Detection, Mitigation & Response

Detect and mitigate DDoS attacks in under 1 second, respond automatically, and keep your users informed.

All features →
Docs
Documentation Quick Start API Reference Agent Setup Integrations 18
Learn
Free Tools 37 Free Certifications State of DDoS 2026 REPORT DDoS Protection Landscape Buyer's Guide PDF Hackathon Sponsorships DDoS Protection Facts
Company
About Us Become a Consultant 30% Partners White Label Managed Protection Contact Us System Status
Open Source
ftagent-lite MIT NetHawk MIT
Legal
Security Trust Center Terms & Privacy
Who Uses Flowtriq

From indie hosts to ISPs, see how teams like yours use Flowtriq to detect and stop DDoS attacks.

All use cases →

Integrations

Connect Flowtriq to your stack

DDoS detection and automated mitigation for firewalls, hosting panels, and routers. Install ftagent directly or receive NetFlow exports from your network gear.

pfSense

Export NetFlow from pfSense via softflowd to Flowtriq for real-time DDoS detection. Works with pfSense CE and pfSense Plus.

NetFlow Export

OPNsense

OPNsense has built-in NetFlow export with no plugins required. Enable it, point it at ftagent, and DDoS detection starts immediately.

Native NetFlow

cPanel / WHM

Install ftagent directly on your cPanel server for per-server DDoS detection. Protect every site on your shared hosting node.

Direct Install

Plesk

Direct agent install on Plesk servers. Real-time DDoS detection, automated firewall rules, and instant alerts for all hosted sites.

Direct Install

VyOS

Two deployment modes: install ftagent directly on VyOS, or export NetFlow from VyOS to an external ftagent host. Your choice.

Direct Install or NetFlow

WHMCS

Sell DDoS protection through your WHMCS storefront. Auto-provisioning, client area status, billing integration, and white-label support.

API Module

Blesta

Provision DDoS protection automatically when Blesta services are created. Client-facing status tab, incident history, and white-label dashboard access.

API Module

DirectAdmin

Hook-based provisioning for DirectAdmin. Every new user gets DDoS monitoring set up automatically, with per-package control.

Plugin + Hooks

Virtualizor

Auto-discover VPS instances from your Virtualizor panel and provision DDoS monitoring for each one. No plugin install needed.

API Auto-Sync

SolusVM v2

Connect your SolusVM v2 panel to auto-discover servers and provision monitoring. Pull-based integration with no SolusVM plugins required.

API Auto-Sync

Pterodactyl Panel

Automatic port sync, game-aware protocol classification, and on-node firewall rules for every game server your panel manages.

Addon + Auto Sync

Docker / Kubernetes

Run ftagent as a Docker container or Kubernetes DaemonSet. Official image on Docker Hub with docker-compose and DaemonSet examples.

Container Image

Agones GameServers

Detect DDoS attacks on individual GameServer pods and label them via the Agones SDK sidecar REST API for automated fleet response.

SDK Sidecar Labels

Proxmox VE

Deploy ftagent on Proxmox hosts for aggregate visibility, or inside individual VMs and LXC containers for per-tenant monitoring.

Direct Install

Vultr Cloud

Deploy ftagent on any Vultr instance. One-click Marketplace image or manual pip install with auto-setup via user-data.

1-Click Deploy

DigitalOcean

Deploy ftagent on DigitalOcean Droplets. 1-Click Marketplace app or manual install with auto-setup via user-data.

1-Click App

Linode / Akamai Cloud

Deploy ftagent on Linode instances. Marketplace app, StackScript provisioning, or manual pip install on Akamai cloud infrastructure.

Marketplace + StackScript

Splunk

Receive DDoS incident data in Splunk via HTTP Event Collector. Pre-built dashboard, CIM-compliant field mappings, and real-time attack visibility.

HEC + Add-on

MISP

Share DDoS attack intelligence with MISP. Export attacker IPs as structured events and enrich indicators with Flowtriq threat data.

Expansion + Export Module

CrowdSec

Feed DDoS attacker IPs into CrowdSec as ban decisions. Share threat intelligence with the CrowdSec community network and enforce blocks via bouncers.

Ban Decisions via LAPI

Elastic / Kibana

Ingest DDoS incidents into Elasticsearch with ECS-mapped fields. Pre-built Kibana dashboards for real-time attack visibility and SIEM correlation.

JSON Document Indexing

Microsoft Sentinel

Forward DDoS incidents to Microsoft Sentinel via Syslog CEF or direct API ingestion. Correlate network attacks with your broader SIEM workflow.

Syslog CEF / API

Flow Ingestion

Works with any router

The Flowtriq agent ingests NetFlow v5/v9, sFlow, and IPFIX (RFC 7011) from any router or switch that exports standard flow telemetry. Built-in config snippets for Juniper, Cisco IOS-XE, MikroTik, and VyOS.

Juniper Cisco MikroTik VyOS Arista Nokia Huawei Palo Alto Fortinet Cumulus / NVIDIA

For BGP mitigation: ExaBGP, GoBGP, BIRD2, or FRRouting. Works with any BGP-speaking router including Juniper, Cisco, MikroTik, VyOS, Arista, and Nokia.

Coming Soon

More integrations on the way

We are building integrations for more platforms. Let us know what you need.

DirectAdmin

Start protecting your infrastructure

Real-time DDoS detection starting at $9.99/node/month. Free 14-day trial with no credit card required.

FAQ

Frequently Asked Questions

What platforms does Flowtriq integrate with?

Flowtriq integrates with pfSense, OPNsense, cPanel/WHM, Plesk, VyOS, WHMCS, Blesta, DirectAdmin, Virtualizor, SolusVM, Pterodactyl Panel, Docker, Kubernetes, Proxmox VE, Agones, Vultr, DigitalOcean, Linode, Splunk, Elasticsearch, CrowdSec, MISP, and any platform that supports NetFlow v5/v9, sFlow, or IPFIX export. You can also install ftagent directly on any Linux server for direct packet-level monitoring.

Do I need to install Flowtriq on the firewall itself?

No. For firewall integrations (pfSense, OPNsense, VyOS), Flowtriq works by receiving NetFlow exports from the firewall. You install ftagent on a separate Linux machine. For hosting panels (cPanel, Plesk), ftagent installs directly on the server.

Can I use multiple integrations at the same time?

Yes. Each integration creates its own node in Flowtriq. You can run ftagent on your cPanel servers while also receiving NetFlow from your pfSense firewall, all reporting to the same Flowtriq account.