{"id":"T1498.001","name":"Direct Network Flood","url":"https://attack.mitre.org/techniques/T1498/001","tactics":["impact"],"platforms":["Windows","IaaS","Linux","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0343","stix_id":"x-mitre-detection-strategy--6e1ea095-9f21-4544-8e9b-4fab2668033e","name":"Direct Network Flood Detection across IaaS, Linux, Windows, and macOS","url":"https://attack.mitre.org/detectionstrategies/DET0343","analytics":[{"id":"AN0969","stix_id":"x-mitre-analytic--0de81d5a-ffba-4eba-915d-c4f4d8b30f9a","name":"Analytic 0969","description":"High-volume packet generation by local processes (e.g., PowerShell, cmd, curl.exe) or network service processes resulting in excessive outbound traffic over short time window, correlated with abnormal resource usage or degraded host responsiveness.","url":"https://attack.mitre.org/detectionstrategies/DET0343#AN0969","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"PacketRateThreshold","description":"Defines the burst threshold (e.g., 10,000 pps) above which activity should be flagged as anomalous."},{"field":"TimeWindow","description":"Duration over which to aggregate and analyze flow volume."}],"live":true,"detection_strategies":["DET0343"],"techniques":["T1498.001"]},{"id":"AN0970","stix_id":"x-mitre-analytic--a94c1081-d66b-4009-95a9-247721fcd394","name":"Analytic 0970","description":"Kernel or userland processes generating high-rate network traffic (ICMP, UDP, TCP SYN) beyond expected interface throughput or user behavior norms.","url":"https://attack.mitre.org/detectionstrategies/DET0343#AN0970","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"connect or sendto system call with burst pattern","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"SyscallBurstCount","description":"Threshold of repeated socket calls within a short interval indicating flood behavior."},{"field":"UserContext","description":"Restrict to non-admin user traffic unless elevated access is detected."}],"live":true,"detection_strategies":["DET0343"],"techniques":["T1498.001"]},{"id":"AN0971","stix_id":"x-mitre-analytic--a82a14f4-6fc9-43b5-b183-68af3cb075a2","name":"Analytic 0971","description":"Excessive outbound traffic via `ping`, `curl`, or custom scripts indicating flooding behavior, especially with no UI context or user interaction.","url":"https://attack.mitre.org/detectionstrategies/DET0343#AN0971","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process created with repeated ICMP or UDP flood behavior","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"sudden burst in outgoing packets from same PID","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"BurstTimeWindow","description":"Tunable range (e.g., 15s, 30s) for detecting packet floods."}],"live":true,"detection_strategies":["DET0343"],"techniques":["T1498.001"]},{"id":"AN0972","stix_id":"x-mitre-analytic--408b2724-079c-4636-9764-52f435726de7","name":"Analytic 0972","description":"VM or cloud instance generating anomalously high network egress targeting same destination IP or service, especially using stateless protocols.","url":"https://attack.mitre.org/detectionstrategies/DET0343#AN0972","platforms":["IaaS"],"log_source_references":[{"name":"AWS:VPCFlowLogs","channel":"source instance sends large volume of traffic in short window","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"aws-vpcflowlogs"},{"name":"AWS:CloudWatch","channel":"NetworkOut spike beyond baseline","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"aws-cloudwatch"}],"mutable_elements":[{"field":"InstanceTrafficThreshold","description":"Alert when egress exceeds normal usage by X%."},{"field":"ProtocolType","description":"Prioritize alerts on stateless protocols such as UDP and ICMP."}],"live":true,"detection_strategies":["DET0343"],"techniques":["T1498.001"]}],"live":true,"version":"1.0","techniques":["T1498.001"]}],"sigma_rules":[],"kev_cves":[{"cveID":"CVE-2024-45195","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}