If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1498 - Network Denial of Service, Tec.

site address: attack.mitre.org/techniques/T1498 redirected to: attack.mitre.org/techniques/T1498

site title: Network Denial of Service, Technique T1498 - Enterprise MITRE ATT&CK®

Our opinion (on Thursday 20 August 2026 2:48:54 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

network, denial, of, service, procedure, examples, mitigations, detection, strategy, references, sub, techniques,

Text of the page (most frequently used words):
the (33), network (22), and (12), att (10), all (10), service (10), dos (10), traffic (9), #denial (9), enterprise (7), retrieved (7), attacks (7), t1498 (7), techniques (6), can (6), ics (5), mobile (5), none (5), resources (5), ddos (5), october (5), may (5), attack (5), for (5), system (5), mitre (4), detection (4), mitigations (4), defenses (4), across (4), multiple (4), being (4), version (4), address (4), are (3), cti (3), data (3), sub (3), april (3), 2019 (3), nkabuse (3), 2024 (3), 2020 (3), lucifer (3), devices (3), november (3), targeting (3), ports (3), description (3), name (3), flood (3), blocking (3), source (3), targeted (3), connection (3), internet (3), adversaries (3), 2026 (2), corporation (2), use (2), domains (2), reference (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), response (2), unveiling (2), new (2), critical (2), windows (2), 2014 (2), september (2), fraud (2), mike (2), tools (2), large (2), volumes (2), amplification (2), platforms (2), analytic (2), 3rd (2), plan (2), volume (2), filtering (2), that (2), protocols (2), when (2), capacity (2), filter (2), such (2), hosting (2), several (2), distributed (2), against (2), apt28 (2), availability (2), impact (2), 002 (2), 001 (2), attacking (2), more (2), reflection (2), this (2), have (2), perform (2), including (2), bandwidth (2), malicious (2), resource (2), example (2), with (2), services (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, meintanis, revuelto, socha, 2017, march, overview, guide, kaspersky, gert, 2023, december, multiplatform, threat, abusing, nkn, protocol, february, hsu, june, cryptojacking, hybrid, malware, exploiting, high, vulnerabilities, infect, brady, 2018, indictment, united, states, aleksei, sergeyevich, morenets, wueest, continued, rise, isac, 2012, alert, cyber, criminals, financial, institution, employee, credentials, conduct, wire, transfer, ned, moran, scott, oppenheim, fireeye, operation, poisoned, handover, ties, between, apt, activity, hong, kong, pro, democracy, movement, references, flooding, like, hping3, nping, sending, packets, ips, an1435, executable, script, generating, outbound, remote, hosts, known, an1434, behavioral, det0518, strategy, immediate, require, rapid, engagement, parties, analyze, risk, associated, affected, create, disaster, recovery, business, continuity, respond, incidents, depending, premises, possible, addresses, sourcing, used, transport, exceed, typically, necessary, intercept, incoming, upstream, out, from, legitimate, provided, provider, isp, party, content, delivery, cdn, providers, specializing, m1037, mitigation, enables, types, capabilities, post, installation, s1107, execute, tcp, udp, http, s0532, 2016, conducted, world, anti, doping, agency, g0007, procedure, examples, live, permalink, 2025, last, modified, created, vishwas, manral, mcafee, yossi, weizman, azure, defender, research, team, contributors, type, containers, iaas, linux, macos, tactic, directly, see, endpoint, original, spoof, make, difficult, trace, back, enable, increase, difficulty, defenders, defending, reducing, eliminating, effectiveness, defense, aspects, apply, methods, spoofing, botnets, will, occur, exhausted, due, directed, connections, relies, adversary, send, 10gbps, server, hosted, 1gbps, generated, single, systems, spread, which, commonly, referred, degrade, block, users, performed, exhausting, rely, include, specific, websites, email, dns, web, based, applications, been, observed, conducting, political, purposes, support, other, activities, distraction, hacktivism, extortion, direct, home, open, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, learn, about, get, started, detections, technique,


