Why I Built DDactic

Stav David — Founder

For a few years I ran DDoS tests. Different vendor environments, different architectures. I would help companies understand their attack surface and tune their defenses.

Most kickoff meetings followed the same pattern. We would sit with the security team, map assets together, ask about scope, topology, rate limit thresholds, existing protection configs. White-box, grey-box, somewhere in between.

Every time I thought: this is backwards. I am the attacker. I should already know this. A real attacker does not call ahead and ask. I should be the one telling the customer where the gaps are, not waiting for them to brief me first.

Then the engagement would end and we would deliver a PDF. Recommendations, best practices. That was useful. But the recon we had already done could have directly generated the hardening items: incident playbooks, WAF rules tuned to their specific endpoints.

I did not want to show up empty-handed. So I built DDactic.

Run a free scan Connect on LinkedIn