MITRE ATT&CK technique
Network Denial of Service detection rulesT1498
Network Denial of Service (T1498) is a MITRE ATT&CK technique in the Impact tactic. This page lists the 3 community-maintained Sigma detection rules in the library mapped to T1498 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target opencanary, windows, kubernetes.
Top products
Tactic
OpenCanary - NTP Monlist Request
highDetects instances where an NTP service on an OpenCanary node has had a NTP monlist request.
opencanary · application
Potential BlackByte Ransomware Activity
highDetects command line patterns used by BlackByte ransomware in different operations
windows · process_creation
Deployment Deleted From Kubernetes Cluster
lowDetects the removal of a deployment from a Kubernetes cluster. This could indicate disruptive activity aiming to impact business operations.
kubernetes · application