eHAWK DDoS logo
eHAWK DDoS
by Hexalon Technologies
Automated DDoS protection platform · Version 2.0

eHAWK DDoS: automated, network-level DDoS protection that watches every packet, every second.

eHAWK DDoS is an automated DDoS protection platform that watches all traffic coming into your network, blocks threats at the network level with AI anomaly detection and BGP RTBH mitigation, and gives you a clear dashboard to see what's happening in real time — written so anyone on your team can understand it.

28 capabilities 24/7 automated defence AI anomaly detection BGP RTBH black-hole
30–120sPre-attack warning window
50K+Known-bad IPs cross-checked
14Report types (PDF / CSV)
4Global threat databases queried
DDoS protection features

28 capabilities, organized around how you'll actually use them

From the moment traffic hits your network to the report you hand to management, eHAWK DDoS covers detection, blocking, intelligence, network-level defence, analytics, customer management, and operations — all from one browser tab.

Detection & Automated Blocking

Features 01–02, 09
FEATURE 01

Automatic Attack Detection & Blocking

  • Watches your traffic 24/7 — monitors data and packets flowing in every second
  • Spots an abnormal flood instantly and flags the source IP as an attack
  • Blocks attackers automatically at the network level — no human needed
  • Auto-unblocks after a configurable period (e.g. 30 minutes)
  • Manual block/unblock with a single click from the dashboard
  • Three trigger types: traffic threshold, AI flag, or known-bad IP match
FEATURE 02

Early Warning Radar (Pre-Attack Alert)

  • Scans every 12 seconds for IPs behaving suspiciously below the block threshold
  • Gives a 30–120 second head-start before your links saturate
  • Risk levels: CRITICAL, HIGH, or MEDIUM per suspicious IP
  • Live radar badge highlights the most dangerous current threat
FEATURE 09

Auto-Threshold Tuner

  • Analyses up to 90 days of your own traffic to recommend the right pps threshold
  • Prevents false alarms from thresholds set too low
  • Side-by-side recommended vs. current setting, applied in one click

Dashboard & Attack Intelligence

Features 03–06
FEATURE 03

Live Traffic Dashboard

  • Real-time Gbps and packets-per-second in and out of your network
  • Scrolling traffic-history graph over the last hour
  • Top attackers list and attack-type breakdown (SYN, UDP, Volumetric, Amplification, ICMP…)
  • Live updates every few seconds — no page refresh
FEATURE 04

Attack Intelligence

  • Attack category cards: Volumetric, UDP/Flow Flood, Protocol/SYN, Amplification, ICMP, Brute Force, Recon, AI Anomaly
  • Country-level breakdown as a bar chart
  • Full attack history with timestamps, type, volume, and severity (Low/Med/High/Critical)
  • Filter and search by IP, type, country, or date range
FEATURE 05

AI / Machine Learning Anomaly Detection

  • Learns your network's normal traffic patterns
  • Flags statistically abnormal traffic even below simple thresholds
  • Gives each event a threat score to prioritize response
  • Retrains automatically every 24 hours (or on demand)
  • Classifies attack types — not just "suspicious"
FEATURE 06

Threat Intelligence Feeds

  • Loads known-bad IPs from Emerging Threats, Feodo Tracker, Blocklist.de, Spamhaus, CINS Score, TOR exit nodes
  • Cross-checks AbuseIPDB, VirusTotal, Shodan, and GreyNoise for every blocked IP
  • Refreshes automatically every 6 hours
  • Dashboard shows total known-bad IPs loaded — typically 40,000–60,000+

Network-Level Defence

Features 07–08, 10
FEATURE 07

BGP / Network-Level Blocking (RTBH)

  • Advertises a black-hole route to your upstream router before attack traffic reaches you
  • Happens automatically the moment an IP is blocked
  • One-click manual announce/withdraw from the dashboard
  • Configurable AS number, peer AS, neighbor IP, next-hop, community string
  • Route table view, with automatic resync on restart
FEATURE 08

RTBH Effectiveness Report

  • Shows attacks stopped at the router vs. only at your server
  • Calculates bandwidth offloaded in Gbps
  • Gives management real numbers to justify BGP RTBH infrastructure
FEATURE 10

Smart GeoFence (Country Blocking)

