|
|
|
|
|
by viraptor
1975 days ago
|
|
Sec/ops doesn't normally involve looking at live network capture snapshots all day. ("Eyes on glass" monitoring exists, but that's not for common services) You're not distracting people from spotting exfil. Either the company has the capacity to spot traffic anomalies like that or it doesn't. If they do, you're caught. If they don't, you're only giving them a reason to look in the logs because of DDoS. If your only issue was masking the higher network throughput, you can slow down. By starting DDoS you don't know what protections will be activated - it can be "running services in this state is useless, let's kill all of them until traffic stops". Or "there's lots of traffic to/from this AS, let's just kill that route". (it was your AS) |
|
No, but if the people on call are being drowned in alerts because everything is down due to the DDoS, an alert saying there's anomalous traffic ( if it's even capable to detect that during a DDoS, when all traffic would be anomalous depending on infrastructure) could be easily missed.