Endpoint Denial of Service: OS Exhaustion Flood T1499.001

Tactic: Impact

Adversaries may launch a denial of service (DoS) attack targeting an endpoint's operating system (OS). A system's OS is responsible for managing the finite resources as well as preventing the entire system from being overwhelmed by excessive demands on its capacity. These attacks do not need to exhaust the actual resources on a system; the attacks may simply exhaust the limits and available resources that an OS self-imposes.

Events covered

1 catalog event is tagged with this technique by at least one rule.

Authoring guide

These 1 rule share fields, values, and exclusions.

Fields filtered most (3 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
Description1contains 1contains a corrupted file record, the name of the file is "\"
Origin1eq 1file system driver
Provider_Name1eq 1ntfs

Top indicator values (4 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
Descriptioncontains
contains a corrupted file record
1
Descriptioncontains
the name of the file is "\"
1
Origineq
file system driver
1
Provider_Nameeq
ntfs
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Windows

Domain: Endpoint

Sigma 1 rule