// MITRE ATT&CK
T1499.003 · Application Exhaustion Flood
Sub-technique of T1499 · Endpoint Denial of Service.
Adversaries may target resource intensive features of applications to cause a denial of service (DoS), denying availability to those applications. For example, specific features in web applications may be highly resource intensive. Repeated requests to those features may be able to exhaust system re...
How to detect & mitigate it
Detecting Application Exhaustion Flood starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Related techniques
T1561.002
Disk Structure Wipe T1498.001
Direct Network Flood T1491.002
External Defacement T1499.001
OS Exhaustion Flood T1485.001
Lifecycle-Triggered Deletion T1496.003
SMS Pumping T1561
Disk Wipe T1565.001
Stored Data Manipulation
Disk Structure Wipe T1498.001
Direct Network Flood T1491.002
External Defacement T1499.001
OS Exhaustion Flood T1485.001
Lifecycle-Triggered Deletion T1496.003
SMS Pumping T1561
Disk Wipe T1565.001
Stored Data Manipulation
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.