  • Block all traffic from a consistently attacking country
  • AI ranks which countries to block based on your last 30 days of attacks
  • Every suggestion comes with attack count, unique IPs, and traffic volume
  • One-click add/remove instantly

Analytics, Reporting & Visualization

Features 11–17, 19–20
FEATURE 11

Persistent Threat Detection

  • Flags IPs blocked 3+ times as persistent threats
  • Shows attack count, first/last seen, avg. size, country, and ISP
  • Recommends permanent blocks for repeat offenders
FEATURE 12

Velocity Trend Analysis

  • Week-over-week comparison of ban counts, as a percentage change
  • 30-day sparkline to spot upward trends before they become a crisis
FEATURE 13

Bandwidth Saved Calculator

  • Converts blocked attack traffic into GB blocked and Gbps-hours
  • Estimates the dollar cost avoided — ready for a management report
FEATURE 14

Network Group Analytics (Campaign Detection)

  • Groups attackers by internet provider (ASN) to reveal shared infrastructure
  • Flags likely coordinated campaigns across multiple IPs from one provider
  • Cross-matrix view of attack types by provider
FEATURE 15

Live Cyber Attack Map

  • World map with live animated attack arcs and country colour-coding
  • Side panel lists the last 50 attack events in real time
FEATURE 16

SEA Submarine Cable Map

  • Visualises 15+ major undersea cable systems across South-East Asia & Indo-Pacific
  • Cable status shown as OK, Degraded, or Fault
  • Click any cable for capacity, length, operators, and year built
FEATURE 17

Protected Prefix Management

  • Register your own CIDRs so the system knows which prefixes belong to your customers
  • Automatic customer linking for attacks inside a registered prefix
  • Per-customer name, contact, SLA commitment, and plan tier
  • Per-prefix 30-day attack reports with PDF download
FEATURE 19

SLA Compliance Tracking (Time-to-Mitigation)

  • Records exact time between detection and block (TTM)
  • Colour-coded SLA compliance percentage — green/amber/red
  • Average, P50, P95, P99 response times, plus a daily trend chart
  • Breach table for every event that exceeded the SLA target
  • Configurable SLA target: 1, 2, 5, 10, or 15 minutes
FEATURE 20

Reporting

  • 14 report types — daily summary, weekly rollup, top attackers, heat map, SLA compliance, full incident reports, and more
  • Heat map by hour × day of week to spot cron-based botnets
  • CSV and server-generated PDF export — no headless browser needed
  • Scheduled daily (08:00 UTC) and weekly email reports

Customer Management & Alerts

Features 18, 21
FEATURE 18

Customer Portal

  • Separate scoped login per customer — they see only their own data
  • Per-customer dashboard: attacks on their prefix, SLA uptime, recent incidents
  • No access to your internals, other customers, or system configuration
  • Admin creates accounts and assigns the specific IP prefix owned
FEATURE 21

Alerts & Notifications

  • Email alerts via your own SMTP (Gmail, Office 365, or custom)
  • Deduplication — one alert per repeat IP, not a flood of emails
  • Escalation threshold for higher-priority alerts on repeat attacks
  • Webhook forwarding to Slack, Microsoft Teams, PagerDuty, or custom HTTP
  • SIEM integration (Splunk, IBM QRadar, Elastic SIEM, Graylog) in CEF syslog format
  • Prometheus metrics for Grafana dashboards

Access Control, Configuration & Operations

Features 22–28
FEATURE 22

IP Whitelist

  • Safe list for trusted IPs — never automatically blocked, even over threshold
  • Protects your own monitoring systems and trusted peers
  • Immune to all three block triggers: threshold, AI, and threat-intel
FEATURE 23

User Management & Access Control

  • Multiple operator accounts, each with its own login
  • Three access levels: Admin, Operator/Viewer, Customer
  • 2FA (TOTP) per user, resettable by admins
  • Named, revocable API keys — read-only or full-admin
  • 8-hour session timeout, 5-attempt account lockout, constant-time login
FEATURE 24

FastNetMon Configuration Editor

  • Change thresholds, traffic sources (NetFlow/sFlow/IPFIX), and notifications from the browser
  • Validates settings before saving
  • Restart the detection engine with a single click — fully audit-logged
FEATURE 25

