network threat intelligence · real-time

Anticipate
your
security.

Built by a former ISP engineer after 30 years on the frontlines. clone-DDOS Pro delivers dynamic, real-time threat intelligence to protect your infrastructure before attacks land.

1M+
ban events tracked
134K
threat IPs catalogued
70K+
ASNs monitored
5 yrs
of historical data
clone-ddos · live feed · eu-fr probe
[ 2s ago ] BAN 160.119.76.55 SC · AS37105
[ 5s ago ] BAN 185.220.101.45 DE · AS51396
[ 8s ago ] PROBE 45.139.122.80 NL · port 3306
[ 12s ] BAN 49.213.225.146 ID · AS4761
[ 15s ] PROBE 193.32.162.28 RO · port 22
[ 19s ] BAN 178.62.216.118 GB · AS14061
[ 23s ] PROBE 62.60.130.237 DE · port 9090
[ 28s ] BAN 20.14.93.239 US · AS8075
→ firewall rules updated · 368 probes/h

Security tools that react.
Not anticipate.

30 years running ISP infrastructure taught us one thing: by the time you know you're under attack, it's already too late.

Blind to the outside

Traditional firewalls log what hits them. They have zero visibility on what is preparing to hit them. Your perimeter is invisible until the first packet arrives.

Static blacklists

Spamhaus and similar services focus on spam/email. Threat IPs change constantly. By the time a list is updated, the attack vector has moved. You need real-time, not yesterday's data.

Cost and complexity

Enterprise-grade threat intelligence (CISCO, Akamai) is accessible only to large operators. Small and mid-size providers are left with open-source patchwork that requires deep expertise.

Collective intelligence.
Individual protection.

A distributed network of probes collects threat data from servers worldwide. Your firewall benefits from every observation made by every node.

01
Deploy a probe

One-line install on your server. The probe passively captures all unauthorized connection attempts via kernel-level logging.

02
Data flows to the network

Your observations — IP, port, ASN, country — are aggregated in real-time across all probes in the nearest GeoIP node.

03
Intelligence is shared

Every participant benefits from the collective. An IP seen attacking a probe in Singapore protects a server in Paris within seconds.

04
Firewall auto-updates

Pro and Enterprise tiers push blocking rules directly to your firewall in real-time. No manual intervention required.

compatible platforms
CentOS Stream / RHEL
Stream 9, Stream 10
AlmaLinux 8/9
Rocky Linux 8/9
✓ recommended
Debian
Debian 11 (Bullseye)
Debian 12 (Bookworm)
✓ recommended
Ubuntu Server
20.04 LTS
22.04 LTS
24.04 LTS
✓ recommended
Other
Fedora 39+
openSUSE Leap 15.5
RHEL 8/9
✓ supported
kernel ≥ 4.14 (nftables support)
python 3.8+
vps type KVM or bare metal (not OpenVZ)
access root required
not supported Windows · FreeBSD · Docker · OpenVZ · CentOS 7

"I spent 30 years running ISP networks. Every DDoS, every intrusion attempt, every sleepless night taught me the same lesson: we were always one step behind."

— founder, clone-DDOS · former ISP engineer

clone-DDOS Pro was built from real operational pain. Not a product roadmap. Every feature exists because someone needed it at 3am during an incident.

  • 01
    Prevention, not reaction

    Block known attackers before they reach your services. Dynamic rules updated from live network observations.

  • 02
    ISP-grade intelligence, SMB price

    The same threat visibility previously available only to major operators. Now accessible to any hosting provider.

  • 03
    Privacy-first community

    Only network metadata collected. No packet contents, no user data. GDPR compliant by design.

  • 04
    Your data stays yours

    Local retention configurable. Aggregate stats shared with the community. Raw data stays on your probe.

Why not Spamhaus?

Spamhaus is excellent for email reputation. It was not built for infrastructure intrusion prevention. Here is the difference.

feature clone-DDOS Pro Spamhaus Enterprise SIEM
Real-time firewall updates ✓ Pro+ ~ custom
Network intrusion focus ✗ email only
Distributed probe network ~ ~ vendor
Port & ASN intelligence
Accessible to SMB/MSP ✓ freemium ~ basic free ✗ enterprise only
Self-hosted option ~ some
GDPR / privacy-first ~ ~ varies
Price free → subscription free (limited) → $$ $$$$$

No solution guarantees 100% protection. clone-DDOS Pro significantly reduces exposure surface through real-time collective intelligence.

Start free.
Scale when ready.

No credit card required to start. Upgrade when your infrastructure demands more.

community
Free / forever

For individual contributors. Contribute your data, get visibility in return.

  • 1 server
  • nftables kernel logging
  • Local stats dashboard
  • 30-day data retention
  • GeoIP probe (nearest)
  • Real-time firewall updates
  • fail2ban integration
  • Alerts & exports
→ join community
most popular
pro
TBD / server / mo

For hosting providers and MSPs managing multiple client servers.

  • Up to 20 servers
  • nftables + fail2ban
  • Real-time firewall rule push
  • 90-day data retention
  • Multi-client dashboard
  • Email & webhook alerts
  • Blocklist export
  • soon SNMP supervision
→ contact us
enterprise
Custom / on quote

For large operators, ISPs, and organizations with specific requirements.

  • Unlimited servers
  • Everything in Pro
  • Dedicated GeoIP probe
  • Custom data retention
  • SIEM integration
  • SLA guaranteed
  • soon SNMP full supervision
  • Dedicated support
→ request a quote

Pricing will be announced at service launch. Early partners benefit from founding rates.

Not ready for Pro?
Join the community first.

clone-DDOS started as an open, non-commercial project. The community platform remains free forever. Contribute your server's threat data, access global statistics, and help build the network that makes Pro possible.

→ clone-ddos.org
free · open · non-commercial