# T1499.002 Service Exhaustion Flood

> As of 2026-10-05, T1499.002 (Service Exhaustion Flood) appears in 10 tracked threats, first reported 2026-02-16 and most recently 2026-09-27; it most often appears alongside T1499.004 (Application or System Exploitation).

- **Tracked threats:** 10 (1 critical, 7 high, 2 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-09-27
- **Detection rules:** 29 (counts only; Blue tier and above)

## Key facts

- **ID:** T1499.002
- **Framework:** MITRE ATT&CK
- **Tactics:** Impact
- **Matrix:** Enterprise
- **Parent:** T1499
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1499/002/

## Activity timeline

T1499.002 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 4 reports, and 10 of the 10 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1499.002 Service Exhaustion Flood is catalogued by MITRE ATT&CK under the Impact tactic in the Enterprise matrix, as a sub-technique of [T1499 Endpoint Denial of Service](https://intel.threadlinqs.com/technique/T1499). Threadlinqs maps 10 of 2623 tracked threats (0.4%) to it; by severity that is 1 critical, 7 high, 2 medium.

Threats that use T1499.002 most often also use [T1499.004 Application or System Exploitation](https://intel.threadlinqs.com/technique/T1499.004) (7 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (6 threats), [T1587.004 Exploits](https://intel.threadlinqs.com/technique/T1587.004) (6 threats), [T1595.002 Vulnerability Scanning](https://intel.threadlinqs.com/technique/T1595.002) (6 threats), [T1499.003 Application Exhaustion Flood](https://intel.threadlinqs.com/technique/T1499.003) (5 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1499.002.

- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)

## Data sources

Telemetry that can reveal T1499.002, per MITRE ATT&CK.

- Application Log — Application Log Content
- Network Traffic — Network Traffic Content, Network Traffic Flow
- Sensor Health — Host Status

## Tracked threats

10 tracked threats use T1499.002.

- [x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draining](https://intel.threadlinqs.com/threat/TL-2026-2686) — high — 2026-09-27
- [F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)](https://intel.threadlinqs.com/threat/TL-2026-2596) — high — 2026-09-21
- [NatJack: NAT Connection-Tracking Manipulation Attacks Hijack TCP Sessions Across Windows, Linux, and macOS…](https://intel.threadlinqs.com/threat/TL-2026-1927) — high — 2026-08-07
- [Multiple Vulnerabilities in Citrix XenServer 8.4 and 9 Enable Guest-to-Host Escalation and Denial of Service…](https://intel.threadlinqs.com/threat/TL-2026-1781) — high — 2026-07-31
- [OpenSSL Silently Patches "HollowByte" Memory-Exhaustion DoS Vulnerability](https://intel.threadlinqs.com/threat/TL-2026-1554) — medium — 2026-07-20
- [OpenSSL "HollowByte" TLS Handshake Memory-Amplification DoS (No CVE Assigned)](https://intel.threadlinqs.com/threat/TL-2026-1459) — medium — 2026-07-17
- [148 npm Packages Disguised as Student Tutoring Proxies Turn Browsers Into DDoS Botnet (Lucide Proxy)](https://intel.threadlinqs.com/threat/TL-2026-1304) — high — 2026-07-14
- [SolarWinds Serv-U DoS (CVE-2026-28318) — Actively Exploited Uncontrolled Resource Consumption via…](https://intel.threadlinqs.com/threat/TL-2026-0717) — high — 2026-06-08
- [NGINX Rift — CVE-2026-42945 Heap Buffer Overflow in ngx_http_rewrite_module (CVSS v4 9.2 Critical…](https://intel.threadlinqs.com/threat/TL-2026-0517) — critical — 2026-05-14
- [CVE-2024-3393 PAN-OS DNS Security DoS — Unauthenticated Firewall Crash Forces Maintenance Mode, Perimeter…](https://intel.threadlinqs.com/threat/TL-2026-0112) — high — 2026-02-16

## Related CVEs

CVEs referenced by the tracked threats that use T1499.002, most frequent first.

- [CVE-2024-3393](https://intel.threadlinqs.com/cve/CVE-2024-3393)
- [CVE-2026-11622](https://intel.threadlinqs.com/cve/CVE-2026-11622)
- [CVE-2026-40701](https://intel.threadlinqs.com/cve/CVE-2026-40701)
- [CVE-2026-42492](https://intel.threadlinqs.com/cve/CVE-2026-42492)
- [CVE-2026-42945](https://intel.threadlinqs.com/cve/CVE-2026-42945)
- [CVE-2026-42946](https://intel.threadlinqs.com/cve/CVE-2026-42946)
- [CVE-2026-56181](https://intel.threadlinqs.com/cve/CVE-2026-56181)

## Detection coverage

Threadlinqs maintains 29 detection rules mapped to T1499.002 (SPL 8, KQL 9, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.

29 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1499 Endpoint Denial of Service](https://intel.threadlinqs.com/technique/T1499) — 127 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1499.002
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
