1200KM / detection
T1499.002 Service Exhaustion Flood — Detection Rules
Detection workspace for T1499.002 Service Exhaustion Flood: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0173 Detection Strategy for Endpoint DoS via Service Exhaustion Flood
AN0489 Analytic 0489
High-frequency, repetitive service requests (e.g., HTTP, TLS renegotiation) originating from a single or small set of source IPs targeting endpoint web services or application ports, leading to exhaustion of CPU or memory on targeted Windows services.
AN0490 Analytic 0490
Excessive inbound HTTP or TLS connections to services such as Apache or Nginx, causing worker thread exhaustion or segmentation faults.
AN0491 Analytic 0491
Flood of incoming TLS or HTTP(S) connections to macOS-hosted services (e.g., MAMP, Apache), causing high CPU usage and system unresponsiveness.
AN0492 Analytic 0492
Automated or scripted HTTP/TLS flooding from one VM or cloud instance against another service, exploiting compute-based billing or exhaustion of service infrastructure.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1499.002 simulation workspace
- Application Log Content · DC0038
- Firewall Rule Modification · DC0051
- Host Status · DC0018
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- Process Access · DC0035
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.