DDoSphere
Illustration

DDoS resilience testing

Prove your protection holds.

Controlled load against targets registered to your organisation, with the source of every reading shown. Watch it live, then keep the evidence.

Authorised, controlled, and yours to stop

DDoSphere is not a way to attack anyone. You run controlled load against infrastructure registered to your own organisation, on a schedule you set, from origins you choose, and you can stop it the moment you want. The point is not the load. The point is the proof that your protection stayed standing.

How it works

Four steps, from plan to proof.

  1. 1

    Plan the run

    Pick a target registered to your organisation, set the level and duration, choose the origins, and order the steps.

  2. 2

    Confirm and launch

    Type the target's name to confirm, then launch. Stop the whole run, or a single step, at any second.

  3. 3

    Watch it live

    Follow the run on the globe while offered load and response time are drawn as the readings arrive.

  4. 4

    Prove it held

    Keep the resilience rating, the first down event, and an evidence report you can hand to an auditor.

What you get

Everything a resilience run needs, and nothing it does not.

Every feature here runs today. We left the half-built ideas off the page on purpose.

Set up

  • Targets

    Domains and IP addresses registered to your organisation, auto-located on the map.

  • Plans

    A target, a level, and ordered steps that advance on their own or on your call.

  • Labels

    Tag plans and runs, then filter the dashboard by what you care about.

  • Team and roles

    Invite people as admin, operator, or read-only observer.

Run

  • Confirmed launch

    No run starts until the target name is typed back. Nothing fires by accident.

  • Emergency stop

    Halt the run or the current step instantly, without waiting for it to finish.

  • Scheduled runs

    Repeat a plan by the hour, day, week, or month, ending on a date or after a count.

  • Cloud and dedicated generators

    Load from cloud regions, from your own hardware, or both together.

Watch

  • Live globe and map

    Region-level origins converging on the target, drawn by hand on a canvas, no third party.

  • Timeline

    Offered load and response time over the run, with up and down marked from the monitor.

  • Compare runs

    Overlay two or three runs to see whether a fix actually moved the numbers.

  • Logs and notes

    Download the per-generator result files and keep notes against the run.

Prove

  • Resilience rating

    A 0 to 100 rating and a band for every run, to track resilience over time.

  • First down event

    When the target first stopped answering, from an independent HTTP monitor.

  • Evidence report

    Print or save it as PDF from the browser, plus a JSON evidence bundle.

  • Source IP list

    Export the static source IPs as CSV so your SOC or ISP can allow the load in advance.

In-app and email notifications Plans sized to your capacity, arranged with us

Resilience rating

One number you can watch over time.

Every run gets a rating from 0 to 100 and a band. It weighs whether the run completed, how many requests succeeded, how long the target kept answering, and how much response time slipped against a baseline.

Read it as a way to compare your own runs quarter to quarter, not as a certificate. The reading that matters most sits next to it: did the target stay up, and when did it first go down.

Resilience band

0–30

Weak

31–70

Partial

71–100

Strong

Bands are fixed thresholds on the rating. They describe a run, they do not grade your vendor.

Evidence

Something you can hand to an auditor.

Evidence report

Run identity, the steps as they ran, the readings, and what was covered. Print it or save it as PDF from the browser, and export a JSON evidence bundle.

Source IP list

The static IP addresses your load will come from, as CSV, so your SOC or ISP can allow them before the run instead of paging someone during it.

Run comparison

Put two or three runs side by side on response time, throughput, and success, to show a change held up.

Coverage

Cloud regions on six continents, or your own hardware.

Run from cloud regions worldwide, from dedicated generators on hardware you control, or both at once. The source IPs are static, so nothing about the run is a surprise to your defenders.

Americas

  • Virginia
  • California
  • Canada
  • São Paulo

Europe

  • Frankfurt
  • Ireland
  • Stockholm
  • Spain
  • Zurich
  • Milan

Middle East and Africa

  • Bahrain
  • UAE
  • Cape Town
  • Istanbul

Asia Pacific

  • Mumbai
  • Singapore
  • Tokyo
  • Hong Kong
  • Sydney

Regions are switched on per organisation. Dedicated generators run as containers on your own machines and join the same run as the cloud origins.

Get in touch

Show your protection what it is up against.

Plans are arranged with us, not bought from a checkout. Tell us the infrastructure you need to prove out and the load you want to stand against, and we will set you up.