kentik Kentik Product Updates logo
Back to Homepage Subscribe to Updates

Kentik Product Updates

Latest features, improvements, and product updates on the Kentik Network Intelligence Platform.

Labels

  • All Posts
  • Improvement
  • Hybrid Cloud
  • Core
  • Service Provider
  • UI/UX
  • Synthetics
  • Insights & Alerting
  • DDoS
  • New feature
  • BGP Monitoring
  • MyKentik Portal
  • Agents & Binaries
  • Kentik Map
  • API
  • BETA
  • Flow
  • SNMP
  • NMS
  • AI

Jump to Month

  • July 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • July 2021
  • June 2021
  • May 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • October 2020
  • September 2020
  • June 2020
  • February 2020
  • August 2019
  • June 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • September 2018
  • August 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • July 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • April 2016
3 weeks ago

10 New Alert Policy Templates for Kentik Protect!

We are thrilled to drop a powerful batch of pre-configured Alert Policy Templates designed to level up your network defense, compliance posture, and threat visibility in a flash! Whether you are defending high-capacity service provider backbones, managing complex enterprise environments, or squashing aggressive DDoS vectors, we've got you covered.

Here is everything you need to know about what’s new, why it matters, and how you can tune these shiny new templates to fit your environment like a glove!

⚡ What’s New?

We’ve added 10 brand-new out-of-the-box policy templates targeting high-impact security risks, advanced carpet bombing tactics, and specialized outbound threats:

🛡️ Outbound Security & DDoS Vectors (Built for Service Providers & Complex Enterprise Networks)

Outbound threats are notoriously tricky for large-scale environments. Unmonitored outbound floods can quickly degrade upstream peering links, harm your IP reputation, or lead to costly transit overages. We’ve added dedicated templates specifically engineered for these topologies:

  • DDoS: Outbound Volumetric UDP Flood
    Catches internal source IPs or interface blocks generating abnormal outbound UDP traffic volumes. Crucial for service providers to spot compromised subscriber hosts or internal systems participating in outbound reflection/DDoS attacks before they disrupt transit capacity.
  • DDoS: Outbound TCP SYN Flood
    Detects sudden spikes in outbound TCP packets with only the SYN flag set originating from your internal IP space. Protects your brand reputation by catching compromised hosts launching outbound SYN floods.
  • Security: Internal Vertical IP Scanning
    Spots lateral movement and reconnaissance across complex networks by alerting when a single internal source IP attempts to sweep across an unusually high number of unique destination IPs.
  • Security: Threat Feed Compromised Hosts
    Flags internal network assets actively communicating with external threat infrastructure mapped directly against Spamhaus Botnet C&C nodes and malicious hosts.

🌐 Advanced Carpet Bombing Defense

Modern DDoS attacks don't always target a single IP with massive traffic—they scatter traffic across whole subnets to bypass traditional single-target thresholds. These templates give you multi-layered coverage against distributed attacks:

  • DDoS: Carpet Bombing CIDR Aggregation
    Identifies horizontal carpet bombing attacks spread across broad subnets, aggregating volumetric anomalies at the /24 routing prefix level.
  • DDoS: Carpet Bombing Port Fragmentation
    Detects fragmented, high-intensity stateless traffic (UDP, ICMP, reflection vectors) aimed at a wide array of destination IPs across a single target service port.
  • DDoS: Carpet Bombing Interface Impact
    Acts as an essential safety net by tracking traffic anomalies distributed across an entire downstream customer or internal interface block.

🔒 Geo-Compliance & Sanction Monitoring

  • Security: Embargoed Country Traffic (Tier 1)
    Monitors bidirectional traffic touching comprehensively embargoed nations and disputed territories to immediately flag high-risk compliance violations.
  • Security: Sanctioned Country Traffic (Tier 2) & Regime-Targeted Traffic (Tier 3)
    Provides granular compliance tracking for high-risk, sanctioned, or UN-embargoed jurisdictions across secondary tiers.

🎯 Why This Matters to You

  • Instant Protection, Zero Setup Hassle: No need to build complex flow filters or mathematical baseline models from scratch. These templates come with industry-tested baselines and static thresholds.
  • Protect Your Brand & Transit Capacity: For Service Providers and Enterprise Edge networks, catching outbound malicious floods ensures your IP space stays off global blocklists and preserves upstream provider SLAs.
  • Defend Against Stealthy Distributed DDoS: By aggregating traffic across /24 subnets, service ports, and entire interface blocks, you can stop carpet bombing campaigns that traditionally slip under single-IP alert radars.
  • Automated Regulatory Compliance: Maintain strict, automated compliance oversight against international sanction lists without setting up manual geo-fencing rules.

🛠️ How to Enable & Tune Policies for Your Network

By default, these templates are imported in a disabled state so you can safely review and tune them before going live.

Step 1: Enable the Template

  1. Head over to Alerting > Manage Alert Policies > Alert Policy Templates in the Kentik portal.
  2. Search for the template name (e.g., DDoS: Outbound Volumetric UDP Flood or DDoS: Carpet Bombing CIDR Aggregation).
  3. Then click the “Create policy from template” icon to add the alert policy to your account.

Step 2: Tailor & Tune to Your Environment

Every network has its own unique baseline. Here is how you can make these templates fit seamlessly:

Adjust Static & Baseline Thresholds:

  • For high-volume service provider backbones, you can scale up static packet/bit thresholds to match your transit capacities.
  • For tight enterprise environments, lower the required percentage jump above historical baselines.

Refine Traffic Filters & Boundaries:

  • Ensure your network boundary tags (e.g., internal vs external, or inside vs outside) are accurately defined so outbound flood and lateral scanning policies evaluate traffic correctly.

Attach Notifications & Automated Mitigations:

  • Link your team's preferred notification channels (Slack, PagerDuty, Webhooks, or Email) under the policy's Notifications section.
  • For DDoS templates, attach Mitigation Associations if you want Kentik Protect to automatically trigger RTBH, BGP Flowspec, or third-party mitigation platforms upon activation
Avatar of authorMatt Wilson