Network investigation guide
Investigating SYN Flood
A SYN flood overwhelms a host or service with large numbers of TCP connection requests, consuming connection capacity and reducing availability.
Understand the finding
What does SYN Flood mean?
A flood may be a deliberate denial-of-service attack, part of a larger traffic storm, or heavy legitimate and faulty traffic. Service health and the role of each endpoint establish the actual impact.
Triage workflow
How to investigate SYN Flood
- 1
Confirm service degradation, resource exhaustion, or packet loss during the event.
- 2
Identify top sources, targets, rates, duration, and whether addresses appear spoofed.
- 3
Compare the timing with tests, deployments, traffic campaigns, and infrastructure faults.
- 4
Review edge controls and hunt for intrusion activity that may be hidden by the disruption.
Interpret the context
Common benign explanations
Finding this behavior does not by itself prove malicious intent. Common explanations include:
- Load or performance testing and unusually heavy legitimate demand
- Backup, replication, streaming, or telemetry bursts
- Retransmission storms, loops, or a malfunctioning client
Make a decision
When to escalate or de-escalate
Escalate when
- The traffic causes measurable service degradation and has no approved explanation.
- The source is internal, indicating a compromised or malfunctioning system participating in the flood.
De-escalate when
- The event is an approved load test with expected impact and controls.
- Infrastructure evidence confirms a known fault or legitimate demand spike.
Analyze the evidence
Investigate network behavior with Red Hand
Red Hand turns network traffic into a report that identifies meaningful behavior, adds endpoint and process context when available, and provides practical investigation guidance.