h
s
FI ELD GUIDE TO FIGHTING DOS ATTACKS
re
AN G R Y
u
q
in
B OT
s
h
o
M
In thi s pl aybook I demonstrate ICMP,
SYN, and HTTP f loods with practical
examples; the att acks are mapped to
MITRE ATT&CK and NI ST f rameworks
so SOC teams can prepare an
acti ve‑ response pl an to defend
against DoS attacks.
BY MOHSIN QURESH
@MOH SI NQU RE SH OFFI CI AL MOH SI NM TJ@G M AI L .COM MOH SI N-QU R ESH
ANGRY BOT Pl aybook
h
s
re
This guide provides a repeatable, hands‑on method for
u
researching and identifying Denial‑of‑Service attacks in
q
controlled environments. It centers on three common attack
patterns ICMP floods, SYN floods, and high‑volume HTTP
in
GET/POST requests and maps each technique directly to the
s
MITRE ATT&CK and NIST frameworks to help SOCs and analysts
understand the threat in a standards‑based context. Use these
h
procedures only in authorized labs.
o
M
Today’s online platforms are exposed to both high‑volume and
application‑layer denial‑of‑service attempts. Such activity can
threaten service uptime and disrupt contractual performance
guarantees. The attack spectrum ranges from basic ICMP
flooding to sophisticated HTTP request patterns designed to
mimic real users.
INTENDED AUDIENCE
This playbook is designed for defenders in diverse roles
including blue‑team practitioners, SOC analysts, network
architects, and researchers focusing on detection, incident
response, and infrastructure hardening.
ETHICS & LEGAL NOTICE
All simulations and tests described in this playbook must be
carried out only within isolated labs where you have explicit
authorization. Conducting denial-of-service attacks against
systems you do not own or control is both illegal and
unethical. The procedures, configurations, and techniques
here are intended strictly for defensive research, detection
engineering, and permissioned testing.
WHOAMI?
h
s
re
u
q
in
s
h
o
M
I am Mohsin Quresh, a cybersecurity professional with
extensive experience in security research, penetration
testing, and threat analysis. I actively contribute as a
DEF CON Gurgaon Chapter Review Board member. I
am also a Security SME at Hack The Box (HTB) and a
chapter advisor for 0x0Pirates at Jamia Hamdard. My
work focuses on bridging practical cybersecurity
research with hands-on training, helping students and
professionals build strong defensive and offensive
security skills.