eHAWK DDoS: automated, network-level DDoS protection that watches every packet, every second.
eHAWK DDoS is an automated DDoS protection platform that watches all traffic coming into your network, blocks threats at the network level with AI anomaly detection and BGP RTBH mitigation, and gives you a clear dashboard to see what's happening in real time — written so anyone on your team can understand it.
28 capabilities, organized around how you'll actually use them
From the moment traffic hits your network to the report you hand to management, eHAWK DDoS covers detection, blocking, intelligence, network-level defence, analytics, customer management, and operations — all from one browser tab.
Detection & Automated Blocking
Features 01–02, 09Automatic Attack Detection & Blocking
- Watches your traffic 24/7 — monitors data and packets flowing in every second
- Spots an abnormal flood instantly and flags the source IP as an attack
- Blocks attackers automatically at the network level — no human needed
- Auto-unblocks after a configurable period (e.g. 30 minutes)
- Manual block/unblock with a single click from the dashboard
- Three trigger types: traffic threshold, AI flag, or known-bad IP match
Early Warning Radar (Pre-Attack Alert)
- Scans every 12 seconds for IPs behaving suspiciously below the block threshold
- Gives a 30–120 second head-start before your links saturate
- Risk levels: CRITICAL, HIGH, or MEDIUM per suspicious IP
- Live radar badge highlights the most dangerous current threat
Auto-Threshold Tuner
- Analyses up to 90 days of your own traffic to recommend the right pps threshold
- Prevents false alarms from thresholds set too low
- Side-by-side recommended vs. current setting, applied in one click
Dashboard & Attack Intelligence
Features 03–06Live Traffic Dashboard
- Real-time Gbps and packets-per-second in and out of your network
- Scrolling traffic-history graph over the last hour
- Top attackers list and attack-type breakdown (SYN, UDP, Volumetric, Amplification, ICMP…)
- Live updates every few seconds — no page refresh
Attack Intelligence
- Attack category cards: Volumetric, UDP/Flow Flood, Protocol/SYN, Amplification, ICMP, Brute Force, Recon, AI Anomaly
- Country-level breakdown as a bar chart
- Full attack history with timestamps, type, volume, and severity (Low/Med/High/Critical)
- Filter and search by IP, type, country, or date range
AI / Machine Learning Anomaly Detection
- Learns your network's normal traffic patterns
- Flags statistically abnormal traffic even below simple thresholds
- Gives each event a threat score to prioritize response
- Retrains automatically every 24 hours (or on demand)
- Classifies attack types — not just "suspicious"
Threat Intelligence Feeds
- Loads known-bad IPs from Emerging Threats, Feodo Tracker, Blocklist.de, Spamhaus, CINS Score, TOR exit nodes
- Cross-checks AbuseIPDB, VirusTotal, Shodan, and GreyNoise for every blocked IP
- Refreshes automatically every 6 hours
- Dashboard shows total known-bad IPs loaded — typically 40,000–60,000+
Network-Level Defence
Features 07–08, 10BGP / Network-Level Blocking (RTBH)
- Advertises a black-hole route to your upstream router before attack traffic reaches you
- Happens automatically the moment an IP is blocked
- One-click manual announce/withdraw from the dashboard
- Configurable AS number, peer AS, neighbor IP, next-hop, community string
- Route table view, with automatic resync on restart
RTBH Effectiveness Report
- Shows attacks stopped at the router vs. only at your server
- Calculates bandwidth offloaded in Gbps
- Gives management real numbers to justify BGP RTBH infrastructure
Smart GeoFence (Country Blocking)
- Block all traffic from a consistently attacking country
- AI ranks which countries to block based on your last 30 days of attacks
- Every suggestion comes with attack count, unique IPs, and traffic volume
- One-click add/remove instantly
Analytics, Reporting & Visualization
Features 11–17, 19–20Persistent Threat Detection
- Flags IPs blocked 3+ times as persistent threats
- Shows attack count, first/last seen, avg. size, country, and ISP
- Recommends permanent blocks for repeat offenders
Velocity Trend Analysis
- Week-over-week comparison of ban counts, as a percentage change
- 30-day sparkline to spot upward trends before they become a crisis
Bandwidth Saved Calculator
- Converts blocked attack traffic into GB blocked and Gbps-hours
