{"id":"T1498","name":"Network Denial of Service","url":"https://attack.mitre.org/techniques/T1498","tactics":["impact"],"platforms":["Windows","IaaS","Linux","macOS","Containers"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0518","stix_id":"x-mitre-detection-strategy--8103189e-83c8-4246-a56c-193e19c98182","name":"Behavioral Detection of T1498 – Network Denial of Service Across Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0518","analytics":[{"id":"AN1434","stix_id":"x-mitre-analytic--0eff49de-834e-42d3-9a7a-3ac032aa9836","name":"Analytic 1434","description":"Executable or script generating large outbound network traffic targeting remote hosts or known amplification ports","url":"https://attack.mitre.org/detectionstrategies/DET0518#AN1434","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ThresholdEventVolume","description":"Number of connections per second that should trigger anomaly logic"},{"field":"DestinationDiversity","description":"Count of unique destination IPs or ports"}],"live":true,"detection_strategies":["DET0518"],"techniques":["T1498"]},{"id":"AN1435","stix_id":"x-mitre-analytic--1578f892-0644-4974-bf55-9abb802612fa","name":"Analytic 1435","description":"Flooding tools like hping3 or nping sending large volumes of packets across multiple ports or IPs","url":"https://attack.mitre.org/detectionstrategies/DET0518#AN1435","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"Execution of network stress tools or anomalies in socket/syscall behavior","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"High volume flows with incomplete TCP sessions or single-packet bursts","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"PacketRateThreshold","description":"Packets per second beyond normal behavior"}],"live":true,"detection_strategies":["DET0518"],"techniques":["T1498"]}],"live":true,"version":"1.0","techniques":["T1498"]}],"sigma_rules":[{"id":"40967487-139b-4811-81d9-c9767a92aa5a","title":"Deployment Deleted From Kubernetes Cluster","author":"Leo Tsaousis (@laripping)","status":"test","level":"low","date":"2024-03-26","modified":null,"description":"Detects the removal of a deployment from a Kubernetes cluster.\nThis could indicate disruptive activity aiming to impact business operations.\n","references":["https://microsoft.github.io/Threat-Matrix-for-Kubernetes/techniques/Data%20destruction/"],"logsource":{"product":"kubernetes","category":"application","service":"audit"},"tags":["attack.t1498","attack.impact"],"path":"rules/application/kubernetes/audit/kubernetes_audit_deployment_deleted.yml","techniques":["T1498"],"cves":[]},{"id":"7cded4b3-f09e-405a-b96f-24248433ba44","title":"OpenCanary - NTP Monlist Request","author":"Security Onion Solutions","status":"test","level":"high","date":"2024-03-08","modified":null,"description":"Detects instances where an NTP service on an OpenCanary node has had a NTP monlist request.","references":["https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration","https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52"],"logsource":{"product":"opencanary","category":"application"},"tags":["attack.impact","attack.t1498"],"path":"rules/application/opencanary/opencanary_ntp_monlist.yml","techniques":["T1498"],"cves":[]},{"id":"999e8307-a775-4d5f-addc-4855632335be","title":"Potential BlackByte Ransomware Activity","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-02-25","modified":"2023-02-08","description":"Detects command line patterns used by BlackByte ransomware in different operations","references":["https://redcanary.com/blog/blackbyte-ransomware/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.impact","attack.stealth","attack.t1485","attack.t1498","attack.t1059.001","attack.t1140","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Malware/BlackByte/proc_creation_win_malware_blackbyte_ransomware.yml","techniques":["T1485","T1498","T1059.001","T1140"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2025-6543","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2024-11120","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-49897","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-47565","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-1389","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2022-0028","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-22205","state":"mapped","mapping_types":["primary_impact","secondary_impact"]},{"cveID":"CVE-2019-0708","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}