Techniques › T1498 › T1498.001
T1498.001 Direct Network Flood
impact — Windows, IaaS, Linux, macOS · attack.mitre.org · JSON
1
MITRE detection strategy
4
analytics
0
Sigma rules tagged attack.t1498.001
1
KEV CVEs mapped here
<p>Adversaries may attempt to cause a denial of service (DoS) by directly sending a high-volume of network traffic to a target. This DoS attack may also reduce the availability and functionality of the targeted system(s) and network. Direct Network Floods are when one or more systems are used to send a high-volume of network packets towards the targeted service's network. Almost any network protocol may be used for flooding. Stateless protocols such as UDP or ICMP are commonly used but stateful protocols such as TCP can be used as well.</p><p>Botnets are commonly used to conduct network flooding attacks against networks and services. Large botnets can generate a significant amount of traffic from systems spread across the global Internet. Adversaries may have the resources to build out and control their own botnet infrastructure or may rent time on an existing botnet to conduct an attack. In some of the worst cases for distributed DoS (DDoS), so many systems are used to generate the flood that each one only needs to send out a small amount of traffic to produce enough volume to saturate the target network. In such circumstances, distinguishing DDoS traffic from legitimate clients becomes exceedingly difficult. Botnets have been used in some of the most high-profile DDoS flooding attacks, such as the 2012 series of incidents that targeted major US banks.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2024-45195 | Apache OFBiz | secondary impact | Mapped | 2025-02-04 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0343 Direct Network Flood Detection across IaaS, Linux, Windows, and macOS v1.0
AN0969 WindowsHigh-volume packet generation by local processes (e.g., PowerShell, cmd, curl.exe) or network service processes resulting in excessive outbound traffic over short time window, correlated with abnormal resource usage or degraded host responsiveness.Tunable:
PacketRateThresholdTimeWindowAN0970 LinuxKernel or userland processes generating high-rate network traffic (ICMP, UDP, TCP SYN) beyond expected interface throughput or user behavior norms.Tunable:SyscallBurstCountUserContextAN0971 macOSExcessive outbound traffic viaping,curl, or custom scripts indicating flooding behavior, especially with no UI context or user interaction.Tunable:BurstTimeWindowAN0972 IaaSVM or cloud instance generating anomalously high network egress targeting same destination IP or service, especially using stateless protocols.AWS:VPCFlowLogssource instance sends large volume of traffic in short window→ DC0078 Network Traffic FlowTunable:InstanceTrafficThresholdProtocolType
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1498.001
No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content. 1 actively exploited CVE maps here.
Rules tagged at the parent level (attack.t1498) 3
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Leo Tsaousis (@laripping)
· 2024-03-26 · logsource: product=kubernetes category=application service=audit · 40967487-139b-4811-81d9-c9767a92aa5a
Detects the removal of a deployment from a Kubernetes cluster.
This could indicate disruptive activity aiming to impact business operations.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · 7cded4b3-f09e-405a-b96f-24248433ba44
Detects instances where an NTP service on an OpenCanary node has had a NTP monlist request.
Author: Florian Roth (Nextron Systems)
· 2022-02-25 (modified 2023-02-08) · logsource: product=windows category=process_creation · 999e8307-a775-4d5f-addc-4855632335be
Detects command line patterns used by BlackByte ransomware in different operations