Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0518 — Behavioral Detection of T1498 – Network Denial of Service Across Platforms
DET0518

Behavioral Detection of T1498 – Network Denial of Service Across Platforms

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN1434 Analytic 1434
Windows

Executable or script generating large outbound network traffic targeting remote hosts or known amplification ports

WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Sysmon EventCode=1
[ThresholdEventVolume] Number of connections per second that should trigger anomaly logic
[DestinationDiversity] Count of unique destination IPs or ports
AN1435 Analytic 1435
Linux

Flooding tools like hping3 or nping sending large volumes of packets across multiple ports or IPs

auditd:SYSCALL Execution of network stress tools or anomalies in socket/syscall behavior NSM:Flow High volume flows with incomplete TCP sessions or single-packet bursts
[PacketRateThreshold] Packets per second beyond normal behavior

Detected Techniques

1

Details

MITRE ID
DET0518
STIX ID
x-mitre-detection-strategy--8103189e-83c8-4246-a56c-193e19c98182
Analytics
2
Techniques Detected
1
By Tactic
Impact
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.