Detection, Mitigation & Response

Detect and mitigate DDoS attacks in under 1 second, respond automatically, and keep your users informed.

All features →
Learn
Documentation Quick Start API Reference Agent Setup DDoS Protection Landscape State of DDoS 2026 REPORT Free Certifications
Research & Guides
Mirai Botnet Kill Switch Research memcached Amplification Dynamic Baselines PCAP Forensics PagerDuty Setup
Company
About Us Partners Managed Protection Whitelabel / Reseller Affiliate Program Pay with Crypto System Status
Legal & Support
Contact Us Security Trust Center Terms Privacy SLA
Who Uses Flowtriq

From indie hosts to ISPs, see how teams like yours use Flowtriq to detect and stop DDoS attacks.

All Use Cases → Talk to Us →
Infrastructure
Hosting Providers ISPs MSPs/MSSPs Small Operators Routers Edge Node Defense Proxy Providers VPN Providers
Gaming & Entertainment
Game Server Hosting Game Studios Esports Platforms iGaming & Sportsbooks
Business & Emerging
SaaS Platforms E-Commerce Financial Services Compliance VoIP & Cloud Calling GPU & AI Cloud
Last updated: June 14, 2026

Does Flowtriq work on AWS, cloud, or serverless?

Flowtriq works on any Linux cloud VM. It does not work on serverless platforms where there is no host OS to install an agent on. This page covers every major cloud provider and deployment model.

Compatibility

Cloud platform compatibility matrix

PlatformWorks with Flowtriq?DeploymentCloud firewall API
AWS EC2Yesftagent on each instanceAWS Shield Advanced orchestration
GCP Compute EngineYesftagent on each instance-
Azure VMsYesftagent on each VM-
DigitalOceanYesftagent on each DropletYes (Cloud Firewall API)
VultrYesftagent on each instanceYes (Firewall API)
Linode / AkamaiYesftagent on each LinodeYes (Firewall API)
OVH / HetznerYesftagent on each serverOVH VAC + Hetzner DDoS scrubbing
Docker / KubernetesYesftagent on host node (DaemonSet for K8s)-
AWS LambdaNoNo host OSUse AWS Shield
GCP Cloud RunNoNo host OSUse GCP Cloud Armor
Cloudflare WorkersNoNo host OSUse Cloudflare DDoS Protection
Azure FunctionsNoNo host OSUse Azure DDoS Protection

Complementary

Flowtriq complements cloud provider protection

Every major cloud provider includes basic DDoS protection. Flowtriq adds per-instance visibility, forensics, and automated response that provider-level protection does not offer.

AWS Shield Standard + Flowtriq

AWS Shield Standard is free and protects all AWS resources against common L3/L4 DDoS attacks at the network edge.

Flowtriq adds: per-instance detection, attack classification with confidence scoring, PCAP forensics, custom alert channels (Slack, PagerDuty, Discord), audit logging, and automated on-instance mitigation rules. Shield Standard does not provide per-instance visibility or forensic evidence.

Cloudflare + Flowtriq

Cloudflare proxies HTTP/S traffic and absorbs DDoS at its edge network.

Flowtriq adds: detection for non-HTTP protocols (UDP, DNS, game traffic), per-server PCAP evidence, infrastructure-layer visibility behind the Cloudflare proxy, and BGP mitigation for traffic that does not flow through Cloudflare.

OVH / Hetzner + Flowtriq

OVH VAC and Hetzner DDoS Protection scrub traffic at the provider edge.

Flowtriq adds: per-server visibility into what attacks reached your server, forensic evidence (PCAP, classification), alerting, and audit trails. Provider scrubbing mitigates; Flowtriq shows you what happened and generates compliance evidence.

Multi-cloud deployments

If your infrastructure spans AWS, GCP, bare metal, and a colo, each provider has its own DDoS tooling with different dashboards and alert formats.

Flowtriq provides: a single dashboard for DDoS detection across all providers. Same agent, same alerts, same incident format regardless of where the server runs.

Serverless

What about serverless?

Flowtriq cannot protect serverless functions (AWS Lambda, GCP Cloud Run, Cloudflare Workers, Azure Functions) because there is no host operating system to install an agent on. These platforms abstract away the server entirely.

For serverless DDoS protection, use your platform's built-in options:

  • AWS Lambda: AWS Shield Standard (free, automatic) or Shield Advanced (paid, with response team)
  • GCP Cloud Run: GCP Cloud Armor (WAF + DDoS protection)
  • Cloudflare Workers: Cloudflare's built-in DDoS protection (automatic, unmetered)
  • Azure Functions: Azure DDoS Protection Standard

If your architecture is hybrid (some serverless + some VMs/bare metal), Flowtriq protects the VM/bare-metal portion while provider tools cover the serverless functions.

FAQ

Cloud questions

Does Flowtriq work on AWS?

Yes. ftagent runs on any EC2 instance running a modern Linux distribution. It provides per-instance DDoS detection, attack classification, PCAP forensics, and automated mitigation via iptables/nftables rules and cloud scrubbing (including AWS Shield Advanced orchestration). It complements AWS Shield Standard, which provides free basic L3/L4 protection.

Does Flowtriq work on GCP?

Yes. ftagent runs on Compute Engine instances. Install via pip, connect to the dashboard, and detection is active in under 60 seconds. GCP's built-in network protection handles basic volumetric attacks; Flowtriq adds per-instance visibility, classification, forensics, and automated response.

Does Flowtriq work on Azure?

Yes. ftagent runs on Azure VMs running Linux. Azure DDoS Protection Standard operates at the network edge; Flowtriq provides per-VM detection, PCAP forensics, alerting, and mitigation orchestration that Azure does not offer at the instance level.

Does Flowtriq work on DigitalOcean, Vultr, or Linode?

Yes. ftagent runs on Droplets (DigitalOcean), Vultr instances, and Linode/Akamai compute instances. Flowtriq also integrates with the cloud firewall APIs of these providers to auto-deploy blocking rules when attacks are detected.

Does Flowtriq work on serverless (Lambda, Cloud Run, Workers)?

No. Serverless platforms do not provide a host OS to install an agent on. Flowtriq requires a Linux server where ftagent can run. For serverless DDoS protection, use your cloud provider's built-in options: AWS Shield, GCP Cloud Armor, or Cloudflare's proxy.

Does Flowtriq work in containers and Kubernetes?

Yes. ftagent runs on the host node in a containerized environment. It monitors network traffic at the kernel level regardless of container orchestration. For Kubernetes, install ftagent as a DaemonSet on each worker node.

Does Flowtriq need BGP to work on cloud?

No. BGP FlowSpec and RTBH are optional features for operators with BGP infrastructure. On cloud VMs, Flowtriq provides full detection, classification, PCAP forensics, alerting, and on-node mitigation (iptables, nftables) without any BGP configuration. Cloud firewall API integrations (DigitalOcean, Vultr, Linode, Cloudflare WAF) provide additional cloud-native mitigation.

Can I use Flowtriq with AWS Shield Advanced?

Yes. Flowtriq detects attacks at the instance level and can trigger AWS Shield Advanced scrubbing as one of its 9 cloud scrubbing provider integrations. AWS Shield Advanced handles volumetric traffic absorption; Flowtriq provides detection, classification, and forensics.

Works on any Linux cloud VM.

14-day free trial. 60-second install. No credit card required.

Start Free Trial → See Pricing