- Estimates the dollar cost avoided — ready for a management report
Network Group Analytics (Campaign Detection)
- Groups attackers by internet provider (ASN) to reveal shared infrastructure
- Flags likely coordinated campaigns across multiple IPs from one provider
- Cross-matrix view of attack types by provider
Live Cyber Attack Map
- World map with live animated attack arcs and country colour-coding
- Side panel lists the last 50 attack events in real time
SEA Submarine Cable Map
- Visualises 15+ major undersea cable systems across South-East Asia & Indo-Pacific
- Cable status shown as OK, Degraded, or Fault
- Click any cable for capacity, length, operators, and year built
Protected Prefix Management
- Register your own CIDRs so the system knows which prefixes belong to your customers
- Automatic customer linking for attacks inside a registered prefix
- Per-customer name, contact, SLA commitment, and plan tier
- Per-prefix 30-day attack reports with PDF download
SLA Compliance Tracking (Time-to-Mitigation)
- Records exact time between detection and block (TTM)
- Colour-coded SLA compliance percentage — green/amber/red
- Average, P50, P95, P99 response times, plus a daily trend chart
- Breach table for every event that exceeded the SLA target
- Configurable SLA target: 1, 2, 5, 10, or 15 minutes
Reporting
- 14 report types — daily summary, weekly rollup, top attackers, heat map, SLA compliance, full incident reports, and more
- Heat map by hour × day of week to spot cron-based botnets
- CSV and server-generated PDF export — no headless browser needed
- Scheduled daily (08:00 UTC) and weekly email reports
Customer Management & Alerts
Features 18, 21Customer Portal
- Separate scoped login per customer — they see only their own data
- Per-customer dashboard: attacks on their prefix, SLA uptime, recent incidents
- No access to your internals, other customers, or system configuration
- Admin creates accounts and assigns the specific IP prefix owned
Alerts & Notifications
- Email alerts via your own SMTP (Gmail, Office 365, or custom)
- Deduplication — one alert per repeat IP, not a flood of emails
- Escalation threshold for higher-priority alerts on repeat attacks
- Webhook forwarding to Slack, Microsoft Teams, PagerDuty, or custom HTTP
- SIEM integration (Splunk, IBM QRadar, Elastic SIEM, Graylog) in CEF syslog format
- Prometheus metrics for Grafana dashboards
Access Control, Configuration & Operations
Features 22–28IP Whitelist
- Safe list for trusted IPs — never automatically blocked, even over threshold
- Protects your own monitoring systems and trusted peers
- Immune to all three block triggers: threshold, AI, and threat-intel
User Management & Access Control
- Multiple operator accounts, each with its own login
- Three access levels: Admin, Operator/Viewer, Customer
- 2FA (TOTP) per user, resettable by admins
- Named, revocable API keys — read-only or full-admin
- 8-hour session timeout, 5-attempt account lockout, constant-time login
FastNetMon Configuration Editor
- Change thresholds, traffic sources (NetFlow/sFlow/IPFIX), and notifications from the browser
- Validates settings before saving
- Restart the detection engine with a single click — fully audit-logged
Settings & Configuration
- Every setting changed from the web UI — no SSH required
- Configurable attack thresholds (pps/Mbps) and auto-unban duration
- Per-table data retention for ban history, traffic logs, and audit logs
- AES-256 encrypted configuration storage, including passwords and API keys
Audit Log
- Every action logged: login, ban, unban, settings change, user creation, API key use, BGP advertisement, and 15+ more
- Old and new values recorded for settings changes
- Searchable, filterable, and CSV-exportable
- Tamper-evident record for compliance and dispute resolution
Security Hardening
- AES-256 encrypted config on disk — plain text is never written
- Passwords hashed with scrypt and a unique random salt per user
- Cryptographically secure session tokens; forced password change on first login
- nftables kernel-level firewall integration; OWASP Top 10 protections built in
System Health
- Service status panel for FastNetMon, AI engine, threat intel, PostgreSQL, and the dashboard
- Server uptime display and in-browser FastNetMon log viewer
- Start/stop any component with a single click — no SSH required
At a glance — what it does & why it matters
Every capability above translates into a concrete operational or business outcome.
