Web API endpoints are the part of the attack surface that gets the least testing. Login forms get tested. APIs get a "passes the smoke test" check and ship.
#cybersecurity #ddos #infosec
ddactic.net?ref=mastodon
Remote
0
Followers
0
Following
32
Posts
Joined April 06, 2026
Posts
Open post
Replying to
@ddactic@infosec.exchange
DDactic detects true BGP scrubbing by matching origin IP to a scrubbing-provider ASN (Prolexic, Magic Transit, Lumen, AT&T), and inherited L3/L4 from fully-managed components via CNAME (Cloudflare, Akamai, Fastly, Imperva, CloudFront) or vendor headers (API Gateway, ALB). Hyperscaler dedicated protection (Shield Advanced, Cloud Armor, Azure DDoS) requires customer-side config check. Free scan: ddactic.net/free-scan?ref=li-comment
0
0
0
0
Open post
Replying to
@ddactic@infosec.exchange
Full framework with the measurement recipe and common mistakes that poison the baseline: ddactic.net/blog/BLOG_POST_RATE_LIMIT_BASELINE
Free attack surface scan: https://ddactic.net/free-scan?ref=li-comment&utm_source=mastodon&utm_campaign=post_28
0
0
0
0
Open post
"Supports HTTP/2" and "inspects HTTP/2 frames" are not the same sentence. We probed 16 major vendors. The result is uncomfortable.
#cybersecurity #ddos #infosec
ddactic.net?ref=mastodon
0
0
0
0
Open post
Every major application-layer attack class has an HTTP version equivalent. Most defenses are written for HTTP/1.1. The gap is not theoretical.
#cybersecurity #ddos #infosec
ddactic.net?ref=mastodon
0
0
0
0
Open post
Replying to
@ddactic@infosec.exchange
This is what DDactic delivers after every scan - not a PDF, but the exact commands to harden your setup. See how it works: ddactic.net/blog/BLOG_POST_WAF_CONFIG
0
0
0
0
Open post
Replying to
@ddactic@infosec.exchange
Full research with signal matrix and vendor-by-vendor deep-dives: ddactic.net/blog/BLOG_POST_BOT_DETECTION_RE
Free attack surface scan: https://ddactic.net/free-scan?ref=li-comment&utm_source=mastodon&utm_campaign=post_24
0
0
0
0
Open post
I want to put a marker down because customers ask us how to evaluate other DDoS tests they receive from vendors and consultants.
#cybersecurity #ddos #infosec
ddactic.net?ref=mastodon
0
1
0
0
Open post
The login endpoint is the most consistently under-protected attack surface we see in customer scans. Most teams know it is a target. Few teams know how to enumerate the specific ways attackers hit it.
#cybersecurity #ddos #infosec
ddactic.net?ref=mastodon
0
0
0
0
Remote instance
infosec.exchange
Open on original server