AN1434
Analytic 1434
Windows
Executable or script generating large outbound network traffic targeting remote hosts or known amplification ports
WinEventLog:Sysmon
EventCode=3, 22
WinEventLog:Sysmon
EventCode=1
[ThresholdEventVolume]
Number of connections per second that should trigger anomaly logic
[DestinationDiversity]
Count of unique destination IPs or ports
AN1435
Analytic 1435
Linux
Flooding tools like hping3 or nping sending large volumes of packets across multiple ports or IPs
auditd:SYSCALL
Execution of network stress tools or anomalies in socket/syscall behavior
NSM:Flow
High volume flows with incomplete TCP sessions or single-packet bursts
[PacketRateThreshold]
Packets per second beyond normal behavior