XTM Hub by Filigran
Log inSign up
Flowtriq DDoS Incidents logo

Flowtriq DDoS Incidents

Automatic deploy
Supported by community
Detection & Response Enablement

Overview

Imports DDoS attack incidents from Flowtriq as STIX threat intelligence, including target IPs, attack types, severity, and source IPs.

The Flowtriq connector imports DDoS attack incident data from the Flowtriq network monitoring platform into OpenCTI as STIX 2.1 threat intelligence.

Flowtriq detects volumetric DDoS attacks in real time using NetFlow and sFlow analysis. This connector periodically polls the Flowtriq REST API to retrieve resolved or active incident records, then transforms target IPs, attack metadata, and source IPs into STIX Observables and Indicators.

Each incident produces an IPv4 or IPv6 Observable for the attack target, along with optional Indicator objects containing STIX patterns. Attack metadata such as type (SYN flood, UDP flood, DNS amplification), severity, peak volume (PPS/BPS), and timestamps are preserved as labels and descriptions.

When source IP data is available from Flowtriq's Service Port detection, the connector also creates Observables and Indicators for attacker source IPs, linking them back to the target infrastructure.

TLP markings, confidence scores derived from severity, and external references to the Flowtriq dashboard are applied to all objects for proper attribution and sharing controls.

Basic information

Flowtriq DDoS Incidents
Vendor Contact
Connectors
7.261008.0
0
https://flowtriq.com/contact

    We use cookies to run XTM Hub. Necessary cookies are always on, optional cookies (functionality, analytics, marketing) are used with your consent. Accept all, reject all, or manage your choices anytime in "Cookie settings".