1200KM / detection
T1498.001 Direct Network Flood — Detection Rules
Detection workspace for T1498.001 Direct Network Flood: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0343 Direct Network Flood Detection across IaaS, Linux, Windows, and macOS
AN0969 Analytic 0969
High-volume packet generation by local processes (e.g., PowerShell, cmd, curl.exe) or network service processes resulting in excessive outbound traffic over short time window, correlated with abnormal resource usage or degraded host responsiveness.
AN0970 Analytic 0970
Kernel or userland processes generating high-rate network traffic (ICMP, UDP, TCP SYN) beyond expected interface throughput or user behavior norms.
AN0971 Analytic 0971
Excessive outbound traffic via `ping`, `curl`, or custom scripts indicating flooding behavior, especially with no UI context or user interaction.
AN0972 Analytic 0972
VM or cloud instance generating anomalously high network egress targeting same destination IP or service, especially using stateless protocols.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1498.001 simulation workspace
- Host Status · DC0018
- Network Connection Creation · DC0082
- Network Traffic Flow · DC0078
- Process Creation · DC0032
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.