T1499 Endpoint Denial of Service
Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users. Endpoint DoS can be performed by exhausting the system resources those services are hosted on or exploiting the system to cause a persistent crash condition. Example services include websites, email services, DNS, and web-based applications. Adversaries have been observed…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Audit CVE Eventcriticaltest · windows
- Apache Segmentation Faulthightest · apache
- NTFS Vulnerability Exploitationhightest · windows
- Nginx Core Dumphightest · nginx
- CVE-2024-49113 Exploitation Attempt - LDAP Nightmarehighexperimental · windows
- LSASS Crash Via Netlogon Stack Buffer Overflow - CVE-2026-41089highexperimental · windows
- Potential Abuse of Linux Magic System Request Keymediumexperimental · linux
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.