Detection, Mitigation & Response

Detect and mitigate DDoS attacks in under 1 second, respond automatically, and keep your users informed.

All features →
Learn
Documentation Quick Start API Reference Agent Setup DDoS Protection Landscape State of DDoS 2026 REPORT Free Certifications NEW
Research & Guides
Mirai Botnet Kill Switch Research memcached Amplification Dynamic Baselines PCAP Forensics PagerDuty Setup
Company
About Us Partners Managed Protection Whitelabel / Reseller Affiliate Program Pay with Crypto System Status
Legal & Support
Contact Us Security Trust Center Terms Privacy SLA
Who Uses Flowtriq

From indie hosts to ISPs, see how teams like yours use Flowtriq to detect and stop DDoS attacks.

Talk to Us →
Infrastructure
Hosting Providers ISPs MSPs/MSSPs Small Operators Routers Edge Node Defense
Gaming
Game Server Hosting Game Studios
Business
SaaS Platforms E-Commerce Financial Services Compliance

Exposure Scanning

Find what attackers see
before they use it.

Flowtriq scans each node for open services, amplification risks, weak TLS configurations, missing security headers, and exposed management interfaces. Every check runs from your server locally, with no external probes that could increase your attack surface.

40+
Security Checks
10
CVE Checks
7
Check Categories
8
SIEM Destinations

How It Works

One click, full audit. Scheduled or on-demand.

Click "Run Scan" on any node in your dashboard, or enable scheduled automatic rescans to run daily, weekly, or monthly. The agent runs all checks locally on the server, probing its own ports, services, and configuration. Results are sent back to your dashboard with severity ratings, descriptions, and remediation steps.

No external scanning services are used. No ports are opened. No traffic leaves your network. The scan runs entirely on the node itself, checking what services are accessible and how they respond.

Each finding is rated Critical, Warning, Info, or Pass, and the overall node receives a letter grade (A through F) based on its exposure profile. New findings trigger alert notifications to all configured channels.

exposure scan results
GRADE: B
Score: 78/100

CRITICAL UDP/53 open resolver detected
CRITICAL NTP monlist enabled (amplification risk)
WARNING  Missing X-Content-Type-Options header
WARNING  TLS certificate expires in 12 days
INFO     Server version exposed in headers
PASS     No SSDP/UPnP service detected
PASS     No open memcached on UDP/11211
PASS     HTTPS enabled with valid certificate
PASS     DNS zone transfer blocked

30 checks completed in 4.2s

What We Scan

Seven categories, 40+ individual checks

Every check runs on the node itself. No external services, no third-party APIs, no additional attack surface.

Open Ports

Scans for risky open TCP ports: Telnet (23), RDP (3389), SMB (445), MySQL (3306), PostgreSQL (5432), Redis (6379), Memcached (11211), and more. Flags services that should not be internet-facing.

Amplification Risks

Checks for UDP services that can be abused for amplification attacks: DNS open resolver, NTP monlist, SSDP/UPnP, SNMP, Memcached UDP, CharGEN, LDAP, mDNS, and TFTP. These turn your server into an unwitting attack amplifier.

DNS Configuration

Detects open DNS resolvers (anyone can query your server), zone transfer leaks (AXFR), and DNS recursion settings. Open resolvers are a top vector for DNS amplification attacks.

HTTP Security Headers

Checks for missing security headers: X-Frame-Options, X-Content-Type-Options, Strict-Transport-Security (HSTS), Content-Security-Policy, and X-XSS-Protection. Also detects server version leaks in response headers.

SSL/TLS Health

Validates TLS certificates: expiration dates, self-signed certs, certificate chain completeness, and HTTPS availability. Alerts when certificates are expiring soon or already expired.

CDN and Proxy Detection

Detects whether your server is behind a CDN (Cloudflare, AWS CloudFront, Akamai) or reverse proxy that provides DDoS protection. Flags direct IP exposure when CDN should be in front.

