{"id":"T1498.002","name":"Reflection Amplification","url":"https://attack.mitre.org/techniques/T1498/002","tactics":["impact"],"platforms":["Windows","IaaS","Linux","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0408","stix_id":"x-mitre-detection-strategy--20f5a44b-e9bb-48e9-9bea-e7a3d757005f","name":"Detection Strategy for Reflection Amplification DoS (T1498.002)","url":"https://attack.mitre.org/detectionstrategies/DET0408","analytics":[{"id":"AN1140","stix_id":"x-mitre-analytic--fdf11d76-3bd7-41c4-b117-7b0f17b31b17","name":"Analytic 1140","description":"Outbound spoofed traffic to known amplification protocols (e.g., DNS, NTP, Memcached) combined with abnormal network traffic volume targeting remote reflectors, resulting in disproportionate traffic returned to a victim","url":"https://attack.mitre.org/detectionstrategies/DET0408#AN1140","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"Windows:perfmon","channel":"Sudden spike in outbound throughput without corresponding inbound traffic","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"windows-perfmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Interval for measuring sudden outbound spike or volume pattern"},{"field":"AmplificationProtocolPorts","description":"List of known ports used for reflection amplification (e.g., 53/DNS, 123/NTP, 11211/Memcached)"},{"field":"PacketToByteRatio","description":"Heuristic threshold where the response volume far outweighs the request volume"}],"live":true,"detection_strategies":["DET0408"],"techniques":["T1498.002"]},{"id":"AN1141","stix_id":"x-mitre-analytic--eb7692b0-5592-4d23-ba06-fdded48a2a0d","name":"Analytic 1141","description":"Spoofed outbound packets sent to amplification services from command-line tools or scripts, combined with abnormal outbound packet volume on known reflector ports","url":"https://attack.mitre.org/detectionstrategies/DET0408#AN1141","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"Execution of spoofing tools (e.g., hping3, nping, scapy) sending UDP packets to known amplifier ports","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"Outbound UDP floods targeting common reflection services with spoofed IP headers","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"},{"name":"sar:network","channel":"Outbound network saturation with minimal process activity","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"sar-network"}],"mutable_elements":[{"field":"TimeWindow","description":"Sliding interval for detecting volumetric anomalies"},{"field":"AmplificationProtocolList","description":"Which protocols to watch (e.g., DNS, NTP, SSDP, Memcached)"},{"field":"ExecutionToolList","description":"Set of binaries and scripts commonly abused for spoofing/reflection"}],"live":true,"detection_strategies":["DET0408"],"techniques":["T1498.002"]},{"id":"AN1142","stix_id":"x-mitre-analytic--44c2e32e-bd34-4ba9-8105-28c14309207c","name":"Analytic 1142","description":"Command-line initiated UDP traffic bursts to external reflection amplification ports using built-in scripting or binaries with network anomalies","url":"https://attack.mitre.org/detectionstrategies/DET0408#AN1142","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of ping, nping, or crafted network packets via bash or python to reflection services","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Outbound UDP spikes to external reflector IPs","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ReflectionPorts","description":"Ports known for reflection abuse — DNS, NTP, SSDP, Memcached"},{"field":"TrafficSpikeThreshold","description":"How much deviation in outbound traffic constitutes a suspicious spike"}],"live":true,"detection_strategies":["DET0408"],"techniques":["T1498.002"]},{"id":"AN1143","stix_id":"x-mitre-analytic--08c69003-044c-46a5-b17a-7cb5b25f2d50","name":"Analytic 1143","description":"Cloud-hosted VM or container generates spoofed UDP requests to third-party services on known amplifier ports, with high outbound-to-inbound traffic ratios in VPC Flow Logs","url":"https://attack.mitre.org/detectionstrategies/DET0408#AN1143","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"Create egress rule allowing UDP to port 53, 123, 11211","data_component":"DC0051","data_component_name":"Firewall Rule Modification","log_source_slug":"aws-cloudtrail"},{"name":"AWS:VPCFlowLogs","channel":"Large outbound UDP traffic to multiple public reflector IPs","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"aws-vpcflowlogs"},{"name":"AWS:CloudWatch","channel":"Sudden spike in network output without a corresponding inbound request ratio","data_component":"DC0018","data_component_name":"Host Status","log_source_slug":"aws-cloudwatch"}],"mutable_elements":[{"field":"EgressRulePorts","description":"Cloud security group rules permitting UDP to reflector protocols"},{"field":"OutboundToInboundRatio","description":"Ratio threshold to flag traffic as potential reflection behavior"},{"field":"VMInstanceTagContext","description":"Cloud metadata that can help scope anomalous behavior to development, testing, or external-facing services"}],"live":true,"detection_strategies":["DET0408"],"techniques":["T1498.002"]}],"live":true,"version":"1.0","techniques":["T1498.002"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}