DDoS Test Kickoff: Information We Need From You
A pre-kickoff checklist for scoping and preparing a DDoS resilience/attack simulation test
Table of Contents
To make the kickoff call as efficient as possible, please have the following ready beforehand.
1. Assets & Network Design
- In-scope IPs/CIDRs, hostnames, and FQDNs (plus anything explicitly out of scope).
- Basic network diagram: how traffic reaches the asset (edge, firewall, load balancer, origin).
- ASN/upstream provider, and whether cloud, on-prem, or hybrid.
- Environment: production, staging, or dedicated test.
2. Protection Measures
- Vendors/products in use (cloud scrubbing, on-prem appliance, CDN, WAF).
- Always-on vs. on-demand, and known detection/mitigation thresholds.
- Whether the mitigation vendor needs to be notified or on standby during the test.
3. Test Goals
- Primary objective (e.g., validate mitigation time, test a new deployment, compliance requirement, post-incident follow-up).
- Announced vs. unannounced, and black-box vs. white-box.
4. Services in Scope
- Which services: Web/HTTP(S), DNS, SIP/VoIP, APIs, etc.
- Relevant ports/protocols for each.
5. Past Attacks
- Dates, vectors, and rough scale of any prior DDoS incidents.
- Business impact and any changes made afterward.
6. Logistics
- Preferred test window and any blackout periods.
- Traffic/duration limits and abort criteria.