kevmap

TechniquesT1498.002 › AN1141

AN1141 Analytic 1141

Linux · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Spoofed outbound packets sent to amplification services from command-line tools or scripts, combined with abnormal outbound packet volume on known reflector ports</p>
Detects
T1498.002 Reflection Amplification
Part of
DET0408 Detection Strategy for Reflection Amplification DoS (T1498.002)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
auditd:SYSCALLExecution of spoofing tools (e.g., hping3, nping, scapy) sending UDP packets to known amplifier portsDC0064 Command Execution
NSM:FlowOutbound UDP floods targeting common reflection services with spoofed IP headersDC0078 Network Traffic Flow
sar:networkOutbound network saturation with minimal process activityDC0018 Host Status

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TimeWindowSliding interval for detecting volumetric anomalies
AmplificationProtocolListWhich protocols to watch (e.g., DNS, NTP, SSDP, Memcached)
ExecutionToolListSet of binaries and scripts commonly abused for spoofing/reflection