1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1499 Endpoint Denial of Service — Detection Rules

Detection workspace for T1499 Endpoint Denial of Service: 1 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.

Source-backed rule directory

  • Potential Abuse of Linux Magic System Request Key · experimental · medium · {"product":"linux","service":"auditd","definition":"Required auditd configuration:\n-w /proc/sysrq-trigger -p wa -k sysrq\n-w /proc/sys/kernel/sysrq -p wa -k sysrq\n"}

Atlas deterministic concepts

T1499 Endpoint Denial of Service

COUNT(request_or_connection BY source, 1m) >= threshold AND service_error_or_unavailable = true -> ALERT

Anomaly models

ATT&CK analytic guidance

DET0208 Endpoint Resource Saturation and Crash Pattern Detection Across Platforms

AN0584 Analytic 0584

Excessive resource exhaustion or service crash induced by processes launched by users or scripts that rapidly consume CPU/memory or attempt malformed service interactions.

AN0585 Analytic 0585

Malicious script or binary causes repeated kernel panics, OOM kills, or systemd service restarts targeting services like nginx, httpd, sshd.

AN0586 Analytic 0586

Adversary launches high-entropy process or malformed app bundle causing repeated application crashes and system slowdowns.

AN0587 Analytic 0587

Instance enters degraded/unhealthy state due to abnormal process load or memory exhaustion, often caused by automation or script-based attacks.

AN0588 Analytic 0588

Container orchestrator logs show crashlooping pods, repeated resource exhaustion, or malicious binaries with infinite loops consuming systemd/cgroup limits.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1499 simulation workspace

No reviewed association in this snapshot.

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Connected anomaly research

Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.

Telemetry contracts · Maintained query examples · Validation and blind spots

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.