DDoS has always been one of the greatest threats in the Internet landscape, especially towards high-profile organizations and governments. The goal is simple; Profit and financial gain -or damage. But how actually DDoS are currently being executed? Conversely, how are they mitigated? Is it always possible to mitigate an attack? (Hint: NO!) How have the techniques changed throughout the years? Most importantly, in the era of millions of connected devices to the Internet, which every one of the them is a potential bot to the next DDoS, does everyone know what DDoS is and how it works? On 2018, the largest volumetric attack targeting GitHub was recorded. Misconfigured memcached servers were utilized and fortunately for GitHub, the attack was not a zero-day at that point; meaning that it was timely mitigated. However, not all DDoS attacks are the same. Different layers, different attacks. From SYN Flood to DNS amplification, from HTTP GET Flood to CLDAP Reflection, to name a few. Nowadays, more and more DDoS attacks take place. One of the reasons is due to the fact that there are countless zombie devices lying around, but are still connected to the web and thus, composing botnets. In addition, zero-day attacks are inevitable, when it comes to software vulnerabilities. And if this is not enough, the attacker might always be able to take control (C&C) of a device with social engineering tricks, “exploiting” the unaware user(s). DDoS are here to stay. Since the mitigation techniques are evolving, the same applies for the type and techniques used for DDoS. Briefly stated, the sophisticated techniques focus now on the content; the payload (what does the packet contain), rather than the context (i.e the packet or the request on its own). Furthermore, DDoS-as-a-Service makes the future look grimmer rather than brighter. However, both engineers and end users need to understand that in the end it’s up to us. It’s up to our susceptibility for security and our willingness to take the necessary measures and stay safe and aware. This place -the Internet- will never be safe, but we can always do our best.