{"id":"T1499","name":"Endpoint Denial of Service","url":"https://attack.mitre.org/techniques/T1499","tactics":["impact"],"platforms":["Windows","Linux","macOS","Containers","IaaS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0208","stix_id":"x-mitre-detection-strategy--253b632e-c4cb-4207-9b6a-58a35a07d2ea","name":"Endpoint Resource Saturation and Crash Pattern Detection Across Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0208","analytics":[{"id":"AN0584","stix_id":"x-mitre-analytic--3102edb4-6947-4cef-9660-4a35d582a716","name":"Analytic 0584","description":"Excessive resource exhaustion or service crash induced by processes launched by users or scripts that rapidly consume CPU/memory or attempt malformed service interactions.","url":"https://attack.mitre.org/detectionstrategies/DET0208#AN0584","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Application","channel":"Service crash, unhandled exception, or application hang warnings for critical services (e.g., IIS, DNS, SQL Server)","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"wineventlog-application"},{"name":"WinEventLog:System","channel":"System shutdowns due to bugcheck (Event ID 1001) or watchdog timer expirations","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"wineventlog-system"}],"mutable_elements":[{"field":"TimeWindow","description":"Number of service crashes or high-CPU events within a defined time period"},{"field":"ServiceTarget","description":"Specific service name or executable targeted for DoS (e.g., svchost.exe, w3wp.exe)"},{"field":"CPUThresholdPercent","description":"CPU usage percent considered anomalous over duration"}],"live":true,"detection_strategies":["DET0208"],"techniques":["T1499"]},{"id":"AN0585","stix_id":"x-mitre-analytic--b7e4a6de-8ff3-4711-aa83-97533adec211","name":"Analytic 0585","description":"Malicious script or binary causes repeated kernel panics, OOM kills, or systemd service restarts targeting services like nginx, httpd, sshd.","url":"https://attack.mitre.org/detectionstrategies/DET0208#AN0585","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"Out of memory killer invoked or kernel panic entries","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"linux-syslog"},{"name":"journald:systemd","channel":"Repeated service restart attempts or unit failures","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"journald-systemd"}],"mutable_elements":[{"field":"ServiceName","description":"Targeted daemon/service such as sshd, nginx, mysql"},{"field":"RestartThreshold","description":"Number of restarts in short succession to trigger alert"},{"field":"OOMKillCount","description":"Count of OOM kills over a time window"}],"live":true,"detection_strategies":["DET0208"],"techniques":["T1499"]},{"id":"AN0586","stix_id":"x-mitre-analytic--5f2cc434-5edc-4f36-927a-eb48ee72aa6e","name":"Analytic 0586","description":"Adversary launches high-entropy process or malformed app bundle causing repeated application crashes and system slowdowns.","url":"https://attack.mitre.org/detectionstrategies/DET0208#AN0586","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Repeated process crashes logged by CrashReporter or system instability logs in com.apple.console","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Spike in CPU or memory use from non-user-initiated processes","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"CrashCountThreshold","description":"Number of app crashes within monitoring window"},{"field":"PayloadEntropyThreshold","description":"Used for high-entropy binaries often observed in DoS malware samples"}],"live":true,"detection_strategies":["DET0208"],"techniques":["T1499"]},{"id":"AN0587","stix_id":"x-mitre-analytic--472f81b1-99ba-406a-b2ef-d70b2af5b527","name":"Analytic 0587","description":"Instance enters degraded/unhealthy state due to abnormal process load or memory exhaustion, often caused by automation or script-based attacks.","url":"https://attack.mitre.org/detectionstrategies/DET0208#AN0587","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudWatch","channel":"StatusCheckFailed or StatusCheckFailed_System for burstable instances (t2/t3)","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"aws-cloudwatch"},{"name":"AWS:CloudTrail","channel":"StartInstances","data_component":"DC0080","data_component_name":"Instance Start","log_source_slug":"aws-cloudtrail"},{"name":"VPCFlowLogs:All","channel":"High volume internal traffic with low entropy indicating looped or malicious DoS script","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"vpcflowlogs-all"}],"mutable_elements":[{"field":"InstanceType","description":"Burstable vs compute-optimized instances impact DoS effect"},{"field":"FailureThreshold","description":"How many consecutive StatusCheckFailed events to consider critical"}],"live":true,"detection_strategies":["DET0208"],"techniques":["T1499"]},{"id":"AN0588","stix_id":"x-mitre-analytic--7027622a-7a33-4189-a500-c54eef3467b6","name":"Analytic 0588","description":"Container