kevmap

TechniquesT1499.001 › AN1012

AN1012 Analytic 1012

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Burst of incomplete TCP handshakes (e.g., SYN floods) or uncorrelated ACK packets targeting the state table resulting in OS resource exhaustion.</p>
Detects
T1499.001 OS Exhaustion Flood
Part of
DET0356 Endpoint DoS via OS Exhaustion Flood Detection Strategy

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SysmonEventCode=1DC0032 Process Creation
WinEventLog:Microsoft-Windows-TCPIPConnection queue overflow or failure to allocate TCP state objectDC0018 Host Status
NSM:FirewallHigh rate of inbound TCP SYN or ACK packets with missing 3-way handshake completionDC0085 Network Traffic Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TimeWindowThreshold for burst traffic over short period (e.g., 30s - 2min)
ConnectionRateThresholdSYN/ACK packet rate threshold that triggers investigation
ProcessParentCheckWhether parent process of flooding tool is a known admin shell or unexpected context