The DDoS Killchain

insides and usecases - DDoS Online Stresstests by zeroBS GmbH

The DDoS Kill Chain: Attacker Tactics and Defender Strategies

The DDoS Kill Chain, developed by zeroBS GmbH, provides a clear, cyclical model of how Distributed Denial of Service attacks unfold. Unlike a one-time event, it shows DDoS campaigns as an ongoing loop that attackers follow from initial scouting to post-strike evaluation. Understanding both sides – what the attacker does and what defenders can do to disrupt or harden each stage – is key to building effective resilience.

DDoS Kill Chain, developed by zeroBS GmbH

Here is a breakdown of the eight phases:

1. Reconnaissance (Information Gathering)

What the attacker does:

The attacker quietly maps the target’s digital footprint. This includes scanning for exposed IP addresses, identifying key servers and applications, cataloging network topology, spotting outdated software, and noting any existing security controls.

Defender’s options:

Implement strict network monitoring, disable unnecessary services, and use deception techniques like honeypots or fake assets to waste the attacker’s time. Regular audits and minimal public exposure of infrastructure details make reconnaissance far less fruitful.

How zeroBS can help

On our DDoS Threat Simulation Platform „Avydos“, we use an AI-driven reconnaissance workflow to perform exactly the same tasks during the reconnaissance phase that attackers would perform. This allows us to show our customers exactly what an attacker can “extract” from their infrastructure and how the attacker assesses the attack surface.

2. Preparation (Weaponization/Tooling)

What the attacker does:

Armed with target intelligence, the attacker assembles or rents the attack tools — botnets, custom scripts, amplification servers (DNS, NTP, etc.), and command-and-control infrastructure — to create a ready-to-deploy weapon.

Defender’s options:

Adopt proactive threat intelligence sharing, assess and minimize your attack surface, block known malicious tooling domains early, and maintain up-to-date patch management. There is really not much an organization can do, except awareness.

How zeroBS can help

By comparing an organization’s attack surface with its specific threat level, we can identify the expected attack vectors and specific attacks, thereby enabling a tailored and perfectly coordinated defense. That functionality is already built into our DDoS Threat Simulation Platform „Avydos“.

3. Distribution (Distribution/Deployment)

What the attacker does:

The attacker spreads the attack resources globally by infecting or renting thousands of devices, routing traffic through proxies, and positioning botnets so the flood appears to originate from countless unrelated sources.

Defender’s options:

Leverage global threat intelligence feeds, IP reputation databases, and geo-blocking where appropriate. Deploy upstream filtering with ISPs and use anycast-based scrubbing services to absorb or drop malicious traffic before it reaches the network edge.

How zeroBS can help

In our Avydos platform, we use the exact same botnet-style attack framework that enables the same geographic distribution, the same scale, and even the same proxy usage as real attackers, delivering a 100% realistic, real-world attack scenario when you want to test your defenses using our platform.

4. Attack Preparation (Pre-Attack Staging)

What the attacker does:

The attacker finalizes positioning: synchronizing bots, testing connectivity, staging traffic generators, and preparing backup vectors in case the initial plan fails.

Defender’s options:

Enable real-time traffic baselining and anomaly detection systems that flag unusual pre-attack behavior. Automated response playbooks can temporarily tighten access controls or alert security teams the moment suspicious staging activity is spotted.

How zeroBS can help

In our Avydos platform, we use the exact same botnet-style attack framework that enables the same geographic distribution, the same scale, and even the same proxy usage as real attackers, so you get a 100% realistic, real-world attack scenario when you want to test your defenses using our platform.

5. Poking (Test Attacks and Vulnerability Analysis)

What the attacker does:

Before committing full resources, the attacker launches small-scale probe attacks to measure the target’s response times, identify mitigation thresholds, and pinpoint the most effective attack vectors.

Defender’s options:

Treat even low-volume traffic as a warning sign. Rapidly activate temporary rate limiting, engage scrubbing centers early, and log probe attempts for immediate analysis. Behavioral analytics can distinguish test probes from normal traffic and trigger heightened alerts.

How zeroBS can help

During Redteaming-engagements we simulate exactly this attacker-behavior to test if your defense is able to detect the first phases of an attack. This allows organizations to determine whether they have a detection gap

6. Attack (Attack Execution)

What the attacker does:

The attacker unleashes the main assault — volumetric floods, protocol attacks, or application-layer strikes — aiming to overwhelm bandwidth, servers, or applications and knock services offline for legitimate users.

Defender’s options:

Rely on always-on DDoS mitigation platforms (cloud scrubbing, on-premises appliances, or hybrid solutions) that automatically absorb or filter massive traffic volumes. Combine this with web application firewalls (WAFs), API rate limiting, and content delivery networks (CDNs) to maintain availability.

How zeroBS can help

Using our platform, we can simulate all attackvectors and TTPs used by DDoS actors and thereby test whether the defenses are properly configured for each one or not. We can then help to make improvements based on the GAP analysis.

7. Escalation/Adaptation (Sustainment/Evasion)

What the attacker does:

If defenses start to work, the attacker adapts on the fly — switching vectors, rotating botnet sources, increasing volume, or using new evasion techniques to keep the pressure high and prolong the outage.

Defender’s options:

Use adaptive mitigation that automatically evolves with the attack. Maintain multiple layers of defense and rapid human-in-the-loop escalation so defenders can manually adjust rules, engage backup providers, or shift traffic to resilient infrastructure in real time.

How zeroBS can help

Our experienced red teaming consultants can identify defense mechanisms and, following the initial attacks, develop strategies to ensure that subsequent waves of attacks continue to have an impact. In this way, we can identify defense-limitations.

8. Termination and New Planning (Post-Attack)

What the attacker does:

Once goals are achieved or the attack becomes unsustainable, the attacker ceases operations, reviews what succeeded, erases traces where possible, and begins planning the next campaign using fresh lessons learned.

Defender’s options:

Conduct thorough post-incident analysis to identify gaps, update resilience plans, and strengthen weak points. Share anonymized attack data with industry peers and threat-intelligence platforms so the broader community can benefit and future attacks become harder for everyone.

Summary

The circular nature of the kill chain reminds us that attackers rarely stop after one campaign – each attack feeds the next. By applying layered defenses across every phase, organizations can break the chain early, reduce impact, and turn potential disasters into manageable incidents.

zeroBS GmbH’s holistic approach is built directly on this model, helping companies assess their current posture and implement tailored protections from initial evaluation through to continuous improvement. In today’s threat landscape, knowing both the attacker’s playbook and your own defensive playbook is the most effective way to stay resilient.

Our DDoS Threat Simulation Platform Avydos is the leading choice for automated DDoS testing. Built as a self-service cloud solution with 24/7 availability, it gives you full control to run DDoS simulations whenever you need them – quickly, independently, and without external dependencies.

The platform covers all attack vectors, from high-volume Layer 3/4 attacks to sophisticated Layer 7 application attacks, including both single and multi-vector combinations. This broad coverage helps you uncover weaknesses in your defenses that simpler tests often miss.

At the same time, Avydos is perfectly designed to support compliance efforts. It helps organizations meet requirements under DORA, NIS2, and similar regulations by providing continuous, documented resilience testing and clear reporting that auditors and regulators expect.

References

Avydos DDoS Threat Simulation and Automation Platform: https://avydos.com/en/

zeroBS DDoS Testing Services: https://zero.bs/en/

Infos & Contact

Cover Image: zeroBS

de_DEGerman

Ihr Anliegen

Kontaktaufnahme