Data
Data
These tables exist because the numbers circulating about DDoS are mostly true in the narrow sense and misleading in use — a capacity figure that describes a model you were not quoted, an amplification factor quoted as a constant when it is a measurement, a record that combined two providers who were counting different things.
Every dataset here carries its sources, its last-updated date and a visible changelog, and every one is downloadable as JSON and CSV with the same content as the page. Where a value could not be established it reads "not publicly documented" rather than being left blank or filled in by inference — the unknowns are the part that keeps the rest honest.
The rules behind all of it are written down separately, and it is worth reading before quoting any figure from here.
Start here
Datasets
DDoS attack vectors
A reference classification of DDoS attack vectors: layer, what each exhausts, whether it can be spoofed or reflected, and the first-line mitigation. Editorial classification; amplification magnitudes are in a separate sourced dataset.
17 Rows · 2026-08-15
UDP reflection and amplification factors
Bandwidth amplification factors for reflection-capable UDP protocols, transcribed from CISA alert TA14-017A. A factor is a measurement under stated conditions, not a constant — read the methodology note.
19 Rows · 2026-08-15
DDoS standards and primary references
RFCs, BCPs and NIST publications with direct DDoS relevance. Every URL fetched and every publication date read off the document itself.
17 Rows · 2026-08-15
DDoS mitigation vendor capabilities
On-premises DDoS mitigation products on identical fields, in alphabetical order, with "not publicly documented" used wherever a value could not be established. A directory, not a ranking.
6 Rows · 2026-08-15
Verified DDoS records, by metric
Peak bits/s, packets/s and requests/s records, each read from the reporting organisation’s own publication. Deliberately not a single ranked list: a terabits figure and a requests-per-second figure measure different things.
7 Rows · 2026-08-15
Public DDoS threat reports
Who publishes recurring DDoS threat data, what each one can actually see, and the methodology caveat that comes with it. Headline figures are deliberately not reproduced.
5 Rows · 2026-08-15
DDoS-relevant CVEs
Vulnerabilities whose impact is availability through resource exhaustion or amplification. Status, publication date and CVSS read from each NVD record. No exploitation detail.
9 Rows · 2026-08-15
Regulatory instruments with a DDoS dimension
Instruments bearing on availability, incident reporting or data location in a way that changes DDoS architecture. Rows exist only where the instrument could be reached and read.
6 Rows · 2026-08-15
Vendor jurisdiction exposure, by mechanism
The four legal mechanisms that follow a DDoS vendor’s home jurisdiction rather than the buyer’s: what each reaches, what sets it in motion, which document settles it, and which of them an architecture can remove. No vendor is named and no country is rated.
4 Rows · 2026-08-22