RakNet
Minecraft Bedrock · Rust
Handshake validation for RakNet's connection sequence. Fake join floods are dropped before they ever reach the server, with per-player rate limits once a client is in.
DDoS mitigation · XDP / eBPF
PacketGuard filters attack traffic with our own engine, built on XDP and eBPF, running on your hardware and your IPs. Real players stay connected. Everything else is dropped at the edge of your network.
01Platform
Generic mitigation is tuned for web traffic sitting behind a CDN. Game servers are latency-sensitive UDP, where players feel every dropped packet. PacketGuard was built for them, and for the hosting providers who run them.
We architected our own packet processor on XDP and eBPF and we maintain every line of it. No third-party scrubbing service sits between you and your traffic.
Protocol-aware filters for Minecraft, Rust, Counter-Strike, DayZ, TeamSpeak and Unreal Engine servers. Handshake validation and query caching keep servers responsive during an attack.
PacketGuard is licensed software that runs at the edge of your own network. No tunnels, no rerouting, no detour through someone else's data center.
A full control panel plus Grafana dashboards. Live traffic graphs, attack history, per-filter drop counts and packet samples, all in real time.
Attacks are detected, classified and filtered without anyone clicking a button. You get an alert when it starts and a full report when it ends.
Filtering adds less than a millisecond. Your players and users never feel the protection layer.
02Filters
Game protocols are small, fast UDP. Generic DDoS filters either block them or wave everything through. PacketGuard understands how each game connects, so spoofed floods fail and real players get in.
Minecraft Bedrock · Rust
Handshake validation for RakNet's connection sequence. Fake join floods are dropped before they ever reach the server, with per-player rate limits once a client is in.
GoldSrc · Source 1/2 · Unity · UE4 · more
Server-browser queries are answered from an edge cache refreshed every few seconds and gated by a challenge cookie. Covers everything from Half-Life and the Counter-Strike family to Rust, Valheim, ARK and Quake Live.
Counter-Strike · Source dedicated servers
Connection validation for Source and GoldSrc engines, so only clients that complete a real handshake ever reach your game server.
DayZ standalone
Join validation and join-rate limits that absorb fake connection floods without locking real players out of the queue.
Voice servers
Strict validation of new connections, tuned for the small, latency-sensitive packets voice traffic depends on.
Palworld · UE5 dedicated servers
Handshake validation for UE5 dedicated servers. Spoofed sources never get a session.
The same engine carries a set of protocol-level filters that work for anything you run, game or not. They are stateful by default and run symmetrically when traffic flows through us in both directions.
We keep filter internals private on purpose. Attackers read marketing pages too.
03Control panel
The control panel shows live traffic, attack history and per-IP protection settings for every server you protect. Grafana dashboards are included for real-time stats.
Attack Timeline › 82.39.186.103
Attack on 82.39.186.103
Every attack is recorded with start, end, peak traffic and target. Click into any incident for the full breakdown.
Inspect sampled packets from any attack, filter by source, port or action, and download a full packet capture (pcap) of the incident.
Set protection per IP, or apply a preset across many. Changes reach every node in seconds.
Live dashboards for traffic, drops and filter activity. Watch an attack being mitigated as it happens.
Email, Slack and webhook notifications when an attack starts and when it ends.
Single sign-on, two-factor authentication and a log of every change made in the panel.
04Licensing
PacketGuard is licensed to hosting providers, game studios and ISPs. You run the nodes. We provide the engine, the panel and the people behind them.
Tell us what you host and we will set up a pilot on one of your prefixes.