MITRE ATT&CK Technique
T1499.003Application Exhaustion Flood
- First Reported
- Apr 29, 2026
- Latest Reported
- Apr 29, 2026
Official Description
Adversaries may target resource intensive features of applications to cause a denial of service (DoS), denying availability to those applications. For example, specific features in web applications may be highly resource intensive. Repeated requests to those features may be able to exhaust system resources and deny access to the application or the server itself.(Citation: Arbor AnnualDoSreport Jan 2018)
- Tactics
- Impact
- Platforms
- Windows, IaaS, Linux, macOS
- Parent Technique
- T1499 · Endpoint Denial of Service
- MITRE Version
- 1.3
- Last Modified
- Oct 24, 2025
Reported Context (1)
- The HTTP-template raw-TCP variant uses request templates and, according to the article's mapping, chunked-abuse headers against application-layer defenses. Operator’s Debug Build Exposes xlabs_v1 DDoS-for-Hire Botnet
Malware (4)
Threat Actors (1)
MITRE ATT&CK (19)
Vendors (5)
Products (2)
Tools (6)
Countries (2)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.