tcpdump -i any -p --dont-verify-checksums -NNnnvvv -s0 -B131072 -c10000 proto 6 and port 80 and tcp[13] == 2
assuming its port 80 and then strip out the IP addresses and share what that looks like. Bonus if they could capture a few of the known DDoS IP's and exclude the legit traffic. Curious if one of these things is not like the other. DDoS tools are often written by lazy people and rarely are they maintained.
lenova•4mo ago
More info: https://archlinux.org/news/recent-services-outages/