orchestrator logs show crashlooping pods, repeated resource exhaustion, or malicious binaries with infinite loops consuming systemd/cgroup limits.","url":"https://attack.mitre.org/detectionstrategies/DET0208#AN0588","platforms":["Containers"],"log_source_references":[{"name":"kubernetes:events","channel":"CrashLoopBackOff, OOMKilled, container restart count exceeds threshold","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"kubernetes-events"},{"name":"docker:events","channel":"Container exited with non-zero code repeatedly in short period","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"docker-events"}],"mutable_elements":[{"field":"RestartCountThreshold","description":"Number of container restarts within a time window"},{"field":"ContainerImageEntropy","description":"Payload entropy of container image as an anomaly factor"}],"live":true,"detection_strategies":["DET0208"],"techniques":["T1499"]}],"live":true,"version":"1.0","techniques":["T1499"]}],"sigma_rules":[{"id":"3f2c93c7-7b2a-4d58-bb8d-6f39422d8148","title":"CVE-2024-49113 Exploitation Attempt - LDAP Nightmare","author":"Samuel Monsempes","status":"experimental","level":"high","date":"2025-01-08","modified":null,"description":"Detects exploitation attempt of CVE-2024-49113 known as LDAP Nightmare, based on \"Application Error\" log where the faulting application is \"lsass.exe\" and the faulting module is \"WLDAP32.dll\".\n","references":["https://gist.github.com/travisbgreen/82b68bac499edbe0b17dcbfa0c5c71b7","https://www.linkedin.com/feed/update/urn:li:activity:7282295814792605698/"],"logsource":{"product":"windows","service":"application"},"tags":["attack.impact","attack.t1499","cve.2024-49113","detection.emerging-threats"],"path":"rules-emerging-threats/2024/Exploits/CVE-2024-49113/win_application_error_exploit_cve_2024_49113_ldap_nightmare.yml","techniques":["T1499"],"cves":["CVE-2024-49113"]},{"id":"ea61bb82-a5e0-42e6-8537-91d29500f1b9","title":"Potential Abuse of Linux Magic System Request Key","author":"Milad Cheraghi","status":"experimental","level":"medium","date":"2025-05-23","modified":null,"description":"Detects the potential abuse of the Linux Magic SysRq (System Request) key by adversaries with root or sufficient privileges\nto silently manipulate or destabilize a system. By writing to /proc/sysrq-trigger, they can crash the system, kill processes,\nor disrupt forensic analysis—all while bypassing standard logging. Though intended for recovery and debugging, SysRq can be\nmisused as a stealthy post-exploitation tool. It is controlled via /proc/sys/kernel/sysrq or permanently through /etc/sysctl.conf.\n","references":["https://www.kernel.org/doc/html/v4.10/_sources/admin-guide/sysrq.txt","https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/4/html/reference_guide/s3-proc-sys-kernel","https://www.splunk.com/en_us/blog/security/threat-update-awfulshred-script-wiper.html"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.execution","attack.t1059.004","attack.impact","attack.t1529","attack.t1489","attack.t1499"],"path":"rules/linux/auditd/path/lnx_auditd_magic_system_request_key.yml","techniques":["T1059.004","T1529","T1489","T1499"],"cves":[]},{"id":"f8a66a02-4a16-46e5-b7fd-a42c8a93d137","title":"LSASS Crash Via Netlogon Stack Buffer Overflow - CVE-2026-41089","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-06-02","modified":null,"description":"Detects a crash of the LSASS process where netlogon.dll is the faulting module and the exception code is STATUS_STACK_BUFFER_OVERRUN (0xc0000409).\nThis crash, especially on Domain Controllers, might indicate the exploitation of CVE-2026-41089, a denial of service (DoS) vulnerability,\nwhich exists in the Netlogon component of Windows and can be triggered by sending specially crafted requests to the Netlogon service,\nleading to a stack-based buffer overflow and subsequent crash of the LSASS process.\n","references":["https://aretiq.ai/research/vul260513-cve-2026-41089-microsoft-windows-netlogon-buildsamlogonresponse-stack-based-buffer-overflow-rce/","https://learn.microsoft.com/en-us/shows/inside/c0000409","https://github.com/p3Nt3st3r-sTAr/CVE-2026-41089","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41089"],"logsource":{"product":"windows","service":"application"},"tags":["attack.impact","attack.t1499","cve.2026-41089","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Exploits/CVE-2026-41089/win_application_error_exploit_cve_2026_41089_lsass_netlogon_crash.yml","techniques":["T1499"],"cves":["CVE-2026-41089"]}],"kev_cves":[{"cveID":"CVE-2024-54085","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2025-42599","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-6549","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-20109","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-44487","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-35394","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2020-5735","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}