Identifying potential DDoS cases based on ASN with KQL Queries
ID: cca0065b-6c1a-5593-af1e-7223b9089721
STIX ID: report--cca0065b-6c1a-5593-af1e-7223b9089721
Feed Name: Detect FYI
This article presents a defensive approach to identifying and mitigating DDoS activity by analyzing network telemetry with KQL, mapping RemoteIPs to ASNs, and detecting anomalies in connection patterns by ASN and country. It provides practical detection logic (e.g., low success-to-attempt ratios, sudden spikes vs. historical averages) using DeviceNetworkEvents, and recommends segmenting and routing traffic by ASN reputation to protect service performance (e.g., directing suspicious ASNs to isolated replicas via WAF or load balancers) while preserving access for trusted users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
