Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Adversaries may attempt to cause a denial of service (DoS) by directly sending a high-volume of network traffic to a target.
.claude/skills/cyberstrikeus-t1498-001-direct-network-flood/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-05 | ✗→✓ | ▲ Improved | 48% | 0% |
| case-06 | ✗→✓ | ▲ Improved | 51% | 0% |
| case-08 | ✗→✓ | ▲ Improved | 12% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 30% | 0% |
| case-11 | ✗→✓ | ▲ Improved | -34% | 0% |
> Sub-technique of: T1498
Adversaries may attempt to cause a denial of service (DoS) by directly sending a high-volume of network traffic to a target. This DoS attack may also reduce the availability and functionality of the targeted system(s) and network. Direct Network Floods are when one or more systems are used to send a high-volume of network packets towards the targeted service's network. Almost any network protocol may be used for flooding. Stateless protocols such as UDP or ICMP are commonly used but stateful protocols such as TCP can be used as well.
Botnets are commonly used to conduct network flooding attacks against networks and services. Large botnets can generate a significant amount of traffic from systems spread across the global Internet. Adversaries may have the resources to build out and control their own botnet infrastructure or may rent time on an existing botnet to conduct an attack. In some of the worst cases for distributed DoS (DDoS), so many systems are used to generate the flood that each one only needs to send out a small amount of traffic to produce enough volume to saturate the target network. In such circumstances, distinguishing DDoS traffic from legitimate clients becomes exceedingly difficult. Botnets have been used in some of the most high-profile DDoS flooding attacks, such as the 2012 series of incidents that targeted major US banks.
Platforms: Windows, IaaS, Linux, macOS
> Note: No Atomic Red Team tests available for this technique. See Atomic Red Team GitHub for updates.
When flood volumes exceed the capacity of the network connection being targeted, it is typically necessary to intercept the incoming traffic upstream to filter out the attack traffic from the legitimate traffic. Such defenses can be provided by the hosting Internet Service Provider (ISP) or by a 3rd party such as a Content Delivery Network (CDN) or providers specializing in DoS mitigations.
Depending on flood volume, on-premises filtering may be possible by blocking source addresses sourcing the attack, blocking ports that are being targeted, or blocking protocols being used for transport.
As immediate response may require rapid engagement of 3rd parties, analyze the risk associated to critical resources being affected by Network DoS attacks and create a disaster recovery plan/business continuity plan to respond to incidents.
| Finding | Severity | Impact | | ----------------------------------------- | -------- | ------ | | Direct Network Flood technique applicable | Low | Impact |
| CWE ID | Title | | ------- | --------------------------------- | | CWE-400 | Uncontrolled Resource Consumption |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 34,897 | 47,409 | +36% | 1 | 1 | 0% | 4,946 | 7,908 | +60% | 0 | 0 | — |
case-02 | fail→fail | 35,255 | 42,335 | +20% | 1 | 1 | 0% | 4,079 | 7,003 | +72% | 0 | 0 | — |
case-03 | pass→pass | 16,775 | 26,079 | +55% | 1 | 1 | 0% | 2,488 | 4,345 | +75% | 0 | 0 | — |
case-04 | pass→pass | 24,972 | 33,901 | +36% | 1 | 1 | 0% | 2,878 | 5,383 | +87% | 0 | 0 | — |
case-05 | fail→pass | 21,555 | 18,844 | -13% | 1 | 1 | 0% | 2,562 | 3,791 | +48% | 0 | 0 | — |
case-06 | fail→pass | 17,307 | 23,699 | +37% | 1 | 1 | 0% | 2,480 | 3,736 | +51% | 0 | 0 | — |
case-07 | pass→pass | 13,421 | 9,384 | -30% | 1 | 1 | 0% | 1,375 | 2,572 | +87% | 0 | 0 | — |
case-08 | fail→pass | 15,106 | 9,433 | -38% | 1 | 1 | 0% | 1,554 | 1,734 | +12% | 0 | 0 | — |
case-09 | pass→pass | 19,848 | 15,006 | -24% | 1 | 1 | 0% | 2,283 | 3,278 | +44% | 0 | 0 | — |
case-10 | fail→pass | 14,601 | 8,927 | -39% | 1 | 1 | 0% | 1,689 | 2,196 | +30% | 0 | 0 | — |
case-11 | fail→pass | 18,542 | 7,343 | -60% | 1 | 1 | 0% | 2,073 | 1,359 | -34% | 0 | 0 | — |
case-12 | pass→pass | 11,103 | 5,756 | -48% | 1 | 1 | 0% | 886 | 1,742 | +97% | 0 | 0 | — |
case-13 | pass→pass | 13,939 | 5,116 | -63% | 1 | 1 | 0% | 1,253 | 1,753 | +40% | 0 | 0 | — |
case-14 | pass→pass | 26,410 | 26,492 | +0% | 1 | 1 | 0% | 2,884 | 3,954 | +37% | 0 | 0 | — |
case-15 | pass→pass | 14,579 | 20,414 | +40% | 1 | 1 | 0% | 2,113 | 3,127 | +48% | 0 | 0 | — |
case-16 | pass→pass | 14,655 | 4,348 | -70% | 1 | 1 | 0% | 1,530 | 1,594 | +4% | 0 | 0 | — |
case-17 | fail→pass | 13,484 | 5,165 | -62% | 1 | 1 | 0% | 1,338 | 1,464 | +9% | 0 | 0 | — |
case-18 | pass→pass | 18,725 | 17,100 | -9% | 1 | 1 | 0% | 1,775 | 2,805 | +58% | 0 | 0 | — |
case-19 | pass→pass | 11,292 | 8,680 | -23% | 1 | 1 | 0% | 1,881 | 1,605 | -15% | 0 | 0 | — |
case-20 | pass→pass | 20,876 | 9,674 | -54% | 1 | 1 | 0% | 3,123 | 1,805 | -42% | 0 | 0 | — |
case-21 | fail→pass | 16,364 | 1,737 | -89% | 1 | 1 | 0% | 1,792 | 1,324 | -26% | 0 | 0 | — |
case-22 | fail→pass | 22,694 | 7,994 | -65% | 1 | 1 | 0% | 1,748 | 1,482 | -15% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +36 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.