Network investigation guide

Investigating SYN Flood

A SYN flood overwhelms a host or service with large numbers of TCP connection requests, consuming connection capacity and reducing availability.

Denial of service MITRE ATT&CK: T1499.001 OS Exhaustion Flood

What does SYN Flood mean?

A flood may be a deliberate denial-of-service attack, part of a larger traffic storm, or heavy legitimate and faulty traffic. Service health and the role of each endpoint establish the actual impact.

How to investigate SYN Flood

  1. 1

    Confirm service degradation, resource exhaustion, or packet loss during the event.

  2. 2

    Identify top sources, targets, rates, duration, and whether addresses appear spoofed.

  3. 3

    Compare the timing with tests, deployments, traffic campaigns, and infrastructure faults.

  4. 4

    Review edge controls and hunt for intrusion activity that may be hidden by the disruption.

Common benign explanations

Finding this behavior does not by itself prove malicious intent. Common explanations include:

  • Load or performance testing and unusually heavy legitimate demand
  • Backup, replication, streaming, or telemetry bursts
  • Retransmission storms, loops, or a malfunctioning client

When to escalate or de-escalate

Escalate when

  • The traffic causes measurable service degradation and has no approved explanation.
  • The source is internal, indicating a compromised or malfunctioning system participating in the flood.

De-escalate when

  • The event is an approved load test with expected impact and controls.
  • Infrastructure evidence confirms a known fault or legitimate demand spike.

Investigate network behavior with Red Hand

Red Hand turns network traffic into a report that identifies meaningful behavior, adds endpoint and process context when available, and provides practical investigation guidance.