Endpoint Denial of Service: Application Exhaustion Flood T1499.003

Tactic: Impact

Adversaries may target resource intensive features of applications to cause a denial of service (DoS), denying availability to those applications. For example, specific features in web applications may be highly resource intensive. Repeated requests to those features may be able to exhaust system resources and deny access to the application or the server itself.

Authoring guide

These 2 rules share fields, values, and exclusions.

Fields filtered most (3 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType1in 1application.integration.rate_limit_exceeded, core.concurrency.org.limit.violation, system.org.rate_limit.violation
action1in 1bulk_session_reset_by_admin, user_session_invalidated, user_session_reset_by_admin
data_stream.dataset1eq 1okta.system

Top indicator values (8 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypein
application.integration.rate_limit_exceeded
1
EventTypein
core.concurrency.org.limit.violation
1
EventTypein
system.org.rate_limit.violation
1
EventTypein
system.org.rate_limit.warning
1
actionin
bulk_session_reset_by_admin
1
actionin
user_session_invalidated
1
actionin
user_session_reset_by_admin
1
data_stream.dataseteq
okta.system
148

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Elastic 1 rule

Panther 1 rule