Text of the page (random words):
network denial of service technique t1498 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise network denial of service network denial of service sub techniques 2 id name t1498 001 direct network flood t1498 002 reflection amplification adversaries may perform network denial of service dos attacks to degrade or block the availability of targeted resources to users network dos can be performed by exhausting the network bandwidth services rely on example resources include specific websites email services dns and web based applications adversaries have been observed conducting network dos attacks for political purposes 1 and to support other malicious activities including distraction 2 hacktivism and extortion 3 a network dos will occur when the bandwidth capacity of the network connection to a system is exhausted due to the volume of malicious traffic directed at the resource or the network connections and network devices the resource relies on for example an adversary may send 10gbps of traffic to a server that is hosted by a network with a 1gbps connection to the internet this traffic can be generated by a single system or multiple systems spread across the internet which is commonly referred to as a distributed dos ddos to perform network dos attacks several aspects apply to multiple methods including ip address spoofing and botnets adversaries may use the original ip address of an attacking system or spoof the source ip address to make the attack traffic more difficult to trace back to the attacking system or to enable reflection this can increase the difficulty defenders have in defending against the attack by reducing or eliminating the effectiveness of filtering by the source address on network defense devices for dos attacks targeting the hosting system directly see endpoint denial of service id t1498 sub techniques t1498 001 t1498 002 ⓘ tactic impact ⓘ platforms containers iaas linux windows macos ⓘ impact type availability contributors vishwas manral mcafee yossi weizman azure defender research team version 1 2 created 17 april 2019 last modified 24 october 2025 version permalink live version procedure examples id name description g0007 apt28 in 2016 apt28 conducted a distributed denial of service ddos attack against the world anti doping agency 4 s0532 lucifer lucifer can execute tcp udp and http denial of service dos attacks 5 s1107 nkabuse nkabuse enables multiple types of network denial of service capabilities across several protocols post installation 6 mitigations id mitigation description m1037 filter network traffic when flood volumes exceed the capacity of the network connection being targeted it is typically necessary to intercept the incoming traffic upstream to filter out the attack traffic from the legitimate traffic such defenses can be provided by the hosting internet service provider isp or by a 3rd party such as a content delivery network cdn or providers specializing in dos mitigations 7 depending on flood volume on premises filtering may be possible by blocking source addresses sourcing the attack blocking ports that are being targeted or blocking protocols being used for transport 7 as immediate response may require rapid engagement of 3rd parties analyze the risk associated to critical resources being affected by network dos attacks and create a disaster recovery plan business continuity plan to respond to incidents 7 detection strategy id name analytic id analytic description det0518 behavioral detection of t1498 network denial of service across platforms an1434 executable or script generating large outbound network traffic targeting remote hosts or known amplification ports an1435 flooding tools like hping3 or nping sending large volumes of packets across multiple ports or ips references ned moran mike scott mike oppenheim of fireeye 2014 november 3 operation poisoned handover unveiling ties between apt activity in hong kong s pro democracy movement retrieved november 17 2024 fs isac 2012 september 17 fraud alert cyber criminals targeting financial institution employee credentials to conduct wire transfer fraud retrieved september 23 2024 wueest c 2014 october 21 the continued rise of ddos attacks retrieved april 24 2019 brady s 2018 october 3 indictment united states vs aleksei sergeyevich morenets et al retrieved october 1 2020 hsu k et al 2020 june 24 lucifer new cryptojacking and ddos hybrid malware exploiting high and critical vulnerabilities to infect windows devices retrieved november 16 2020 kaspersky gert 2023 december 14 unveiling nkabuse a new multiplatform threat abusing the nkn protocol retrieved february 8 2024 meintanis s revuelto v socha k 2017 march 10 ddos overview and response guide retrieved april 24 2019 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Images from subpage: "attack.mitre.org/datacomponents" Verify
Images from subpage: "attack.mitre.org/groups" Verify
Images from subpage: "attack.mitre.org/software" Verify
Images from subpage: "attack.mitre.org/campaigns" Verify
Images from subpage: "attack.mitre.org/resources/" Verify

Verified site has: 53 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-53


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1498/
access-control-allow-origin *
expires Thu, 20 Aug 2026 02:58:54 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 95E4:3442:18E82D0:190DC83:6A866B16
x-github-edge-region fra
accept-ranges bytes
age 0
date Thu, 20 Aug 2026 02:48:54 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290036-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787194135.593061,VS0,VE105
vary Accept-Encoding
x-fastly-request-id 86fc6f8ff2a49ebb7099d2f88adf05ac43a5166c
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
last-modified Fri, 07 Aug 2026 14:24:19 GMT
access-control-allow-origin *
etag W/ 6a75ea93-c486
expires Thu, 20 Aug 2026 02:58:54 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 8E08:1EC02:1A303EA:1A58212:6A866B16
x-github-edge-region fra
accept-ranges bytes
age 0
date Thu, 20 Aug 2026 02:48:54 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290036-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787194135.705690,VS0,VE110
vary Accept-Encoding
x-fastly-request-id d49aef9d47b05bfa29bc623e943c57711bbae638
content-length 8869

Meta Tags

title="Network Denial of Service, Technique T1498 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size8869
load time (s)0.517305
redirect count1
speed download17154
server IP 185.199.110.153
* all occurrences of the string "http://" have been changed to "htt???/"