Targets
6
0 Online
Free real-time DDoS Dstat — Layer4 & Layer7 Dstat graphs for bandwidth, connections and requests.
Target Status Matrix
A real-time overview of all monitored Dstat targets — aggregate Layer4 / Layer7 DDoS Dstat traffic per server, with any target one click from its full live Dstat graph.
Targets
6
0 Online
Online
0/6
0%
Unprotected
4
67%
Protected
2
33%
The complete guide to live Dstat and FAQ
A Dstat — short for “destination statistics”, and often just called a live DDoS graph — shows, second by second, how much traffic a target server or website is taking. During a stress test or a DDoS attack it is a direct way to tell whether the target is absorbing the load or going down: bandwidth, packet rate and request rate are all plotted in real time.
This page is a live DDoS Dstat panel. The graph above refreshes every few seconds with second-level inbound and outbound throughput, so you can watch exactly how a target network behaves under Layer4 or Layer7 load.
Dstat graphs are usually split into two categories, named after the OSI layers they measure.
A Layer4 Dstat measures raw network traffic — TCP/UDP packets, bits per second and packets per second. It is used to gauge volumetric floods such as UDP, SYN or amplification attacks, where the goal is to saturate bandwidth or exhaust the network stack of the target.
Full Layer4 Dstat guide →A Layer7 Dstat measures application traffic — the HTTP/HTTPS requests per second that actually reach the web server. It reflects methods like HTTP floods or cache-bypass attacks, and shows whether protection layers such as UAM, captcha or a WAF are really filtering requests.
Full Layer7 Dstat guide →Reading a DDoS Dstat graph is straightforward once you know what each series means:
A flat line right after a spike usually means mitigation kicked in or the target dropped offline; a sustained plateau means the target is absorbing the load.
Each protection / statistics type has its own live Dstat page — from unprotected request counters to Cloudflare UAM and CAPTCHA challenge targets.
Dstat stands for “destination statistics”. It is a real-time graph of the traffic a destination (server, IP or website) is receiving, commonly used to observe how a target performs during a stress test or DDoS attack.
A Layer4 Dstat tracks raw network traffic (TCP/UDP packets, bits and packets per second), while a Layer7 Dstat tracks application traffic (HTTP/HTTPS requests per second reaching the web server). Layer4 reflects volumetric floods; Layer7 reflects request-based attacks.
Yes. The live Dstat graphs on this page are free, with no registration required. Additional tools are available through our Telegram bot.
The live Dstat graph refreshes every few seconds and shows a rolling 60-second window of second-level inbound and outbound traffic.
Yes — a Dstat is a passive measurement of traffic, and monitoring infrastructure you own or are authorized to test is the intended use. Never direct traffic at systems you do not have permission to test.
Pretty much — the two terms get used interchangeably. Both mean a real-time view of the traffic hitting a target, broken down by Layer4 and Layer7. That is exactly what this page is, and it is free to watch with no sign-up.