TL;DR: Sustained internet demand, higher DNS noise, and longer, more automated DDoS activity defined the end of 2025, with attackers increasingly using prolonged pressure rather than brief spikes to stress infrastructure, according to DigiCert. That shifts resilience from burst handling to continuous operations across DNS, network, and application layers.
At a glance
What this is: This is DigiCert's Q4 2025 threat intelligence brief on how sustained demand, DNS noise, and longer DDoS campaigns are changing internet resilience.
Why it matters: It matters because identity and security teams have to plan for continuous pressure on DNS, application, and availability controls, not just short-lived attack bursts.
Context
DDoS pressure and DNS noise now look less like intermittent events and more like a standing operating condition during busy periods. That changes the resilience problem from short recovery windows to sustained service protection across infrastructure, application, and operational layers.
For IAM, NHI, and platform teams, the governance question is not only whether a control exists, but whether it can keep working when load and probing remain elevated for weeks. The article's core point is that peak conditions are becoming normal conditions.
Persistent application probing also means misconfigurations and weak assumptions stay exposed for longer. That shifts attention toward continuous control performance, rather than reliance on a brief lull between attacks.
Key questions
Q: How should security teams prepare for sustained DNS and DDoS pressure?
A: Teams should plan for prolonged pressure, not just peak traffic. That means testing mitigation capacity, escalation paths, provider coordination, and staffing assumptions under multi-day conditions. DNS, application, and identity dependencies should be reviewed together so degraded availability does not quietly become degraded trust.
Q: Why do sustained DNS failures and NXDOMAIN noise matter to availability?
A: They matter because they show the environment is under constant pressure, not just occasional load. High background noise can hide reconnaissance, misconfiguration churn, and service degradation, so DNS monitoring has to focus on persistence and trend shifts as much as on acute errors.
Q: What are the signs that low-noise application probing is becoming a real risk?
A: Look for repeated request variation, unexpected cookie manipulation, steady automated activity, and control behaviour that changes under small input differences. Those signals show the application is being tested continuously, which often precedes exploit attempts or exposure of weak logic.
Q: When should organisations treat internet traffic growth as a resilience governance issue?
A: When demand stays elevated for weeks, the problem is no longer just capacity planning. It becomes governance over how DNS, network, and application teams coordinate under sustained pressure, because availability now depends on joined-up ownership rather than isolated controls.
Technical breakdown
Why sustained DNS load changes resilience planning
DNS is a dependency layer, so when query volume stays high for weeks rather than days, the control problem becomes endurance, not just capacity. NXDOMAIN spikes and repeated automated lookups are useful signals because they show background noise, misconfiguration churn, and reconnaissance pressure occurring at the same time. In that state, a resolver or authoritative service can remain technically available while still degrading user experience, increasing latency, or masking an active attack. Resilience therefore depends on keeping DNS observability, filtering, and response paths active under prolonged stress.
Practical implication: validate DNS handling against sustained load, not only peak-event traffic, and watch for prolonged NXDOMAIN and bot-generated query patterns.
How prolonged DDoS changes defensive assumptions
Traditional DDoS thinking often assumes short, sharp surges that can be absorbed or outlasted. DigiCert's brief describes a different pattern: longer, larger attacks that are designed to wear down infrastructure and defenders over time. That changes the operational model because scrubbing, rate limiting, and incident staffing must hold across a longer attack window. The risk is no longer only total outage. It is cumulative degradation, rising operating cost, and partial service failure that persists long enough to affect customers and downstream systems.
Practical implication: test whether your DDoS controls and response staffing can sustain multiday pressure without relying on a rapid attacker retreat.
Why automated application probing remains a governance issue
Application-layer attacks in the brief are described as persistent, automated testing rather than loud exploitation attempts. That matters because repeated probing can stay below obvious alert thresholds while steadily searching for weak cookie handling, misconfiguration, or logic gaps. The governance issue is not just detection, but whether application controls remain effective when requests are varied, continuous, and distributed. This is where runtime visibility, configuration discipline, and response speed matter more than periodic review alone.
Practical implication: treat ongoing low-noise probing as a control validation problem and monitor whether application protections still behave correctly under repetitive request variation.
Threat narrative
Attacker objective: The attacker objective is to wear down internet-facing services over time so that availability, responsiveness, and defensive capacity deteriorate under continuous pressure.
- Entry begins with sustained internet traffic and automated probes that blend into normal DNS and application demand, making the environment harder to distinguish from routine load.
- Escalation occurs as attackers extend DDoS activity in frequency, scale, and duration, turning short disruptions into prolonged pressure that drains defensive capacity.
- Impact is cumulative degradation across DNS, network, and application layers, with performance loss, higher operating cost, and greater customer disruption than brief spikes would create.
Breaches seen in the wild
- GitHub code signing certificate theft 2022: A machine account's compromised token cloned GitHub's Desktop and Atom repos, exposing encrypted signing certificates later revoked.
