DDoS SYN flood
DDoS floodDistributed SYN flood: many sources toward one target on port 80, no replies observed.
syn_rate_1s
Replay runs recorded metadata through the same passive pipeline the sensor uses. Nothing is transmitted to the monitored network: a run either reads a capture file from disk or generates metadata locally.
Controlled testing
Distributed SYN flood: many sources toward one target on port 80, no replies observed.
syn_rate_1s
Reflection and amplification: small port-53 requests answered by far larger responses toward the victim.
amplification_ratio_5s
Fixed-interval check-ins with a stable payload size to a destination the host never otherwise uses.
c2_beacon.periodicity_score
Data carried in long, unique, hex-encoded subdomains under a single zone, as TXT lookups.
dns_tunnel.dns_domain_length
Generated-domain lookups from one host; most return NXDOMAIN.
dga.dga_probability
One source probing port 445 across the whole subnet.
recon.unique_dst_ips_60s
One source enumerating many ports on a few hosts.
recon.unique_dst_ports_60s
Sustained outbound bulk upload to a new destination, after a deliberate baseline warm-up.
exfiltration.bytes_out_per_sec_60s_zscore
Ordinary traffic: established connections, cached DNS, low fan-out. Expect no alerts.
anomaly.anomaly_score
Benign traffic overlaid with every attack pattern, so the detectors must find the signal in the traffic.
flow_count
A scenario is deterministic: the generator is seeded, so the same scenario and event count replay the same metadata. Each card names the field its detector is expected to fire on.
Replay controls require an active operator session. Unlock in System diagnostics.
Upload a .pcap or .pcapng file. It is parsed by Zeek and ingested through the same pipeline (Zeek to features to detectors to fusion). Alerts stream live when Redis is available.