Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a botnet-driven denial-of-service attack?

A botnet-driven attack uses compromised or automated devices to generate disruptive traffic. Owners of participating routers, cameras, servers or computers are often victims, not knowing participants.

Establish common coordination

Compare timing, target, traffic pattern, malware, configuration and tasking across examined sources. Common features can support central control; differences may reveal several botnets or unrelated systems.

On a participating device, preserve the agent, control channel, received task and owner context. A shared target and time support coordination but do not replace direct tasking or provider evidence.

Separate controller from autonomous traffic

One command can trigger thousands of devices, so every packet is not a human decision. Devices may continue retrying or executing schedules after active tasking stops.

Distinguish bot operator, control infrastructure, compromised device and innocent owner. Changes after blocking infrastructure may help identify automated continuation versus fresh commands.

Key takeaway

Prove botnet coordination through common agent, configuration and tasking evidence, keeping device owners, infrastructure and human control as distinct attribution layers.

Reference: CIM-201Cyber Incidents & Offender Methods