PacketGuard

DDoS mitigation · XDP / eBPF

DDoS protection built for hosting providers.

PacketGuard filters attack traffic with our own engine, built on XDP and eBPF, running on your hardware and your IPs. Real players stay connected. Everything else is dropped at the edge of your network.

01Platform

Why PacketGuard

Generic mitigation is tuned for web traffic sitting behind a CDN. Game servers are latency-sensitive UDP, where players feel every dropped packet. PacketGuard was built for them, and for the hosting providers who run them.

  1. In-house filtering engine

    We architected our own packet processor on XDP and eBPF and we maintain every line of it. No third-party scrubbing service sits between you and your traffic.

  2. Game server specialists

    Protocol-aware filters for Minecraft, Rust, Counter-Strike, DayZ, TeamSpeak and Unreal Engine servers. Handshake validation and query caching keep servers responsive during an attack.

  3. Your hardware, your IPs

    PacketGuard is licensed software that runs at the edge of your own network. No tunnels, no rerouting, no detour through someone else's data center.

  4. Real-time analytics

    A full control panel plus Grafana dashboards. Live traffic graphs, attack history, per-filter drop counts and packet samples, all in real time.

  5. Automatic mitigation

    Attacks are detected, classified and filtered without anyone clicking a button. You get an alert when it starts and a full report when it ends.

  6. No noticeable latency

    Filtering adds less than a millisecond. Your players and users never feel the protection layer.

02Filters

Built for game traffic

Game protocols are small, fast UDP. Generic DDoS filters either block them or wave everything through. PacketGuard understands how each game connects, so spoofed floods fail and real players get in.

RakNet

Minecraft Bedrock · Rust

Handshake validation for RakNet's connection sequence. Fake join floods are dropped before they ever reach the server, with per-player rate limits once a client is in.

A2S query cache

GoldSrc · Source 1/2 · Unity · UE4 · more

Server-browser queries are answered from an edge cache refreshed every few seconds and gated by a challenge cookie. Covers everything from Half-Life and the Counter-Strike family to Rust, Valheim, ARK and Quake Live.

Source & GoldSrc connections

Counter-Strike · Source dedicated servers

Connection validation for Source and GoldSrc engines, so only clients that complete a real handshake ever reach your game server.

DayZ

DayZ standalone

Join validation and join-rate limits that absorb fake connection floods without locking real players out of the queue.

TeamSpeak 3

Voice servers

Strict validation of new connections, tuned for the small, latency-sensitive packets voice traffic depends on.

Unreal Engine 5

Palworld · UE5 dedicated servers

Handshake validation for UE5 dedicated servers. Spoofed sources never get a session.

Beyond per-game filters

The same engine carries a set of protocol-level filters that work for anything you run, game or not. They are stateful by default and run symmetrically when traffic flows through us in both directions.

Stateful filtering
Every flow is tracked in a connection table, tens of millions at a time per node. Packets that don't belong to a known, validated session are dropped before they reach your server.
TCP SYNPROXY
The node completes the TCP handshake at the edge using SYN cookies and only hands fully established, legitimate connections to your backend, so SYN floods never touch it.
Symmetrical filters
When traffic passes through PacketGuard in both directions, filters use the reply path to confirm a session is genuine. Spoofed sources that can't complete the exchange are dropped.
UDP symmetrical generic filter
A protocol-agnostic UDP filter for any service we don't ship a dedicated filter for. It validates real two-way traffic, so unknown UDP games and applications still get flood protection.
Packet captures on attacks
Every mitigated attack is stored with full packet captures. Download the pcap straight from the panel to see exactly what hit you, by source, port and action.
Custom filters on request
Running something we don't list? Traffic falls back to the generic filters, and our engineers build dedicated filters for your protocols on request.

We keep filter internals private on purpose. Attackers read marketing pages too.

03Control panel

One panel for your whole network

The control panel shows live traffic, attack history and per-IP protection settings for every server you protect. Grafana dashboards are included for real-time stats.

Attack timeline

Every attack is recorded with start, end, peak traffic and target. Click into any incident for the full breakdown.

Packet samples and captures

Inspect sampled packets from any attack, filter by source, port or action, and download a full packet capture (pcap) of the incident.

Per-IP rules and presets

Set protection per IP, or apply a preset across many. Changes reach every node in seconds.

Grafana and real-time stats

Live dashboards for traffic, drops and filter activity. Watch an attack being mitigated as it happens.

Alerts

Email, Slack and webhook notifications when an attack starts and when it ends.

Audit log and SSO

Single sign-on, two-factor authentication and a log of every change made in the panel.

04Licensing

Runs on your network, not ours

PacketGuard is licensed to hosting providers, game studios and ISPs. You run the nodes. We provide the engine, the panel and the people behind them.

  • Runs on standard Linux servers, no special hardware required, though an XDP-compatible NIC helps for native, line-rate performance.
  • Updates apply under live traffic, without downtime or dropped connections.
  • Prometheus metrics and ready-made Grafana dashboards included.
  • REST API for everything the panel can do.
  • Onboarding and filter tuning together with our engineers, not a ticket queue.

Keep your servers online

Tell us what you host and we will set up a pilot on one of your prefixes.