A packet-level walkthrough of a DNS amplification DDoS attack. See what the traffic looks like in real time, how to identify it, and why it works so well....
Jun 24, 2026 · 9 min read →Blog
Attack postmortems.
Engineering deep-dives.
Practical guides from engineers who've been DDoS'd and learned from it.
Canada's Cyber Centre assessed DDoS attacks against World Cup infrastructure as "very likely." The real targets aren't stadiums. They're the...
Jun 16, 2026 · 10 min read →How ransom DDoS campaigns target sportsbooks with event-timed extortion, and how sub-second detection changes the economics....
Jun 7, 2026 · 12 min read →What TDoS is, how it differs from volumetric DDoS, and how baseline anomaly detection catches automated call floods....
Jun 7, 2026 · 9 min read →Analysis of the 313 Team DDoS extortion campaign against Canonical and what operators can learn from it....
Jun 7, 2026 · 8 min read →How iGaming operators are responding to the surge in ransom DDoS campaigns targeting live betting platforms....
Jun 7, 2026 · 10 min read →Why residential proxy infrastructure attracts targeted DDoS attacks and how to defend against them....
Jun 7, 2026 · 9 min read →How telephony denial of service differs from volumetric DDoS and how to detect automated call floods....
Jun 7, 2026 · 10 min read →A new DoS attack combines HPACK compression amplification with flow control stalling to overwhelm NGINX, Apache, IIS, Envoy, and Cloudflare ...
Jun 4, 2026 · 10 min read →Spoofed source IPs cannot be blocked one by one. Flowtriq detects them by measuring the Shannon entropy of TTL values across attack traffic....
May 27, 2026 · 12 min read →31.4 Tbps Aisiru floods, geopolitical hacktivism surges, 2.45 billion request L7 attacks, Operation PowerOFF, and what defenders should take...
May 20, 2026 · 16 min read →Europol and 21 nations seized 53 booter domains, exposed 3 million accounts, and entered a prevention phase targeting young users. What it m...
May 20, 2026 · 12 min read →API-targeting DDoS attacks increased 200% in 2025. GraphQL recursive queries, Slowloris thread exhaustion, and distributed L7 floods are res...
May 20, 2026 · 13 min read →The amplification vectors attackers are using beyond DNS, NTP, and Memcached. Protocol mechanics, amplification factors, global reflector co...
May 20, 2026 · 15 min read →Triple extortion is the 2026 norm. How RDDoS extortion works, why paying encourages repeat attacks, and why automated detection makes the DD...
May 20, 2026 · 14 min read →600% increase in IPv6 DDoS traffic. Extension header floods, NDP exhaustion, and why most detection tools treat IPv6 as an afterthought....
May 20, 2026 · 13 min read →DOJ seized 3M+ device botnet infrastructure, but the devices remain vulnerable. The post-takedown state of the IoT botnet ecosystem....
May 20, 2026 · 13 min read →NETSCOUT data shows 70% of DDoS attacks last fewer than 15 minutes. Manual response takes 15 to 30 minutes minimum. The math means most atta...
Apr 26, 2026 · 10 min read →How attackers layer NTP amplification and SYN floods, why each vector alone may stay below detection thresholds, and how Flowtriq correlated...
Apr 26, 2026 · 14 min read →From the 300 Gbps Spamhaus attack to 5.6 Tbps Mirai variants: the biggest DDoS attacks ever recorded, what made them possible, and the defen...
Mar 12, 2026 · 13 min read →The full Mirai lifecycle: scanning, credential brute-force, multi-architecture loaders, C2 registration, and coordinated DDoS floods from hu...
Mar 15, 2026 · 12 min read →A deep technical walkthrough of SYN flood attacks at the packet level. TCP handshake exploitation, kernel behavior under load, and detection...
Mar 15, 2026 · 14 min read →How attackers exploit connectionless UDP protocols to amplify traffic by 50,000x. Protocol mechanics, amplification factors, and mitigation ...
Mar 15, 2026 · 15 min read →Technical analysis of the Aisiru botnet that generated record-breaking 5.6 Tbps attacks. Infrastructure, capabilities, targets, and detectio...
Mar 15, 2026 · 13 min read →How carpet bombing distributes attack traffic across entire subnets to stay below per-IP thresholds. Why per-host detection fails and what w...
Mar 15, 2026 · 12 min read →The economics, infrastructure, and law enforcement actions around the DDoS-for-hire industry. How $30 buys a 100 Gbps attack and what defend...
Mar 15, 2026 · 14 min read →From 3.8 Tbps Mirai variants to 5.6 Tbps Aisiru floods. The attacks that broke records, the infrastructure that enabled them, and what shift...
Mar 15, 2026 · 13 min read →Mirai botnet traffic has distinct fingerprints in kernel counters and packet logs. Spot scanning, C2 command traffic, and victim floods with...
Mar 11, 2026 · 9 min read →The 50,000x amplification factor explained at the packet level, a ready-to-use NOC email template, and the exact iptables rule to stop it im...
Feb 26, 2026 · 10 min read →Complete guide to DNS amplification DDoS attacks. Learn how they work at the protocol level, what the traffic looks like in packet captures,...
Feb 24, 2026 · 12 min read →memcached amplification attacks can reach 50,000x amplification. Here's exactly what the traffic looks like at the packet level and how Flow...
Feb 18, 2026 · 8 min read →Sophisticated attackers don't use one protocol. They rotate between UDP, TCP, and HTTP to evade simple threshold detection. Here's how Flowt...
Jan 24, 2026 · 9 min read →