Loading interactive filters…
1200KM / detection
T1499 Endpoint Denial of Service — Detection Rules
Detection workspace for T1499 Endpoint Denial of Service: 1 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.
Source-backed rule directory
Atlas deterministic concepts
T1499 Endpoint Denial of Service
COUNT(request_or_connection BY source, 1m) >= threshold AND service_error_or_unavailable = true -> ALERT
Anomaly models
Service or system availability disrupted — T1499 Endpoint Denial of Service
Comparison unit: service metrics and request stream.
Expected behavior: request rate, latency, error ratio, and availability stay within operating ranges.
Deviation: rate tail event, abrupt level shift, and synchronized error increase.
ATT&CK analytic guidance
Excessive resource exhaustion or service crash induced by processes launched by users or scripts that rapidly consume CPU/memory or attempt malformed service interactions.
Malicious script or binary causes repeated kernel panics, OOM kills, or systemd service restarts targeting services like nginx, httpd, sshd.
Adversary launches high-entropy process or malformed app bundle causing repeated application crashes and system slowdowns.
Instance enters degraded/unhealthy state due to abnormal process load or memory exhaustion, often caused by automation or script-based attacks.
Container orchestrator logs show crashlooping pods, repeated resource exhaustion, or malicious binaries with infinite loops consuming systemd/cgroup limits.
Connected ecosystem references
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.