A hands-on sandbox for the one thing most DDoS explainers skip: where a defense sits decides what it can protect. It's live at kitsunetechnologies.org/ddos-sandbox.

What it does

You launch attacks at different layers of the stack, from volumetric floods to application-layer requests, and toggle defenses (rate limiting, a WAF, upstream scrubbing, connection limits) while three meters respond in real time: bandwidth, server load, and legitimate-user success rate. Turn on the wrong defense for the wrong attack and you watch it do nothing.

Why we built it

We run public-facing infrastructure with real attack traffic hitting it daily, so mitigation isn't theoretical for us. This turns what we've learned operating it into something you can poke at in a browser and actually understand, rather than a wall of text about SYN floods.