New

CVE & Known Vulnerabilities

Checks for 10 CVEs relevant to DDoS and server exposure: cPanel CVE-2026-41940 (unauthenticated reset), DNS amplification CVEs, NTP reflection CVEs, memcached UDP exploit checks, and Nginx/Apache misconfig CVEs. Database updated from NIST NVD and CISA KEV feeds.

SIEM & IDS/IPS Integration

Export findings to your security stack

Exposure scan findings and live attack events can be forwarded to your existing SIEM, SOAR, or IDS/IPS platform. Flowtriq supports push delivery to 8 destinations so your security team works in the tools they already use.

For Suricata and Zeek deployments, Flowtriq generates compatible rule/intelligence files from active attack data, keeping your on-premise IDS signatures current with real attacks against your infrastructure.

Splunk HECHTTP Event Collector push, JSON events
ElasticsearchBulk index API, configurable index name
Microsoft SentinelLog Analytics workspace via DCR
Syslog CEFRFC 5424 + CEF extension format
WazuhManager API integration, custom rule IDs
MISPEvent and attribute push, threat sharing
SuricataCompatible rules export from attack events
ZeekIntelligence feed files (IP, domain, cert)
flowtriq · siem export
Findings → Splunk HEC
POST https://splunk:8088/services/collector
200 OK (3 events queued)

Event 1:
{
 "sourcetype": "flowtriq:exposure",
 "check": "cve_cpanel_2026_41940",
 "severity": "critical",
 "node": "nyc-web-01",
 "remediation": "Patch cPanel"
}

Also sent to: Elastic, Sentinel, Wazuh
_

FAQ

Common questions

Does the scan open ports or expose my server?

No. The scan runs entirely on the node itself, checking its own services. It does not open ports, install listeners, or send traffic to external services. It is a passive audit of what is already running.

What CVEs does Flowtriq scan for?

Flowtriq currently scans for 10 CVEs relevant to DDoS and server exposure, including cPanel CVE-2026-41940, DNS amplification CVEs, NTP reflection vulnerabilities, memcached UDP exploit checks, and Nginx/Apache misconfig CVEs. The CVE database is updated automatically from NIST NVD and CISA KEV feeds.

How often should I scan?

Run a scan after any infrastructure change. You can also enable scheduled automatic rescans (daily, weekly, or monthly) from the dashboard so new findings surface without manual intervention.

What SIEM and IDS/IPS integrations are available?

Flowtriq exports findings to: Splunk HEC, Elasticsearch, Microsoft Sentinel (Log Analytics), Syslog CEF, Wazuh, and MISP threat sharing. Attack-time events can also be streamed as Suricata-compatible rules and Zeek intelligence feeds for your on-premise IDS/IPS.

Can attackers use the scan results against me?

Scan results are only visible to your workspace members in the Flowtriq dashboard. They are never shared, published, or sent to third parties.

Know your exposure before attackers do.

Run your first exposure scan in under a minute. No external tools, no additional attack surface.

Start Free Trial Read the Docs

FAQ

Frequently Asked Questions

Does the scan open ports or expose my server?

No. The scan runs entirely on the node itself, checking its own services. It does not open ports, install listeners, or send traffic to external services. It is a passive audit of what is already running.

What CVEs does Flowtriq scan for?

Flowtriq currently scans for 10 CVEs relevant to DDoS and server exposure, including cPanel CVE-2026-41940, DNS amplification CVEs, NTP reflection vulnerabilities, memcached UDP exploit checks, and Nginx/Apache misconfig CVEs. The CVE database is updated automatically from NIST NVD and CISA KEV feeds.

How often should I scan?

Run a scan after any infrastructure change. You can also enable scheduled automatic rescans (daily, weekly, or monthly) from the dashboard so new findings surface without manual intervention.

What SIEM and IDS/IPS integrations are available?

Flowtriq exports findings to: Splunk HEC, Elasticsearch, Microsoft Sentinel (Log Analytics), Syslog CEF, Wazuh, and MISP threat sharing. Attack-time events can also be streamed as Suricata-compatible rules and Zeek intelligence feeds for your on-premise IDS/IPS.

Can attackers use the scan results against me?

Scan results are only visible to your workspace members in the Flowtriq dashboard. They are never shared, published, or sent to third parties.