| What it does | Benefit to you |
|---|---|
| Blocks DDoS attacks in seconds | Your network stays up during attacks |
| Early warning radar before attacks peak | Time to act before links are saturated |
| Detects attacks with AI, not just rules | Catches new attack types automatically |
| Checks 50,000+ known bad IPs | Blocks known criminals before they cause damage |
| BGP black-hole at router level | Stops volumetric attacks before they reach your servers |
| Smart GeoFence suggestions | Block the right countries based on your real attack data |
| Persistent threat tracking | Escalate repeat offenders automatically |
| SLA compliance tracking | Prove your response-time commitment to customers |
| Customer portal with scoped access | Resell DDoS protection to your own clients |
| 14 report types with PDF and CSV export | Compliance-ready reports without extra tools |
| Scheduled daily and weekly email reports | Stay informed without logging in every day |
| SIEM, webhook, and Prometheus integration | Works with your existing monitoring stack |
| Full audit trail | Know exactly who did what, when |
| 2FA on every user account | Secure even if a password is compromised |
| API keys for automation | Integrate with scripts and external systems |
| Everything managed from a browser | No command-line knowledge needed for daily operation |
| AES-256 encrypted config | Sensitive data is protected even if the server is compromised |
Frequently asked questions about eHAWK DDoS
What is eHAWK DDoS?
eHAWK DDoS is an automated DDoS protection platform that monitors network traffic 24/7, detects attacks with threshold, AI and threat-intelligence triggers, and blocks them automatically at the network level.
How does automated DDoS protection work?
eHAWK continuously analyzes traffic for volumetric floods and anomalies; when an attack is confirmed it blocks the source IP automatically, without requiring a human to intervene, and can auto-unblock after a configurable period.
Does eHAWK support BGP RTBH?
Yes. eHAWK can automatically advertise a BGP RTBH (remotely triggered black hole) route to your upstream router the moment an IP is blocked, stopping volumetric traffic before it reaches your edge — see how BGP RTBH mitigation works for the full mechanism.
How does AI anomaly detection work?
eHAWK's AI engine learns your network's normal traffic patterns, flags statistically abnormal traffic even below fixed thresholds, scores each event, and classifies the likely attack type automatically, retraining roughly every 24 hours.
Does eHAWK protect ISPs?
Yes. eHAWK includes protected-prefix management, per-customer SLA tracking and a multi-tenant customer portal built specifically for ISPs and network operators reselling DDoS protection — see what DDoS protection for ISPs requires.
How quickly can an attack be detected?
eHAWK's early warning radar scans every 12 seconds and can give a 30–120 second warning before an attack saturates your links, ahead of the automated block itself.
Does eHAWK provide attack reports?
Yes. eHAWK generates 14 report types, including daily and weekly summaries, SLA compliance and full incident reports, exportable as PDF or CSV.
Can customers access their own DDoS reports?
Yes. eHAWK's customer portal gives each customer a scoped login showing only their own prefix, attack history and SLA uptime, with no access to other customers or system configuration.
See eHAWK DDoS defend a live traffic feed
Request a walkthrough of the dashboard, early-warning radar, and BGP RTBH black-holing on your own network.