1200KM / detection
T1498 Network Denial of Service — Detection Rules
Detection workspace for T1498 Network Denial of Service: 2 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Deployment Deleted From Kubernetes Cluster · test · low · {"category":"application","product":"kubernetes","service":"audit"}
- OpenCanary - NTP Monlist Request · test · high · {"category":"application","product":"opencanary"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0518 Behavioral Detection of T1498 – Network Denial of Service Across Platforms
AN1434 Analytic 1434
Executable or script generating large outbound network traffic targeting remote hosts or known amplification ports
AN1435 Analytic 1435
Flooding tools like hping3 or nping sending large volumes of packets across multiple ports or IPs
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.