation, errorlog, intrusionevent
Provider_Name4eq 4application error, audit-cve, microsoft-windows-audit-cve, ntfs
sourcetype4eq 3, in 1auditd, cisco:sfw:estreamer, ollama:server, vmw-syslog, vmware:esxlog*
Status3eq 3429, deny, offline
triaged3ne 3True
Category2in 2BOTNET ACTIVITY, COMMAND & CONTROL, EXFILTRATION
aws::errorCode2is_null 2
aws::eventName2in 2FailoverDBCluster, FailoverGlobalCluster, RebootDBCluster, RebootDBInstance, RebootDBShardGroup
aws::eventSource2eq 2rds.amazonaws.com
data.description2eq 2dynamic client registration, guardian - second factor sms sent
data.type2eq 2gd_send_sms, sapi
data_stream.dataset2eq 1, in 1network_traffic.dns, okta.system, zeek.dns

Top indicator values (130 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
DeviceProducteq
X Series
67
DeviceVendoreq
Vectra Networks
67
DeviceEventClassIDne
asc
44
DeviceEventClassIDne
audit
44
DeviceEventClassIDne
campaigns
44
DeviceEventClassIDne
health
44
DeviceEventClassIDne
hsc
44
triagedne
True
33
Categoryin
BOTNET ACTIVITY
22
Categoryin
COMMAND & CONTROL
22
Categoryin
EXFILTRATION
22
Categoryin
LATERAL MOVEMENT
22
Categoryin
RECONNAISSANCE
22
Provider_Nameeq
application error
25
aws::eventSourceeq
rds.amazonaws.com
223
levelin
Critical
22
levelin
High
22
typeeq
path
219
AdditionalExtensionscontains
account
1
AppNameeq
lsass.exe
12
AvgUptimelt
99.9
1
Computerin
DC01.simulandlabs.com
1
Computerin
DC02.simulandlabs.com
1
Countgt
5000
13
CriticalCountcross_field_compare
prevCritical
1
Datacontains
lsass.exe
1
Datacontains
wldap32.dll
1
Descriptioncontains
contains a corrupted file record
1
Descriptioncontains
the name of the file is "\"
1
DestinationPorteq
53
1

Exclusions (7 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
AdditionalExtensionscontains
account
1
EventTypein
flow_terminated
1
EventTypein
network_flow
1
data_stream.dataseteq
zeek.connection
1
event.dataseteq
conn
1
event.durationgt
60000000000
1
event.moduleeq
corelight
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 9 rules

Elastic 6 rules

Splunk 5 rules

Kusto 22 rules

Panther 5 rules