{"id":"T1499.002","name":"Service Exhaustion Flood","url":"https://attack.mitre.org/techniques/T1499/002","tactics":["impact"],"platforms":["Windows","IaaS","Linux","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0173","stix_id":"x-mitre-detection-strategy--1a45b10a-c410-4212-8018-7c00bb292dab","name":"Detection Strategy for Endpoint DoS via Service Exhaustion Flood","url":"https://attack.mitre.org/detectionstrategies/DET0173","analytics":[{"id":"AN0489","stix_id":"x-mitre-analytic--8c03988c-3387-48e4-8013-7b9d223b8911","name":"Analytic 0489","description":"High-frequency, repetitive service requests (e.g., HTTP, TLS renegotiation) originating from a single or small set of source IPs targeting endpoint web services or application ports, leading to exhaustion of CPU or memory on targeted Windows services.","url":"https://attack.mitre.org/detectionstrategies/DET0173#AN0489","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Application","channel":"Unexpected spikes in request volume, application-level errors, or thread pool exhaustion in web or API logs","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"wineventlog-application"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"Windows:perfmon","channel":"Sustained CPU/memory exhaustion by service process (e.g., w3wp.exe)","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"windows-perfmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Defines burst threshold (e.g., 1 min, 5 min) for connection spikes"},{"field":"TargetServicePort","description":"Specific ports/services likely to be abused (e.g., 80, 443, 8080)"},{"field":"CPUThreshold","description":"Level of sustained CPU usage considered anomalous for a given service"}],"live":true,"detection_strategies":["DET0173"],"techniques":["T1499.002"]},{"id":"AN0490","stix_id":"x-mitre-analytic--c7752951-1077-478d-9511-df852cba6b28","name":"Analytic 0490","description":"Excessive inbound HTTP or TLS connections to services such as Apache or Nginx, causing worker thread exhaustion or segmentation faults.","url":"https://attack.mitre.org/detectionstrategies/DET0173#AN0490","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"High frequency of accept(), read(), or SSL_read() syscalls tied to nginx/apache processes","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"Sudden spike in incoming flows to web service ports from single/multiple IPs","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"},{"name":"linux:syslog","channel":"Repetitive HTTP 408, 500, or 503 errors logged within short timeframe","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"ErrorCodeWindow","description":"Tunable count of specific HTTP error codes in timeframe"},{"field":"ConnectionRateThreshold","description":"Defines number of connections per second considered anomalous"}],"live":true,"detection_strategies":["DET0173"],"techniques":["T1499.002"]},{"id":"AN0491","stix_id":"x-mitre-analytic--00bf6b2e-444a-4a83-aafd-43bc8eea4594","name":"Analytic 0491","description":"Flood of incoming TLS or HTTP(S) connections to macOS-hosted services (e.g., MAMP, Apache), causing high CPU usage and system unresponsiveness.","url":"https://attack.mitre.org/detectionstrategies/DET0173#AN0491","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Web service process (e.g., httpd) entering crash loop or consuming excessive CPU","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Rapid incoming TLS handshakes or HTTP requests in quick succession","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"TLSHandshakeRate","description":"Number of renegotiations per minute considered suspicious"},{"field":"ServiceCrashFrequency","description":"Threshold of crashes before alerting on instability"}],"live":true,"detection_strategies":["DET0173"],"techniques":["T1499.002"]},{"id":"AN0492","stix_id":"x-mitre-analytic--7dbd928f-da93-4cbf-af73-ac5987a7858a","name":"Analytic 0492","description":"Automated or scripted HTTP/TLS flooding from one VM or cloud instance against another service, exploiting compute-based billing or exhaustion of service infrastructure.","url":"https://attack.mitre.org/detectionstrategies/DET0173#AN0492","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"AuthorizeSecurityGroupIngress","data_component":"DC0051","data_component_name":"Firewall Rule Modification","log_source_slug":"aws-cloudtrail"},{"name":"AWS:VPCFlowLogs","channel":"Unusual volume of inbound packets from single source across short time interval","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"aws-vpcflowlogs"},{"name":"AWS:CloudWatch","channel":"Sustained spike in CPU usage on EC2 instance with web service role","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"aws-cloudwatch"}],"mutable_elements":[{"field":"VPCFlowBurstRate","description":"Threshold for traffic burst on target service port"},{"field":"EC2CPUThreshold","description":"Compute saturation level for alerting (e.g., >90% for 3 minutes)"}],"live":true,"detection_strategies":["DET0173"],"techniques":["T1499.002"]}],"live":true,"version":"1.0","techniques":["T1499.002"]}],"sigma_rules":[],"kev_cves":[{"cveID":"CVE-2022-26258","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2021-45382","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}