// MITRE ATT&CK

T1499.003 · Application Exhaustion Flood

🎯 Impact WindowsIaaSLinuxmacOS Sub-technique

Sub-technique of T1499 · Endpoint Denial of Service.

Adversaries may target resource intensive features of applications to cause a denial of service (DoS), denying availability to those applications. For example, specific features in web applications may be highly resource intensive. Repeated requests to those features may be able to exhaust system re...

How to detect & mitigate it

Detecting Application Exhaustion Flood starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.