- CISA Private-CISA GitHub leak 2026: A CISA contractor's public GitHub repo exposed AWS GovCloud admin keys, Artifactory credentials and plaintext passwords for six months.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Sustained pressure is now the operating condition, not the exception: The article shows that DNS demand and malicious traffic both remained elevated for long stretches, which collapses the old assumption that teams can recover between spikes. That matters because resilience programmes built around burst handling can look healthy in calm windows while failing under continuous load. Practitioners should treat endurance as a control property, not a capacity afterthought.
Prolonged DDoS changes the defensive unit of measure: Short attacks test peak absorption, but long attacks test operational stamina, escalation paths, and decision latency. When disruption lasts long enough, the security problem becomes cumulative exhaustion across people, processes, and infrastructure. The field should stop describing DDoS only as a traffic event and start treating it as an availability governance problem.
Persistent automated probing is an application governance signal: Repeated cookie manipulation and low-noise request variation show that applications are being tested continuously, even when traffic appears normal. That creates a named concept we can call background adversary pressure, meaning the environment is under constant weak-signal testing rather than a single obvious attack. Security programmes need to measure how controls behave under sustained probing, not just during incident peaks.
DNS resilience, network resilience, and application resilience are converging into one control plane: The article's strongest implication is that separate teams can no longer assume separate pressure patterns. DNS noise, DDoS strain, and application probing now rise together, so the failure domain is the combined service path. Practitioners should align monitoring, response ownership, and service protection across those layers.
The market is moving from incident response to continuous exposure management: The article describes a landscape where defenders must operate under persistent demand and attack pressure simultaneously. That is not just a tooling challenge. It is a governance challenge about whether teams can maintain service trust when normal traffic and hostile traffic are both sustained for long periods.
What this signals
Background adversary pressure: The useful planning unit is no longer the burst, but the long tail of noisy demand and repeated probing. Teams should expect attack conditions to coexist with legitimate traffic, which means availability controls have to be measured continuously rather than validated only during test windows.
The operational consequence is that service resilience now spans DNS, network, and application layers at the same time. If those domains are monitored and escalated separately, the response will lag the attack pattern. The practical answer is tighter cross-team ownership of the full service path.
For practitioners
- Harden DNS endurance testing Stress-test authoritative and recursive DNS paths under sustained query volume, repeated NXDOMAIN noise, and mixed automated traffic so the team can see when degradation starts.
- Validate multiday DDoS response coverage Exercise the full mitigation chain across scrubbing, rate limiting, escalation, and vendor coordination for attacks that last longer than a single shift.
- Tune application controls for quiet probing Review cookie handling, request variation tolerance, and anomaly thresholds so low-noise automated testing is surfaced before it becomes exploitation.
- Align service ownership across DNS, network, and app layers Define who owns a service outage when the pressure crosses layers, because prolonged attacks fail at the seams between teams more than at any single control.
Key takeaways
- DigiCert's Q4 brief shows that sustained traffic growth and longer DDoS campaigns are replacing the old burst-and-recover model.
- The most important evidence is the shift from brief spikes to weeks of pressure, which raises the risk of cumulative degradation rather than simple outage.
- Security teams should test whether DNS, network, and application controls still work when load, probing, and attack pressure stay elevated together.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0007;TA0004;TA0008 — Discovery; Privilege Escalation; Lateral Movement | The brief describes persistent probing, abuse attempts, and multi-layer pressure patterns. |
| Recommendation — Map sustained probing and pressure patterns to ATT&CK tactics and hunt for repeated discovery and abuse behaviour. | ||
| NIST CSF 2.0 | DE.CM-01 — Networks and systems monitored | Continuous DNS and application noise demands active monitoring of service behaviour and anomalies. |
| RS.CO-02 — Incidents are communicated | Prolonged DDoS requires coordination across response teams and providers. | |
| Recommendation — Instrument DNS, network, and application telemetry so elevated background pressure is detected before degradation. Define escalation and communication paths that stay active during multiday attack pressure. | ||
| CIS Controls v8 | CIS-12 — Network Infrastructure Management | The article centres on resilience of internet-facing network services under sustained attack pressure. |
| Recommendation — Harden internet-facing infrastructure and validate that mitigation controls remain effective under continuous load. | ||
Key terms
- Sustained DDoS pressure: A DDoS pattern in which attack activity lasts long enough to exhaust operational and defensive capacity rather than simply causing a short interruption. The challenge is endurance, because response teams, mitigation services, and customer experience all degrade when pressure persists across multiple hours or days.
- NXDOMAIN noise: A high volume of failed DNS lookups that signals background churn, misconfiguration, or automated probing. In resilience analysis, it matters because persistent lookup failures can mask malicious scanning and create load that looks like ordinary internet activity until it becomes operationally significant.
- Background adversary pressure: Continuous low-noise hostile activity that blends into normal traffic while still testing systems for weakness. It is especially relevant when applications, DNS, or network controls are repeatedly probed over time, because the security problem becomes ongoing validation of control behaviour under stress.
- Control endurance: The ability of a security or availability control to keep working when demand or attack pressure persists instead of spiking briefly. For internet-facing services, endurance is the practical measure of whether mitigation, routing, and response processes can survive prolonged load without losing effectiveness.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org