Techniques › T1498 › AN1434
AN1434 Analytic 1434
Windows · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Executable or script generating large outbound network traffic targeting remote hosts or known amplification ports</p>
- Detects
- T1498 Network Denial of Service
- Part of
- DET0518 Behavioral Detection of T1498 – Network Denial of Service Across Platforms
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| WinEventLog:Sysmon | EventCode=3, 22 | DC0082 Network Connection Creation |
| WinEventLog:Sysmon | EventCode=1 | DC0032 Process Creation |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
ThresholdEventVolume | Number of connections per second that should trigger anomaly logic |
DestinationDiversity | Count of unique destination IPs or ports |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2019-0708 | Microsoft Remote Desktop Services | Mapped |
| CVE-2021-22205 | GitLab Community and Enterprise Editions | Mapped |
| CVE-2022-0028 | Palo Alto Networks PAN-OS | Mapped |
| CVE-2023-1389 | TP-Link Archer AX21 | Mapped |
| CVE-2023-47565 | QNAP VioStor NVR | Mapped |
| CVE-2023-49897 | FXC AE1021, AE1021PE | Mapped |
| CVE-2024-11120 | GeoVision Multiple Devices | Mapped |
| CVE-2025-6543 | Citrix NetScaler ADC and Gateway | Mapped |