Techniques › T1499.001 › AN1013
AN1013 Analytic 1013
Linux · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Flood of spoofed SYN or ACK packets causing exhaustion of OS TCP state table, potentially via user-space utilities or kernel-level DoS agents.</p>
- Detects
- T1499.001 OS Exhaustion Flood
- Part of
- DET0356 Endpoint DoS via OS Exhaustion Flood Detection Strategy
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| auditd:SYSCALL | Invocation of packet generation tools (e.g., hping3, nping) or fork bombs | DC0032 Process Creation |
| NSM:Flow | High volumes of SYN/ACK packets with unacknowledged TCP handshakes | DC0078 Network Traffic Flow |
| NSM:Flow | TCP: possible SYN flood or backlog limit exceeded | DC0018 Host Status |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
AmplificationThreshold | Volume of fake TCP requests before OS begins degradation |
Interface | Which network interface is being targeted or impacted |