Flowtriq
What is Flowtriq?
Flowtriq is a SaaS platform that detects DDoS attacks in under one second and responds automatically through BGP FlowSpec, RTBH, cloud scrubbing, and on-host firewall rules. It is designed for hosting providers, ISPs, MSPs, game server operators, and any organization running its own Linux infrastructure.
How It Works
The Flowtriq agent installs on Linux servers in under two minutes via pip and runs as a systemd service. It samples packets-per-second and bandwidth from kernel-level network stats every single second, compared to the 30-60 second polling intervals typical of traditional monitoring tools. When traffic crosses a dynamic baseline threshold, the agent classifies the attack, opens an incident, fires alerts, and triggers mitigation, all within the same second.
Detection and Classification
Flowtriq identifies eight attack families including SYN floods, UDP floods, DNS amplification, ICMP floods, HTTP floods, and multi-vector attacks, each with protocol-level confidence scores. A sliding window p99 baseline adapts to normal traffic patterns automatically, reducing false positives without manual threshold tuning. Layer 7 detection analyzes web server access logs in real time to identify HTTP floods, credential stuffing, API abuse, and bot activity.
Mitigation and Response
When an attack is detected, Flowtriq can deploy 27 firewall rule types across iptables, nftables, ipset, ufw, and null routing, plus five kernel-level mitigation intents. For network-wide protection, it supports automated BGP FlowSpec and RTBH deployment. Cloud scrubbing integrations cover nine providers including Cloudflare, OVH, Hetzner, AWS Shield, DigitalOcean, Vultr, and Linode. Mitigation steps can be chained into automated incident response playbooks.
Forensics and Visibility
A 1,000-packet PCAP ring buffer captures pre-attack traffic automatically, providing forensic evidence from before the detection threshold was crossed. Flowtriq includes public status pages, a full audit log with SHA-256 hash chaining, IOC pattern matching against 65,000+ known threat indicators, and AI-generated incident summaries.
Alerting
Alerts are delivered through 12+ channels including Slack, Discord, PagerDuty, OpsGenie, SMS, email, and webhooks.
Validated Performance
In a documented incident during a live 240-participant cybersecurity event, the vendor states that Flowtriq detected a 48.3 Gbps multi-vector attack in 0.9 seconds and deployed upstream BGP FlowSpec mitigation in 11 seconds with zero participant disconnections. They further state this incident was independently covered by The AI Journal and National Law Review.
Pricing
Agent-based monitoring starts at $9.99 per node per month ($7.99 annually). Flow source pricing for sFlow/NetFlow/IPFIX ingestion ranges from $19-$49 per source per month. There are no per-seat charges, no traffic-volume surcharges, and no per-alert fees. A 14-day free trial is available with no credit card required.
Supported Platforms
Ubuntu 20.04+, Debian 11+, CentOS 8+, and any Linux-based router including VyOS, MikroTik CHR, and OpenWrt. Python 3.8+ required.
Categories & Use Cases
Technical Details
| Deployment Types | On-Premise, SaaS |
|---|---|
| Operating Systems | Linux |
| Mobile Application | No |
FAQs
How much does Flowtriq cost?
Flowtriq starts at $9.99.