FORENSIA

ATT&CK · T1498

Network Denial of Service

Tactics: impact

About

Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users. Network DoS can be performed by exhausting the network bandwidth services rely on. Example resources include specific websites, email services, DNS, and web-based applications. Adversaries have been observed conducting network DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion. A Network DoS will occur when the bandwidth capacity of the network connection to a system is exhausted due to the volume of malicious traffic directed at the resource or the network connections and network devices the resource relies on. For example, an adversary may send 10Gbps of traffic to a server that is hosted by a network with a 1Gbps connection to the internet. This traffic can be generated by a single system or multiple systems spread across the internet, which is commonly referred to as a distributed DoS (DDoS). To perform Network DoS attacks several aspects apply to multiple methods, including IP address spoofing, and botnets. Adversaries may use the original IP address of an attacking system, or spoof the source IP address to make the attack traffic more difficult to trace back to the attacking system or to enable reflection. This can increase the difficulty defenders have in defending against the attack by reducing or eliminating the effectiveness of filtering by the source address on network defense devices. For DoS attacks targeting the hosting system directly, see Endpoint Denial of Service.

Platforms: Windows, IaaS, Linux, macOS, ContainersMITRE ATT&CK ↗

Used by actors

1 known groups

Software

2 malware/tools implement this

LuciferNKAbuse

Corpus indicators tagged with this technique

50 indicators in the corpus carry T1498.

IndicatorTypeFamilySevSrc
cve-2017-17215cve852
cve-2024-1781cve851
cve-2018-8007cve851
cve-2016-15047cve854
cve-2025-34054cve854
cve-2021-27137cve858
eead44c0af7ddb12cece1a6125cf213bab3c22511cd59aff9d63dcfddb7d4386hash804
450ea44da0c9d96a2e8f4d6bad34f1c35cd35743295b8cd2defa9f7a9884685dhash804
8fc2d35b66c692d37a85ae9d30dc5c7f06f0b3eaf01112a5a6398a1a0feb3aeehash804
b519ae088ee0fd4658c16aab474d51c6acdc5c9cd7fab3fd69032d05a45ffd9bsha256801
a5d1b65b1055677156cd87b357ef488704115a2cbf52044dbb041072efed2f9dsha256801
1cd9eccc8e73d60164390beddf4cdc48hash804
703a8383a3df68abce59b02fcd0b5678hash804
28f871af1833935beba160b51e4a732c43a5dde5hash804
ca9d7aaff7c636120149168e2bbb509c10544993hash804
20042f1efb59c99e3addf822a3e9e5a496f0b701362df038a50a32a9f504a136hash804
3ddb67ab079509dd1e7ac77fc4cfed25a271526668c68f8a2221e96a4cc21812hash804
41e8e327abbf2ba721be677ad8a416a7295708257b39688a0af03275fb199cechash804
444a9d34a9f59dc7975dfabefb47d789813a4497bbac9127c4806dd816e85211hash804
7413cbb6eab4d6b10346f71be5dd76d7cf2f4817f7776367b162f83755aefa1fhash804
9394666007fac4014a4641fdae150c1b969ed2bc4299876318a336fd386abf59hash804
b61a5508847a2167b737d31193dc393e92c5be2aa5141bbe4b7ea6f440fd4799hash804
b6f835ced11059d341222eba11fff3a4672f4de47a3a4d791fad86059a2b06d4hash804
d452f22dacab9785539484245c13e9cce58df23fc82eeef205684fcd196da20bhash804
dff0edae6e8854ddd3e617054ee0bd74c696c91411f704dff60aabaec839bec9hash804
ea44138b9701fce1b2fe13de8f9e00681c007c9adc625edc9f507f177704c2e8hash804
f02b1d8010dac35b007796def0cbd5d0c9414df790e2b55b105c95df2f2ffa91hash804
6aa791c76b3107fca9d57b7ecea8f46d97d83738sha1781
d39a3ee96be6b8f5238cb1253514ab55c88f714csha1781
8315f650e9e4f67c00277b076ab304eed23db47dsha1781

Showing the top 30 by severity of 50.