Back to Blog

New Alert Policy Templates for Kentik Protect: Security and Compliance Visibility in Minutes

Steve Stover
Steve StoverVice President of Product Marketing
feature-alerting

Summary

Securing distributed networks and maintaining regulatory compliance is often manual, expertise-heavy work of configuring alert policies. Kentik Protect now includes additional pre-configured, production-ready Alert Policy Templates across three categories: outbound security and DDoS, carpet bombing defense, and geopolitical compliance monitoring.


Alert Policies Dashboard

Detection expertise should not be a deployment bottleneck

Detection tooling has matured, but operationalizing detection for advanced threats still often depends on manual configuration. Teams must decide which traffic dimensions matter, establish meaningful thresholds, validate filters, and connect alerts to operational workflows. That work requires deep knowledge of protocols, network boundaries, traffic behavior, and the specific failure modes each policy is meant to detect.

The result is a familiar operational gap. A team may have the telemetry required to identify a threat or compliance issue, yet lack an alert policy that is ready to evaluate it. Defining precise thresholds for TCP SYN patterns or outbound UDP volume can require protocol expertise and historical traffic analysis. Deployment that should take minutes can stretch into weeks.

Regulatory monitoring introduces a second challenge. Manual IP blocklists and static geo-fencing rules cannot reliably keep pace with changing sanctions, embargoes, and geopolitical boundaries. Coverage becomes inconsistent just as security and compliance teams need it to be precise.

There is also an internal visibility problem. Reconnaissance activity, lateral scanning, and communications with known command-and-control infrastructure may remain undetected until they contribute to a larger breach investigation, a reputation issue, or unexpected egress costs.

Kentik Protect Alert Policy Templates convert hard-won detection expertise into capabilities teams can enable, review, and tune for their own environments.

Faster protection for the threats that matter

The new templates provide industry-tested starting points for high-impact security and compliance use cases. Teams do not need to build every flow filter, traffic boundary, and baseline model from scratch before they can begin monitoring.

For service providers and enterprises operating significant edge capacity, outbound malicious traffic is not only a security concern. It can degrade peering and transit capacity, expose IP space to reputation damage and global blocklists, and put upstream service-level commitments at risk. The outbound templates help identify compromised hosts and systems before their traffic becomes a wider operational problem.

The carpet bombing templates address a DDoS pattern designed to evade traditional detection. Rather than concentrating enough traffic on one IP address to trigger an alert, attackers distribute traffic across a subnet, service port, or interface block. Effective detection must aggregate the right traffic dimensions instead of evaluating each destination independently.

For enterprises with international infrastructure, compliance monitoring also needs to be continuous. The geo-compliance templates provide structured visibility into traffic involving embargoed, sanctioned, and regime-targeted jurisdictions without requiring teams to construct and maintain every policy manually.

What is new in Kentik Protect

This release adds ten Alert Policy Templates across three categories.

Outbound security and DDoS vectors

The first category helps identify outbound activity that can affect network capacity, customer experience, and IP reputation, as well as internal behavior that may indicate compromise.

  • DDoS: Outbound Volumetric UDP Flood identifies internal source IPs or interface blocks generating abnormal volumes of outbound UDP traffic. This policy helps surface compromised subscriber hosts, internal systems, or other assets participating in reflection and volumetric attacks before they consume transit capacity.

  • DDoS: Outbound TCP SYN Flood detects sudden spikes in outbound TCP packets with only the SYN flag set from internal IP space. These patterns can indicate systems launching SYN flood activity against external targets.

  • Security: Internal Vertical IP Scanning identifies internal reconnaissance and lateral movement by alerting when a single internal source attempts to connect with an unusually high number of unique destination IPs. Teams can tune this policy to distinguish expected activity, such as approved vulnerability scanning, from behavior requiring investigation.

  • Security: Threat Feed Compromised Hosts flags internal assets communicating with external infrastructure identified through Spamhaus command-and-control and malicious-host intelligence. This helps teams identify compromised systems that may otherwise blend into normal outbound traffic.

Alert Policies - Security

Advanced carpet bombing defense

The second category addresses carpet bombing attacks, which distribute traffic across multiple destinations to remain below single-target thresholds. These three templates provide complementary views across routing prefixes, service ports, and interface blocks.

  • DDoS: Carpet Bombing CIDR Aggregation identifies inbound volumetric anomalies aggregated at the /24 routing-prefix level, evaluating traffic entering the network from outside. This helps detect attacks dispersed across a broad subnet rather than concentrated on one IP address.

  • DDoS: Carpet Bombing Port Fragmentation detects high-intensity stateless traffic, including UDP, ICMP, and reflection vectors, distributed across many destination IPs but focused on a target service port. This pattern can reveal attacks intended to overwhelm a service while avoiding a per-host threshold.

  • DDoS: Carpet Bombing Interface Impact tracks distributed traffic anomalies affecting an entire downstream customer or internal interface block, evaluated on a per-device basis. It provides a safety net for attacks whose operational impact is visible as interface saturation across a device rather than at a single destination.