Settings & Configuration

  • Every setting changed from the web UI — no SSH required
  • Configurable attack thresholds (pps/Mbps) and auto-unban duration
  • Per-table data retention for ban history, traffic logs, and audit logs
  • AES-256 encrypted configuration storage, including passwords and API keys
FEATURE 26

Audit Log

  • Every action logged: login, ban, unban, settings change, user creation, API key use, BGP advertisement, and 15+ more
  • Old and new values recorded for settings changes
  • Searchable, filterable, and CSV-exportable
  • Tamper-evident record for compliance and dispute resolution
FEATURE 27

Security Hardening

  • AES-256 encrypted config on disk — plain text is never written
  • Passwords hashed with scrypt and a unique random salt per user
  • Cryptographically secure session tokens; forced password change on first login
  • nftables kernel-level firewall integration; OWASP Top 10 protections built in
FEATURE 28

System Health

  • Service status panel for FastNetMon, AI engine, threat intel, PostgreSQL, and the dashboard
  • Server uptime display and in-browser FastNetMon log viewer
  • Start/stop any component with a single click — no SSH required
Summary

At a glance — what it does & why it matters

Every capability above translates into a concrete operational or business outcome.

What it doesBenefit to you
Blocks DDoS attacks in secondsYour network stays up during attacks
Early warning radar before attacks peakTime to act before links are saturated
Detects attacks with AI, not just rulesCatches new attack types automatically
Checks 50,000+ known bad IPsBlocks known criminals before they cause damage
BGP black-hole at router levelStops volumetric attacks before they reach your servers
Smart GeoFence suggestionsBlock the right countries based on your real attack data
Persistent threat trackingEscalate repeat offenders automatically
SLA compliance trackingProve your response-time commitment to customers
Customer portal with scoped accessResell DDoS protection to your own clients
14 report types with PDF and CSV exportCompliance-ready reports without extra tools
Scheduled daily and weekly email reportsStay informed without logging in every day
SIEM, webhook, and Prometheus integrationWorks with your existing monitoring stack
Full audit trailKnow exactly who did what, when
2FA on every user accountSecure even if a password is compromised
API keys for automationIntegrate with scripts and external systems
Everything managed from a browserNo command-line knowledge needed for daily operation
AES-256 encrypted configSensitive data is protected even if the server is compromised
FAQ

Frequently asked questions about eHAWK DDoS

What is eHAWK DDoS?

eHAWK DDoS is an automated DDoS protection platform that monitors network traffic 24/7, detects attacks with threshold, AI and threat-intelligence triggers, and blocks them automatically at the network level.

How does automated DDoS protection work?

eHAWK continuously analyzes traffic for volumetric floods and anomalies; when an attack is confirmed it blocks the source IP automatically, without requiring a human to intervene, and can auto-unblock after a configurable period.

Does eHAWK support BGP RTBH?

Yes. eHAWK can automatically advertise a BGP RTBH (remotely triggered black hole) route to your upstream router the moment an IP is blocked, stopping volumetric traffic before it reaches your edge — see how BGP RTBH mitigation works for the full mechanism.

How does AI anomaly detection work?

eHAWK's AI engine learns your network's normal traffic patterns, flags statistically abnormal traffic even below fixed thresholds, scores each event, and classifies the likely attack type automatically, retraining roughly every 24 hours.

Does eHAWK protect ISPs?

Yes. eHAWK includes protected-prefix management, per-customer SLA tracking and a multi-tenant customer portal built specifically for ISPs and network operators reselling DDoS protection — see what DDoS protection for ISPs requires.

How quickly can an attack be detected?

eHAWK's early warning radar scans every 12 seconds and can give a 30–120 second warning before an attack saturates your links, ahead of the automated block itself.

Does eHAWK provide attack reports?

Yes. eHAWK generates 14 report types, including daily and weekly summaries, SLA compliance and full incident reports, exportable as PDF or CSV.

Can customers access their own DDoS reports?

Yes. eHAWK's customer portal gives each customer a scoped login showing only their own prefix, attack history and SLA uptime, with no access to other customers or system configuration.

Get started

See eHAWK DDoS defend a live traffic feed

Request a walkthrough of the dashboard, early-warning radar, and BGP RTBH black-holing on your own network.