1200KM / detection
T1498.002 Reflection Amplification — Detection Rules
Detection workspace for T1498.002 Reflection Amplification: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0408 Detection Strategy for Reflection Amplification DoS (T1498.002)
AN1140 Analytic 1140
Outbound spoofed traffic to known amplification protocols (e.g., DNS, NTP, Memcached) combined with abnormal network traffic volume targeting remote reflectors, resulting in disproportionate traffic returned to a victim
AN1141 Analytic 1141
Spoofed outbound packets sent to amplification services from command-line tools or scripts, combined with abnormal outbound packet volume on known reflector ports
AN1142 Analytic 1142
Command-line initiated UDP traffic bursts to external reflection amplification ports using built-in scripting or binaries with network anomalies
AN1143 Analytic 1143
Cloud-hosted VM or container generates spoofed UDP requests to third-party services on known amplifier ports, with high outbound-to-inbound traffic ratios in VPC Flow Logs
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1498.002 simulation workspace
- Command Execution · DC0064
- Firewall Rule Modification · DC0051
- Host Status · DC0018
- Network Connection Creation · DC0082
- Network Traffic Flow · DC0078
- Process Creation · DC0032
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.