Alert Policy - Security

Geo-compliance and sanction monitoring

The third category supports ongoing visibility into traffic involving high-risk jurisdictions.

  • Security: Embargoed Country Traffic (Tier 1) monitors bidirectional traffic involving strictly embargoed nations, including Cuba, Iran, North Korea, and Syria, alongside specific contested regions and cities such as Donetsk, Luhansk, Crimea and Sevastopol, Simferopol, and Yalta. It is designed to flag high-risk activity requiring prompt compliance review.

  • Security: Sanctioned Country Traffic (Tier 2) provides tracking for traffic involving high-risk sanctioned nations, including Russia, Belarus, and Venezuela, that require ongoing oversight.

  • Security: Regime-Targeted Traffic (Tier 3) extends that coverage to regime and conflict regions subject to UN or human rights embargoes, including Afghanistan, Myanmar, South Sudan, Sudan, Libya, Somalia, the Democratic Republic of the Congo, and the Central African Republic. This gives organizations a more granular way to monitor policy-relevant network activity.

Together, these templates provide a layered compliance-monitoring model that teams can align to their own legal, regulatory, and governance requirements.

Enable, review, and tune policies for your environment

The templates are imported in a disabled state so teams can review their configuration before activating them. In Kentik, navigate to Alerting > Manage Alert Policies > Alert Policy Templates, find the desired template, and select Create policy from template.

From there, teams can tailor thresholds and traffic boundaries to reflect their environment. A high-volume service provider backbone may require higher static packet or bit thresholds, while an enterprise environment may require a lower percentage increase above its historical baseline. Accurate network boundary tags, such as internal and external or inside and outside, are particularly important for outbound flood and lateral-scanning policies.

Teams can then attach their preferred response workflow. Kentik Protect policies can notify operators through Slack, PagerDuty, webhooks, or email. DDoS policies can also be associated with mitigation actions, including RTBH, BGP Flowspec, and third-party mitigation platforms.

Bring alert policy context into AI Advisor

Because these policies run inside the Kentik platform, the alerts they generate become part of the enriched context available to Kentik AI Advisor. Teams do not have to leave an investigation to interpret what fired or why. They can ask about it directly in natural language. Operators can ask questions such as:

  • “Which alert policies fired most often in the last 24 hours, and what triggered them?”
  • “Show me the outbound UDP flood alerts from last night and the internal source hosts involved.”
  • “Summarize traffic to embargoed and sanctioned jurisdictions this week for our compliance report.”
  • “Is the internal vertical IP scanning alert on this host likely reconnaissance or an approved scanner?”

AI Advisor plans the investigation, queries the relevant telemetry, alert history, and traffic context, and returns a data-backed summary with clear follow-up paths. That is useful for recurring security and compliance reporting as well as one-off questions from engineers and leaders who need an answer without rebuilding the analysis each time.

AI Advisor - Sanctioned Country Alert

More than a template pack

Security and network operations teams increasingly work across the same traffic and infrastructure domains. Kentik provides cross-domain coverage for NetOps DDoS use cases and SecOps lateral-threat detection in one platform and query language. Teams do not need separate tools and separate operational models for each category.

Kentik’s streaming engine evaluates network telemetry in near real time at carrier-scale flow rates, supporting environments where traditional appliance-based approaches can struggle with scale or scope. Flexible baseline thresholds also reduce the tuning required to make policies useful in different network environments.

The goal is not to remove operator judgment. It is to give operators a reliable starting point, grounded in established detection logic, so they can spend less time assembling policies and more time validating, investigating, and responding to meaningful events.

The 10 new Alert Policy Templates are part of Kentik’s continuing investment in reducing setup friction while expanding practical, out-of-the-box coverage for security and compliance use cases. A future phase will add alert policy labels to make filtering and search in the template library easier as the catalog grows.

Start protecting your network today

Threats these templates address are not theoretical or static. Outbound floods, carpet bombing campaigns, internal reconnaissance, and traffic involving embargoed and sanctioned jurisdictions are already present on production networks, and the tactics behind them keep evolving. Detection that has to be built from scratch tends to arrive after the exposure it was meant to prevent. Enabling these templates now closes that gap, providing tested coverage for high-impact security and compliance risks in minutes rather than weeks.

Kentik brings that protection into the same network intelligence platform teams already use to detect, investigate, and mitigate threats across modern infrastructure, alongside the telemetry, alerting, and mitigation workflows that turn an alert into a response.

If you are an existing Kentik Protect customer, the new Alert Policy Templates are already available in your Alert Policy Templates library. Log in and enable the ones that fit your environment.

Not yet a customer? Request a demo, and we’ll show you how Kentik helps you detect, investigate, and mitigate threats across your network.

Explore more from Kentik

We use cookies to deliver our services.
By using our website, you agree to the use of cookies as described in our Privacy Policy.