1200KM / detection
T1499.004 Application or System Exploitation — Detection Rules
Detection workspace for T1499.004 Application or System Exploitation: 3 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Apache Segmentation Fault · test · high · {"service":"apache","definition":"Requirements: Must be able to collect the error.log file"}
- Nginx Core Dump · test · high · {"service":"nginx"}
- Audit CVE Event · test · critical · {"product":"windows","service":"application"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0304 Detection Strategy for Endpoint DoS via Application or System Exploitation
AN0850 Analytic 0850
Exploitation of system or application vulnerability (e.g., CVE-based exploit) followed by service crash, restart, or repeated failure within a short time frame, impacting application/system availability.
AN0851 Analytic 0851
User or remote input triggers application crash or segmentation fault (e.g., SIGSEGV) with service recovery attempts, observed via audit logs and systemd journaling.
AN0852 Analytic 0852
Application crash or repeated restart cycle triggered by malformed input or exploit file, observed via unified logs and process crash monitoring.
AN0853 Analytic 0853
Cloud workload exploitation leads to repeated container, service, or VM termination/restart, typically associated with CVE-based crash triggers or fuzzed payloads.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1499.004 simulation workspace
- Application Log Content · DC0038
- Instance Stop · DC0089
- Network Traffic Content · DC0085
- Process Creation · DC0032
- Process Termination · DC0033
- Service Creation · DC0060
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.