1200KM / detection
T1499.003 Application Exhaustion Flood — Detection Rules
Detection workspace for T1499.003 Application Exhaustion Flood: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0415 Application Exhaustion Flood Detection Across Platforms
AN1165 Analytic 1165
Repeated invocation of high-resource application endpoints or GUI components causing CPU and memory spikes, logged as elevated request volumes, prolonged handle locks, or frequent crash recoveries.
AN1166 Analytic 1166
Automated scripts or repeated CLI/API requests that trigger application backends to consume high CPU or memory (e.g., Apache/PHP, MySQL, mail servers), resulting in syslog errors and excessive process spawning.
AN1167 Analytic 1167
Repetitive triggering of GUI or backend application workflows that cause increased CPU/memory usage, logged in unified logs as spin reports or crash dumps.
AN1168 Analytic 1168
Automated abuse of cloud-hosted applications (e.g., web apps, REST endpoints, internal APIs) causing compute exhaustion, high 5xx error rates, or frequent autoscaling triggers logged in app insights or cloudwatch.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1499.003 simulation workspace
- Application Log Content · DC0038
- Cloud Service Metadata · DC0070
- Host Status · DC0018
- Network Traffic Content · DC0085
- Process Creation · DC0032
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.