kevmap

TechniquesT1499.001 › AN1013

AN1013 Analytic 1013

Linux · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Flood of spoofed SYN or ACK packets causing exhaustion of OS TCP state table, potentially via user-space utilities or kernel-level DoS agents.</p>
Detects
T1499.001 OS Exhaustion Flood
Part of
DET0356 Endpoint DoS via OS Exhaustion Flood Detection Strategy

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
auditd:SYSCALLInvocation of packet generation tools (e.g., hping3, nping) or fork bombsDC0032 Process Creation
NSM:FlowHigh volumes of SYN/ACK packets with unacknowledged TCP handshakesDC0078 Network Traffic Flow
NSM:FlowTCP: possible SYN flood or backlog limit exceededDC0018 Host Status

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
AmplificationThresholdVolume of fake TCP requests before OS begins degradation
InterfaceWhich network interface is being targeted or impacted