DDoS detection built for
internet infrastructure operators.
infra/STRUCTURE gathers the executives who run the internet's backbone. If protecting your infrastructure from DDoS is a priority, here's a platform built for operators — not enterprise buyers. $9.99/node/month, sub-second detection, BGP FlowSpec, PCAP forensics, unlimited team access.
The infra/STRUCTURE audience
Flowtriq is used by the operators who run the infrastructure that infra/STRUCTURE exists to serve.
The pricing reality
What legacy DDoS tools actually cost in 2026
FastNetMon launched LiveView in April 2026 — a web dashboard at $70/user/month on top of their $115+/month Advanced license. Here's what that adds up to for a NOC team, and how it compares.
Advanced license (10G): $115/month. LiveView dashboard: $70 × 3 users. Dedicated server: ~$100/month.
FastNetMon
- $115/mo base + $70/user/mo dashboard
- Dedicated server required (~$60–150/mo)
- 30–60s detection latency via NetFlow
- No PCAP forensics
- No multi-tenant isolation
- Trial by application — gated
Flowtriq — $9.99/node/month
- $9.99/node/month — unlimited users, dashboard included
- No dedicated server — runs on existing Linux hosts
- <1s detection — kernel-level, unsampled
- PCAP with pre-attack ring buffer
- Workspace-based multi-tenancy + RBAC
- 7-day free trial — no card, no application
Feature comparison
FastNetMon Advanced vs Flowtriq
The full breakdown for infrastructure leaders who make buying decisions on technical merit.
| Capability | FastNetMon Advanced + LiveView | Flowtriq |
|---|---|---|
| Detection | ||
| Detection method | NetFlow / sFlow (sampled) | Kernel-level, unsampled |
| Detection latency | 30–60s | <1 second |
| Attack classification | Flood type only | 7 families + confidence score |
| L7 HTTP flood detection | L3/L4 only | Access log parsing |
| BGP & Mitigation | ||
| BGP RTBH blackhole | Yes | Yes |
| BGP FlowSpec | Advanced only | Included |
| Automated FlowSpec | Manual | Confidence-gated + auto-rollback |
| Cloud API mitigations | No | Cloudflare, DO, Vultr, Linode |
| Operations & Scale | ||
| Web dashboard | +$70/user/mo | Included, unlimited users |
| Multi-tenant isolation | No | Workspace-based RBAC |
| REST API + Terraform | API Advanced only; no Terraform | Both included |
| Prometheus metrics | Advanced only | 15+ metric families |
| Forensics & Evidence | ||
| PCAP capture | Not available | Pre-attack ring buffer |
| AI incident summaries | No | Yes |
| Automated postmortems | No | PDF / HTML / JSON |
Technical architecture
How Flowtriq works
Built for operators who ask how the sausage is made before they buy it.
Kernel-level capture
AF_PACKET + BPF — every packet header inspected, unsampled, at line rate. No NetFlow tap. No router configuration changes.
EWMA baselines
Adaptive per-node baselines via EWMA. Auto-learns in ~5 minutes. Handles diurnal patterns and traffic growth without manual threshold tuning.
BGP FlowSpec automation
Confidence-gated rules with auto-rollback on confidence drop. Supports ExaBGP, GoBGP, BIRD 2, FRRouting. Under 2 seconds detection to BGP.
PCAP ring buffer
Rolling pre-attack buffer flushed at incident declaration — packet-level evidence attached to the incident record before the attack peaked.
Lightweight agent
<30 MB RAM, <0.1% CPU idle. systemd service. Any Linux kernel ≥ 3.10. No DPDK, no PF_RING, no kernel module required.
Multi-tenant RBAC
Workspace-based isolation with per-workspace alerting, reporting, and RBAC. Manage customer or team nodes independently with full access control.
Deploy before infra/STRUCTURE 2026
7 days full access. No credit card. No bandwidth questionnaire. Works on any Linux server you already operate.