After 5 years of providing free DDoS monitoring service to the great security community, we have to regrettably shutdown our service due to circumstance that is beyond our control.
Thank you for your understanding.

DDoS Mon

Discover the global DDoS attacks


Ongoing DDoS attacks


IPs are attacked in last 24 hours


DDoS dedicated botnet attack commands

Open & Free

  • Open for security community, Free to use and cite.

Realtime DDoS Detection

  • CDN aware, track new ip updates in realtime
  • Instant Email Notification

Elaborate Attack Report

  • Full report with detailed break down
  • Get insights about the attack


  • Integration DDoSMon with your security infrastructure.

How does DDoSMon work?

We have partnership with multiple network service providers, some users also contribute their netflow traffic to us, plus, there is a dedicated DDoS botnet c&c tracking system in place to provide insights.

Combining all these data sources, we are able to compute and monitor quite a big chunk of ongoing DDoS attacks.

How to use DDoSMon?

Users may creates monitored objects they are interested, the object could be fqdn, zone, ip, or ip blocks. Then the system will automatically track traffic going to the defined objects.

If a traffic spike is detected with an object, an event is generated and the user can receive an email notification.

Who is behind the ddosmon project?

Network Security Research Lab at Qihoo 360, and we can be reached at