Stressthem is a high-capacity, low-latency stress testing platform engineered for penetration testers, network operators and security researchers. Push your infrastructure to its limits with controlled Layer 4 and Layer 7 attack vectors and find breaking points before attackers do.
Whether you are validating a new deployment, hardening a production load balancer, or simulating adversarial traffic for a red-team engagement, Stressthem gives you the tooling, the bandwidth and the visibility to do it safely, repeatably and at scale.
A globally distributed anycast network with more than 3 Tbps of dedicated stress-test capacity. Spin up a 100 Gbps flood in seconds and scale linearly without node warm-up, so your tests reflect what a real world-wide attack would actually look like.
Every target must be pre-authorized through DNS TXT verification, HTTP file challenge or signed ownership tokens. Unauthorized launches are blocked at the API gateway and reported to your account audit log for compliance traceability.
Real-time graphs for throughput (Gbps), packet rate (pps), target RTT and error ratios. Every job produces a downloadable HAR + PCAP-style capture so you can correlate client-side impact with infrastructure metrics in your own observability stack.
Forty-plus vectors spanning transport-layer floods (UDP, TCP SYN/ACK, ICMP, amplification) and application-layer floods (HTTP GET/POST/HEAD, SLOWLORIS, slow body, cache bypass). Each method is documented with parameters, expected impact and detection signatures.
A clean REST + WebSocket API lets you embed stress testing into CI/CD pipelines, chaos engineering workflows and on-call drills. SDKs available for Python, Go, Node.js and shell, with idempotent launches and signed webhooks for job completion.
Pre-warmed amplification pools and anycast routing mean the time between an API call and the first packet leaving our edge averages just 12 milliseconds. No queues, no cold starts — ideal for time-boxed chaos drills and incident game-days.
Modern infrastructure fails in two different places: at the network/transport layer where bandwidth and connection state are exhausted, and at the application layer where CPU, memory, sessions and databases are the bottleneck. Stressthem covers both, with distinct method families tuned for each.
OSI Layer 3–4 · IP / TCP / UDP / ICMP
Layer 4 methods target the network and transport stack. They aim to saturate the victim's internet pipe, exhaust firewall state tables, consume connection-tracking memory or fill NAT sessions. These vectors are bandwidth-heavy and state-driven — they do not care what application is running on the target, only that packets can reach it. Amplification techniques use misconfigured third-party services to multiply outgoing traffic by factors of 50x to 50,000x.
OSI Layer 7 · HTTP / HTTPS / WebSocket
Layer 7 methods target the application itself. They mimic legitimate user behavior at the HTTP/HTTPS level, consuming server CPU by triggering expensive endpoints, exhausting PHP-FPM / Tomcat / Node worker pools, draining database connection pools or filling session stores. These vectors require very little bandwidth — a single laptop can produce a damaging L7 flood — but they are extremely hard to detect because the traffic looks superficially identical to real users.
Transparent monthly plans for individuals, teams and enterprise security programs. No hidden launch fees, no per-job surcharges — what you see is what you pay. All plans include the full method catalog, the developer API and audit-log export.
Quick answers on legal use, supported methods, billing and integration. If something is missing, the documentation page has the long-form version with code samples.