kevmap

TechniquesT1498.002 › AN1143

AN1143 Analytic 1143

IaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Cloud-hosted VM or container generates spoofed UDP requests to third-party services on known amplifier ports, with high outbound-to-inbound traffic ratios in VPC Flow Logs</p>
Detects
T1498.002 Reflection Amplification
Part of
DET0408 Detection Strategy for Reflection Amplification DoS (T1498.002)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
AWS:CloudTrailCreate egress rule allowing UDP to port 53, 123, 11211DC0051 Firewall Rule Modification
AWS:VPCFlowLogsLarge outbound UDP traffic to multiple public reflector IPsDC0078 Network Traffic Flow
AWS:CloudWatchSudden spike in network output without a corresponding inbound request ratioDC0018 Host Status

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
EgressRulePortsCloud security group rules permitting UDP to reflector protocols
OutboundToInboundRatioRatio threshold to flag traffic as potential reflection behavior
VMInstanceTagContextCloud metadata that can help scope anomalous behavior to development, testing, or external-facing services