{"id":"T1499.001","name":"OS Exhaustion Flood","url":"https://attack.mitre.org/techniques/T1499/001","tactics":["impact"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0356","stix_id":"x-mitre-detection-strategy--bdf67026-8adb-41da-9a58-c9acba4da1f3","name":"Endpoint DoS via OS Exhaustion Flood Detection Strategy","url":"https://attack.mitre.org/detectionstrategies/DET0356","analytics":[{"id":"AN1012","stix_id":"x-mitre-analytic--cecfe3bc-525a-431e-8ee1-5133ab8ce79c","name":"Analytic 1012","description":"Burst of incomplete TCP handshakes (e.g., SYN floods) or uncorrelated ACK packets targeting the state table resulting in OS resource exhaustion.","url":"https://attack.mitre.org/detectionstrategies/DET0356#AN1012","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Microsoft-Windows-TCPIP","channel":"Connection queue overflow or failure to allocate TCP state object","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"wineventlog-microsoft-windows-tcpip"},{"name":"NSM:Firewall","channel":"High rate of inbound TCP SYN or ACK packets with missing 3-way handshake completion","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-firewall"}],"mutable_elements":[{"field":"TimeWindow","description":"Threshold for burst traffic over short period (e.g., 30s - 2min)"},{"field":"ConnectionRateThreshold","description":"SYN/ACK packet rate threshold that triggers investigation"},{"field":"ProcessParentCheck","description":"Whether parent process of flooding tool is a known admin shell or unexpected context"}],"live":true,"detection_strategies":["DET0356"],"techniques":["T1499.001"]},{"id":"AN1013","stix_id":"x-mitre-analytic--fde025ac-a180-472c-a9b5-b4fa1e97cc75","name":"Analytic 1013","description":"Flood of spoofed SYN or ACK packets causing exhaustion of OS TCP state table, potentially via user-space utilities or kernel-level DoS agents.","url":"https://attack.mitre.org/detectionstrategies/DET0356#AN1013","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"Invocation of packet generation tools (e.g., hping3, nping) or fork bombs","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"High volumes of SYN/ACK packets with unacknowledged TCP handshakes","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"},{"name":"NSM:Flow","channel":"TCP: possible SYN flood or backlog limit exceeded","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"AmplificationThreshold","description":"Volume of fake TCP requests before OS begins degradation"},{"field":"Interface","description":"Which network interface is being targeted or impacted"}],"live":true,"detection_strategies":["DET0356"],"techniques":["T1499.001"]},{"id":"AN1014","stix_id":"x-mitre-analytic--4db0f97c-a0c4-4c96-af56-86c6b227ea42","name":"Analytic 1014","description":"Adversary tool/script issuing mass SYN/ACK floods that degrade OS responsiveness and interrupt service response on macOS endpoints.","url":"https://attack.mitre.org/detectionstrategies/DET0356#AN1014","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"network stack resource exhaustion, tcp_accept queue overflow, repeated resets","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"Execution of flooding tools or compiled packet generators","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"},{"name":"NSM:Firewall","channel":"Anomalous TCP SYN or ACK spikes from specific source or interface","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-firewall"}],"mutable_elements":[{"field":"SystemLoadThreshold","description":"Observed CPU/network degradation level that triggers response"},{"field":"ToolExecutionPath","description":"Where DoS tools are commonly dropped or compiled"}],"live":true,"detection_strategies":["DET0356"],"techniques":["T1499.001"]}],"live":true,"version":"1.0","techniques":["T1499.001"]}],"sigma_rules":[{"id":"f14719ce-d3ab-4e25-9ce6-2899092260b0","title":"NTFS Vulnerability Exploitation","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-01-11","modified":"2022-12-25","description":"This the exploitation of a NTFS vulnerability as reported without many details via Twitter","references":["https://twitter.com/jonasLyk/status/1347900440000811010","https://twitter.com/wdormann/status/1347958161609809921","https://www.bleepingcomputer.com/news/security/windows-10-bug-corrupts-your-hard-drive-on-seeing-this-files-icon/"],"logsource":{"product":"windows","service":"system"},"tags":["attack.impact","attack.t1499.001"],"path":"rules/windows/builtin/system/ntfs/win_system_ntfs_vuln_exploit.yml","techniques":["T1499.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}