// MITRE ATT&CK
T1499 · Endpoint Denial of Service
Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users. Endpoint DoS can be performed by exhausting the system resources those services are hosted on or exploiting the system to cause a persistent crash condition. Example services i...
¿Cómo detectarlo y mitigarlo?
La detección de Endpoint Denial of Service parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Sub-técnicas (4)
T1499.001
OS Exhaustion Flood T1499.002
Service Exhaustion Flood T1499.003
Application Exhaustion Flood T1499.004
Application or System Exploitation
OS Exhaustion Flood T1499.002
Service Exhaustion Flood T1499.003
Application Exhaustion Flood T1499.004
Application or System Exploitation
Técnicas relacionadas
T1561.002
Disk Structure Wipe T1498.001
Direct Network Flood T1491.002
External Defacement T1499.001
OS Exhaustion Flood T1485.001
Lifecycle-Triggered Deletion T1496.003
SMS Pumping T1499.003
Application Exhaustion Flood T1561
Disk Wipe
Disk Structure Wipe T1498.001
Direct Network Flood T1491.002
External Defacement T1499.001
OS Exhaustion Flood T1485.001
Lifecycle-Triggered Deletion T1496.003
SMS Pumping T1499.003
Application Exhaustion Flood T1561
Disk Wipe
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.